__init__.py 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217
  1. # -*- coding: utf-8 -*-
  2. #
  3. # This file is part of Radicale Server - Calendar Server
  4. # Copyright © 2008-2010 Guillaume Ayoub
  5. # Copyright © 2008 Nicolas Kandel
  6. # Copyright © 2008 Pascal Halter
  7. #
  8. # This library is free software: you can redistribute it and/or modify
  9. # it under the terms of the GNU General Public License as published by
  10. # the Free Software Foundation, either version 3 of the License, or
  11. # (at your option) any later version.
  12. #
  13. # This library is distributed in the hope that it will be useful,
  14. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. # GNU General Public License for more details.
  17. #
  18. # You should have received a copy of the GNU General Public License
  19. # along with Radicale. If not, see <http://www.gnu.org/licenses/>.
  20. """
  21. Radicale Server module.
  22. This module offers 3 useful classes:
  23. - ``HTTPServer`` is a simple HTTP server;
  24. - ``HTTPSServer`` is a HTTPS server, wrapping the HTTP server in a socket
  25. managing SSL connections;
  26. - ``CalendarHTTPHandler`` is a CalDAV request handler for HTTP(S) servers.
  27. To use this module, you should take a look at the file ``radicale.py`` that
  28. should have been included in this package.
  29. """
  30. import os
  31. import posixpath
  32. import base64
  33. import socket
  34. # Manage Python2/3 different modules
  35. # pylint: disable-msg=F0401
  36. try:
  37. from http import client, server
  38. except ImportError:
  39. import httplib as client
  40. import BaseHTTPServer as server
  41. # pylint: enable-msg=F0401
  42. from radicale import acl, config, ical, xmlutils
  43. def _check(request, function):
  44. """Check if user has sufficient rights for performing ``request``."""
  45. authorization = request.headers.get("Authorization", None)
  46. if authorization:
  47. challenge = authorization.lstrip("Basic").strip().encode("ascii")
  48. plain = request._decode(base64.b64decode(challenge))
  49. user, password = plain.split(":")
  50. else:
  51. user = password = None
  52. if request.server.acl.has_right(user, password):
  53. function(request)
  54. else:
  55. request.send_response(client.UNAUTHORIZED)
  56. request.send_header(
  57. "WWW-Authenticate",
  58. "Basic realm=\"Radicale Server - Password Required\"")
  59. request.end_headers()
  60. class HTTPServer(server.HTTPServer):
  61. """HTTP server."""
  62. def __init__(self, address, handler):
  63. """Create server."""
  64. server.HTTPServer.__init__(self, address, handler)
  65. self.acl = acl.load()
  66. class HTTPSServer(HTTPServer):
  67. """HTTPS server."""
  68. def __init__(self, address, handler):
  69. """Create server by wrapping HTTP socket in an SSL socket."""
  70. # Fails with Python 2.5, import if needed
  71. # pylint: disable-msg=F0401
  72. import ssl
  73. # pylint: enable-msg=F0401
  74. HTTPServer.__init__(self, address, handler)
  75. self.socket = ssl.wrap_socket(
  76. socket.socket(self.address_family, self.socket_type),
  77. server_side=True,
  78. certfile=config.get("server", "certificate"),
  79. keyfile=config.get("server", "key"),
  80. ssl_version=ssl.PROTOCOL_SSLv23)
  81. self.server_bind()
  82. self.server_activate()
  83. class CalendarHTTPHandler(server.BaseHTTPRequestHandler):
  84. """HTTP requests handler for calendars."""
  85. _encoding = config.get("encoding", "request")
  86. # Decorator checking rights before performing request
  87. check_rights = lambda function: lambda request: _check(request, function)
  88. @property
  89. def _calendar(self):
  90. """The ``ical.Calendar`` object corresponding to the given path."""
  91. # ``self.path`` must be something like a posix path
  92. # ``normpath`` should clean malformed and malicious request paths
  93. attributes = posixpath.normpath(self.path.strip("/")).split("/")
  94. if len(attributes) >= 2:
  95. path = "%s/%s" % (attributes[0], attributes[1])
  96. return ical.Calendar(path)
  97. def _decode(self, text):
  98. """Try to decode text according to various parameters."""
