1
0

__init__.py 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360
  1. # -*- coding: utf-8 -*-
  2. #
  3. # This file is part of Radicale Server - Calendar Server
  4. # Copyright © 2008-2011 Guillaume Ayoub
  5. # Copyright © 2008 Nicolas Kandel
  6. # Copyright © 2008 Pascal Halter
  7. #
  8. # This library is free software: you can redistribute it and/or modify
  9. # it under the terms of the GNU General Public License as published by
  10. # the Free Software Foundation, either version 3 of the License, or
  11. # (at your option) any later version.
  12. #
  13. # This library is distributed in the hope that it will be useful,
  14. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. # GNU General Public License for more details.
  17. #
  18. # You should have received a copy of the GNU General Public License
  19. # along with Radicale. If not, see <http://www.gnu.org/licenses/>.
  20. """
  21. Radicale Server module.
  22. This module offers 3 useful classes:
  23. - ``HTTPServer`` is a simple HTTP server;
  24. - ``HTTPSServer`` is a HTTPS server, wrapping the HTTP server in a socket
  25. managing SSL connections;
  26. - ``CalendarHTTPHandler`` is a CalDAV request handler for HTTP(S) servers.
  27. To use this module, you should take a look at the file ``radicale.py`` that
  28. should have been included in this package.
  29. """
  30. import os
  31. import posixpath
  32. import base64
  33. import socket
  34. # Manage Python2/3 different modules
  35. # pylint: disable=F0401
  36. try:
  37. from http import client, server
  38. except ImportError:
  39. import httplib as client
  40. import BaseHTTPServer as server
  41. # pylint: enable=F0401
  42. from radicale import acl, config, ical, log, xmlutils
  43. VERSION = "git"
  44. # Decorators can access ``request`` protected functions
  45. # pylint: disable=W0212
  46. def _check(request, function):
  47. """Check if user has sufficient rights for performing ``request``."""
  48. # If we have no calendar or no acl, don't check rights
  49. if not request._calendar or not request.server.acl:
  50. return function(request)
  51. if request._calendar.owner is None and PERSONAL:
  52. # No owner and personal calendars, don't check rights
  53. return function(request)
  54. log.LOGGER.info(
  55. "Checking rights for calendar owned by %s" % request._calendar.owner)
  56. authorization = request.headers.get("Authorization", None)
  57. if authorization:
  58. challenge = authorization.lstrip("Basic").strip().encode("ascii")
  59. user, password = request._decode(base64.b64decode(challenge)).split(":")
  60. else:
  61. user = password = None
  62. if request.server.acl.has_right(request._calendar.owner, user, password):
  63. log.LOGGER.info("%s allowed" % request._calendar.owner)
  64. function(request)
  65. else:
  66. log.LOGGER.info("%s refused" % request._calendar.owner)
  67. request.send_response(client.UNAUTHORIZED)
  68. request.send_header(
  69. "WWW-Authenticate",
  70. "Basic realm=\"Radicale Server - Password Required\"")
  71. request.end_headers()
  72. def _log_request_content(request, function):
  73. """Log the content of the request and store it in the request object."""
  74. log.LOGGER.info(
  75. "%s request at %s recieved from %s" % (
  76. request.command, request.path, request.client_address[0]))
  77. content_length = int(request.headers.get("Content-Length", 0))
  78. if content_length:
  79. request._content = request.rfile.read(content_length)
  80. log.LOGGER.debug(
  81. "Request headers:\n%s" % "\n".join(
  82. ": ".join((key, value))
  83. for key, value in request.headers.items()))
  84. log.LOGGER.debug(
  85. "Request content:\n%s" % request._decode(request._content))
  86. else:
  87. request._content = None
  88. function(request)
  89. if getattr(request, "_answer"):
  90. log.LOGGER.debug(
  91. "Response content:\n%s" % request._answer)
  92. # pylint: enable=W0212
  93. class HTTPServer(server.HTTPServer):
  94. """HTTP server."""
  95. PROTOCOL = "http"
  96. # Maybe a Pylint bug, ``__init__`` calls ``server.HTTPServer.__init__``
  97. # pylint: disable=W0231
  98. def __init__(self, address, handler, bind_and_activate=True):
  99. """Create server."""
  100. ipv6 = ":" in address[0]
  101. if ipv6:
  102. self.address_family = socket.AF_INET6
  103. # Do not bind and activate, as we might change socketopts
  104. server.HTTPServer.__init__(self, address, handler, False)
  105. if ipv6:
  106. # Only allow IPv6 connections to the IPv6 socket
  107. self.socket.setsockopt(socket.IPPROTO_IPV6, socket.IPV6_V6ONLY, 1)
  108. if bind_and_activate:
  109. self.server_bind()
  110. self.server_activate()
  111. self.acl = acl.load()
  112. # pylint: enable=W0231
  113. class HTTPSServer(HTTPServer):
  114. """HTTPS server."""
  115. PROTOCOL = "https"
  116. def __init__(self, address, handler, bind_and_activate=True):
  117. """Create server by wrapping HTTP socket in an SSL socket."""
  118. # Fails with Python 2.5, import if needed
  119. # pylint: disable=F0401
  120. import ssl
  121. # pylint: enable=F0401
  122. HTTPServer.__init__(self, address, handler, False)
  123. self.socket = ssl.wrap_socket(
  124. self.socket,
  125. server_side=True,
  126. certfile=config.get("server", "certificate"),
  127. keyfile=config.get("server", "key"),
  128. ssl_version=ssl.PROTOCOL_SSLv23)
  129. if bind_and_activate:
  130. self.server_bind()
  131. self.server_activate()
  132. class CalendarHTTPHandler(server.BaseHTTPRequestHandler):
  133. """HTTP requests handler for calendars."""
