/*
Spacebar: A FOSS re-implementation and extension of the Discord.com backend.
Copyright (C) 2023 Spacebar and Spacebar Contributors
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as published
by the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU Affero General Public License for more details.
You should have received a copy of the GNU Affero General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import path from "node:path";
import express, { Request, Response, Router } from "express";
import morgan from "morgan";
import { Server, ServerOptions } from "lambert-server";
import { red } from "picocolors";
import { Config, ConnectionConfig, ConnectionLoader, Email, JSONReplacer, WebAuthn, initDatabase, initEvent, registerRoutes, getDatabase, getRevInfoOrFail } from "@spacebar/util";
import { Authentication, CORS, ImageProxy, BodyParser, ErrorHandler, initRateLimits, initTranslation } from "./middlewares";
import { initInstance } from "./util/handlers/Instance";
import { route } from "./util";
import fs from "node:fs";
import { ProcessLifecycle } from "../util/util/ProcessLifecycle";
import { Monitoring } from "../util/monitoring/Monitoring";
import { BcryptWorkerPool } from "../util/util/workers/bcrypt/BcryptWorkerPool";
import { applyEnv, applyPlugins } from "./middlewares/TestClient";
import fetch, { Response as FetchResponse, Headers } from "node-fetch";
const ASSET_FOLDER_PATH = path.join(__dirname, "..", "..", "assets");
const ASSETS_FOLDER = path.join(__dirname, "..", "..", "assets");
const PUBLIC_ASSETS_FOLDER = path.join(ASSETS_FOLDER, "public");
export type SpacebarServerOptions = ServerOptions;
declare global {
// eslint-disable-next-line @typescript-eslint/no-namespace
namespace Express {
interface Request {
server: SpacebarServer;
}
}
}
export class SpacebarServer extends Server {
declare public options: SpacebarServerOptions;
constructor(opts?: Partial<SpacebarServerOptions>) {
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore
super(opts);
}
async start() {
await Monitoring.init();
Monitoring.attach(this.app);
await initDatabase();
await Config.init();
await initEvent();
await Email.init();
await ConnectionConfig.init();
await initInstance();
WebAuthn.init();
// await BcryptWorkerPool.Init(8); // TODO: make configurable
const logRequests = process.env["LOG_REQUESTS"] != undefined;
if (logRequests) {
this.app.use(
morgan("combined", {
skip: (req, res) => {
let skip = !(process.env["LOG_REQUESTS"]?.includes(res.statusCode.toString()) ?? false);
if (process.env["LOG_REQUESTS"]?.charAt(0) == "-") skip = !skip;
return skip;
},
}),
);
}
this.app.set("json replacer", JSONReplacer);
this.app.disable("x-powered-by");
const trustedProxies = Config.get().security.trustedProxies;
if (trustedProxies) this.app.set("trust proxy", trustedProxies);
this.app.use(CORS);
this.app.use(BodyParser({ inflate: true, limit: "10mb" }));
const app = this.app;
//const api = Router({ mergeParams: true });
const api = Router();
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
// @ts-ignore
this.app = api;
api.use(Authentication);
await initRateLimits(api);
await initTranslation(api);
this.routes = (await registerRoutes(this, path.join(__dirname, "routes", "/"))).filter((r) => !!r);
api.use((req, res, next) => {
console.log(`[Server API Router] Incoming request: ${req.method} ${req.url}`);
next();
});
// 404 is not an error in express, so this should not be an error middleware
// this is a fine place to put the 404 handler because its after we register the routes
// and since its not an error middleware, our error handler below still works.