  99. # List of charsets to try
  100. charsets = []
  101. # First append content charset given in the request
  102. content_type = self.headers.get("Content-Type", None)
  103. if content_type and "charset=" in content_type:
  104. charsets.append(content_type.split("charset=")[1].strip())
  105. # Then append default Radicale charset
  106. charsets.append(self._encoding)
  107. # Then append various fallbacks
  108. charsets.append("utf-8")
  109. charsets.append("iso8859-1")
  110. # Try to decode
  111. for charset in charsets:
  112. try:
  113. return text.decode(charset)
  114. except UnicodeDecodeError:
  115. pass
  116. raise UnicodeDecodeError
  117. # Naming methods ``do_*`` is OK here
  118. # pylint: disable-msg=C0103
  119. @check_rights
  120. def do_GET(self):
  121. """Manage GET request."""
  122. answer = self._calendar.text.encode(self._encoding)
  123. self.send_response(client.OK)
  124. self.send_header("Content-Length", len(answer))
  125. self.end_headers()
  126. self.wfile.write(answer)
  127. @check_rights
  128. def do_DELETE(self):
  129. """Manage DELETE request."""
  130. item = self._calendar.get_item(xmlutils.name_from_path(self.path))
  131. if item and self.headers.get("If-Match", item.etag) == item.etag:
  132. # No ETag precondition or precondition verified, delete item
  133. answer = xmlutils.delete(self.path, self._calendar)
  134. self.send_response(client.NO_CONTENT)
  135. self.send_header("Content-Length", len(answer))
  136. self.end_headers()
  137. self.wfile.write(answer)
  138. else:
  139. # No item or ETag precondition not verified, do not delete item
  140. self.send_response(client.PRECONDITION_FAILED)
  141. def do_OPTIONS(self):
  142. """Manage OPTIONS request."""
  143. self.send_response(client.OK)
  144. self.send_header("Allow", "DELETE, GET, OPTIONS, PROPFIND, PUT, REPORT")
  145. self.send_header("DAV", "1, calendar-access")
  146. self.end_headers()
  147. def do_PROPFIND(self):
  148. """Manage PROPFIND request."""
  149. xml_request = self.rfile.read(int(self.headers["Content-Length"]))
  150. answer = xmlutils.propfind(self.path, xml_request, self._calendar)
  151. self.send_response(client.MULTI_STATUS)
  152. self.send_header("DAV", "1, calendar-access")
  153. self.send_header("Content-Length", len(answer))
  154. self.end_headers()
  155. self.wfile.write(answer)
  156. @check_rights
  157. def do_PUT(self):
  158. """Manage PUT request."""
  159. item = self._calendar.get_item(xmlutils.name_from_path(self.path))
  160. if (not item and not self.headers.get("If-Match")) or \
  161. (item and self.headers.get("If-Match", item.etag) == item.etag):
  162. # PUT allowed in 3 cases
  163. # Case 1: No item and no ETag precondition: Add new item
  164. # Case 2: Item and ETag precondition verified: Modify item
  165. # Case 3: Item and no Etag precondition: Force modifying item
  166. ical_request = self._decode(
  167. self.rfile.read(int(self.headers["Content-Length"])))
  168. xmlutils.put(self.path, ical_request, self._calendar)
  169. self.send_response(client.CREATED)
  170. else:
  171. # PUT rejected in all other cases
  172. self.send_response(client.PRECONDITION_FAILED)
  173. @check_rights
  174. def do_REPORT(self):
  175. """Manage REPORT request."""
  176. xml_request = self.rfile.read(int(self.headers["Content-Length"]))
  177. answer = xmlutils.report(self.path, xml_request, self._calendar)
  178. self.send_response(client.MULTI_STATUS)
  179. self.send_header("Content-Length", len(answer))
  180. self.end_headers()
  181. self.wfile.write(answer)
  182. # pylint: enable-msg=C0103