// Emma [it/its] @ Rory& - the _ is required now, as pillarjs throw an error if you don't pass a param name now
// api.use("*_", (req: Request, res: Response) => {
// res.status(404).json({
// message: "Endpoint not found",
// code: 404,
// request: `${req.method} ${req.url}`,
// });
// });
this.app = app;
//app.use("/__development", )
//app.use("/__internals", )
app.use("/api/v6", api);
app.use("/api/v7", api);
app.use("/api/v8", api);
app.use("/api/v9", api);
app.use("/api/v10", api); // https://discord.com/developers/docs/change-log#api-v10
// app.use("/api", api); // allow unversioned requests
app.use("/imageproxy/:hash/:size/:url", ImageProxy);
// app.get("/", (req, res) => {
// res.set("Cache-Control", "public, max-age=21600");
// return res.sendFile(path.join(PUBLIC_ASSETS_FOLDER, "index.html"));
// });
app.get("/verify-email", (req, res) => {
res.set("Cache-Control", "public, max-age=21600");
return res.sendFile(path.join(PUBLIC_ASSETS_FOLDER, "verify.html"));
});
app.get("/widget", (req, res) => {
res.set("Cache-Control", "public, max-age=21600");
return res.sendFile(path.join(PUBLIC_ASSETS_FOLDER, "widget.html"));
});
app.get("/_spacebar/api/schemas.json", (req, res) => {
res.sendFile(path.join(ASSETS_FOLDER, "schemas.json"));
});
app.get("/_spacebar/api/openapi.json", (req, res) => {
res.sendFile(path.join(ASSETS_FOLDER, "openapi.json"));
});
app.get("/_spacebar/api/version", (req, res) => {
res.json({
implementation: "spacebar-server-ts",
version: getRevInfoOrFail(),
});
});
let html = fs.readFileSync(path.join(ASSET_FOLDER_PATH, "client_test", "index.html"), { encoding: "utf-8" });
console.log("call 3");
html = applyEnv(html); // update window.GLOBAL_ENV according to config
html = applyPlugins(html); // inject our plugins
// current well-known location
app.get("/.well-known/spacebar", (req, res) => {
res.json({
api: (Config.get().api.endpointPublic + "/api/").replace("//api/", "/api/"),
});
});
// new well-known location
app.get("/.well-known/spacebar/client", (req, res) => {
res.json({
api: {
baseUrl: Config.get().api.endpointPublic?.split("/api/")[0],
apiVersions: {
default: Config.get().api.defaultVersion,
active: Config.get().api.activeVersions,
},
},
cdn: {
baseUrl: Config.get().cdn.endpointPublic,
},
gateway: {
baseUrl: Config.get().gateway.endpointPublic,
encoding: ["etf", "json"],
compression: ["zstd-stream", "zlib-stream", null],
},
admin:
Config.get().admin.endpointPublic === null
? undefined
: {
baseUrl: Config.get().admin.endpointPublic,
},
});
});
function isReady(req: Request, res: Response) {
if (!getDatabase()) return res.sendStatus(503);
return res.sendStatus(200);
}
app.get("/readyz", route({ description: "Get the ready state of the server" }), isReady);
app.get("/healthz", route({ description: "Get the ready state of the server" }), isReady);
this.app.use(ErrorHandler);
await ConnectionLoader.loadConnections();
if (logRequests) console.log(red(`Warning: Request logging is enabled! This will spam your console!\nTo disable this, unset the 'LOG_REQUESTS' environment variable!`));
app.use("/assets", express.static(path.join(ASSET_FOLDER_PATH, "public")));
app.use("/assets", express.static(path.join(ASSET_FOLDER_PATH, "cache")));
app.use("/assets/plugins", express.static(path.join(ASSET_FOLDER_PATH, "plugins")));
app.use("/assets/inline-plugins", express.static(path.join(ASSET_FOLDER_PATH, "inline-plugins")));
const assetCache = new Map<string, { response: FetchResponse; buffer: Buffer }>();
// Fetches uncached ( on disk ) assets from discord.com and stores them in memory cache.
app.get("/assets/:file", async (req, res) => {
delete req.headers.host;
if (req.params.file.endsWith(".map")) return res.status(404);
let response: FetchResponse;
let buffer: Buffer;
const cache = assetCache.get(req.params.file);
if (!cache) {
response = await fetch(`https://discord.com/assets/${req.params.file}`, {
headers: { ...(req.headers as { [key: string]: string }) },
});
buffer = await response.buffer();
} else {
response = cache.response;
buffer = cache.buffer;
}
[
"content-length",
"content-security-policy",
"strict-transport-security",
"set-cookie",
"transfer-encoding",
"expect-ct",
"access-control-allow-origin",
"content-encoding",
].forEach((headerName) => {
response.headers.delete(headerName);
});
response.headers.forEach((value, name) => res.set(name, value));
assetCache.set(req.params.file, { buffer, response });
// TODO: I don't like this. Figure out a way to get client cacher to download *all* assets.
if (response.status == 200) {
console.warn(`[TestClient] Cache miss for file ${req.params.file}! Use 'npm run generate:client' to cache and patch.`);
await fs.promises.appendFile(path.join(ASSET_FOLDER_PATH, "cacheMisses"), req.params.file + "\n");
}
return res.send(buffer);
});
app.use((req, res, next) => {
console.log(`[TestClient Wildcard] Intercepted path: ${req.url}`);
if (req.url.startsWith("/api") || req.url.startsWith("/__development")) {
console.log(`[TestClient Wildcard] Bypassing route (matched API guard): ${req.url}`);
return next ? next() : res.sendStatus(404);
}
console.log(`[TestClient Wildcard] Serving index.html for: ${req.url}`);
res.set("Cache-Control", "public, max-age=" + 60 * 60 * 24);
res.set("content-type", "text/html");
return res.send(html);
});
await ProcessLifecycle.Ready();
return super.start();
}
}