  134. _encoding = config.get("encoding", "request")
  135. # Request handlers decorators
  136. check_rights = lambda function: lambda request: _check(request, function)
  137. log_request_content = \
  138. lambda function: lambda request: _log_request_content(request, function)
  139. # Maybe a Pylint bug, ``__init__`` calls ``server.HTTPServer.__init__``
  140. # pylint: disable=W0231
  141. def __init__(self, request, client_address, http_server):
  142. self._content = None
  143. self._answer = None
  144. server.BaseHTTPRequestHandler.__init__(
  145. self, request, client_address, http_server)
  146. # pylint: enable=W0231
  147. @property
  148. def _calendar(self):
  149. """The ``ical.Calendar`` object corresponding to the given path."""
  150. # ``self.path`` must be something like a posix path
  151. # ``normpath`` should clean malformed and malicious request paths
  152. attributes = posixpath.normpath(self.path.strip("/")).split("/")
  153. if attributes:
  154. if attributes[-1].endswith('.ics'):
  155. attributes.pop()
  156. path = "/".join(attributes[:min(len(attributes), 2)])
  157. return ical.Calendar(path)
  158. def _decode(self, text):
  159. """Try to decode text according to various parameters."""
  160. # List of charsets to try
  161. charsets = []
  162. # First append content charset given in the request
  163. content_type = self.headers.get("Content-Type", None)
  164. if content_type and "charset=" in content_type:
  165. charsets.append(content_type.split("charset=")[1].strip())
  166. # Then append default Radicale charset
  167. charsets.append(self._encoding)
  168. # Then append various fallbacks
  169. charsets.append("utf-8")
  170. charsets.append("iso8859-1")
  171. # Try to decode
  172. for charset in charsets:
  173. try:
  174. return text.decode(charset)
  175. except UnicodeDecodeError:
  176. pass
  177. raise UnicodeDecodeError
  178. def log_message(self, *args, **kwargs):
  179. """Disable inner logging management."""
  180. # Naming methods ``do_*`` is OK here
  181. # pylint: disable=C0103
  182. @log_request_content
  183. def do_GET(self):
  184. """Manage GET request."""
  185. self.do_HEAD()
  186. if self._answer:
  187. self.wfile.write(self._answer)
  188. @log_request_content
  189. @check_rights
  190. def do_HEAD(self):
  191. """Manage HEAD request."""
  192. item_name = xmlutils.name_from_path(self.path, self._calendar)
  193. if item_name:
  194. # Get calendar item
  195. item = self._calendar.get_item(item_name)
  196. if item:
  197. items = self._calendar.timezones
  198. items.append(item)
  199. answer_text = ical.serialize(
  200. headers=self._calendar.headers, items=items)
  201. etag = item.etag
  202. else:
  203. self._answer = None
  204. self.send_response(client.GONE)
  205. return
  206. else:
  207. # Get whole calendar
  208. answer_text = self._calendar.text
  209. etag = self._calendar.etag
  210. self._answer = answer_text.encode(self._encoding)
  211. self.send_response(client.OK)
  212. self.send_header("Content-Length", len(self._answer))
  213. self.send_header("Content-Type", "text/calendar")
  214. self.send_header("Last-Modified", self._calendar.last_modified)
  215. self.send_header("ETag", etag)
  216. self.end_headers()
  217. @log_request_content
  218. @check_rights
  219. def do_DELETE(self):
  220. """Manage DELETE request."""
  221. item = self._calendar.get_item(
  222. xmlutils.name_from_path(self.path, self._calendar))
  223. if item and self.headers.get("If-Match", item.etag) == item.etag:
  224. # No ETag precondition or precondition verified, delete item
  225. self._answer = xmlutils.delete(self.path, self._calendar)
  226. self.send_response(client.NO_CONTENT)
  227. self.send_header("Content-Length", len(self._answer))
  228. self.end_headers()
  229. self.wfile.write(self._answer)
  230. else:
  231. # No item or ETag precondition not verified, do not delete item
  232. self.send_response(client.PRECONDITION_FAILED)
  233. @log_request_content
  234. @check_rights
  235. def do_MKCALENDAR(self):
  236. """Manage MKCALENDAR request."""
  237. self.send_response(client.CREATED)
  238. self.end_headers()
  239. @log_request_content
  240. def do_OPTIONS(self):
  241. """Manage OPTIONS request."""
  242. self.send_response(client.OK)
  243. self.send_header(
  244. "Allow", "DELETE, HEAD, GET, MKCALENDAR, "
  245. "OPTIONS, PROPFIND, PROPPATCH, PUT, REPORT")
  246. self.send_header("DAV", "1, calendar-access")
  247. self.end_headers()
  248. @log_request_content
  249. def do_PROPFIND(self):
  250. """Manage PROPFIND request."""
  251. self._answer = xmlutils.propfind(
  252. self.path, self._content, self._calendar,
  253. self.headers.get("depth", "infinity"))
  254. self.send_response(client.MULTI_STATUS)
  255. self.send_header("DAV", "1, calendar-access")
  256. self.send_header("Content-Length", len(self._answer))
  257. self.send_header("Content-Type", "text/xml")
  258. self.end_headers()
  259. self.wfile.write(self._answer)
  260. @log_request_content
  261. def do_PROPPATCH(self):
  262. """Manage PROPPATCH request."""
  263. self._answer = xmlutils.proppatch(
  264. self.path, self._content, self._calendar)
  265. self.send_response(client.MULTI_STATUS)
  266. self.send_header("DAV", "1, calendar-access")
  267. self.send_header("Content-Length", len(self._answer))
  268. self.send_header("Content-Type", "text/xml")
  269. self.end_headers()
  270. self.wfile.write(self._answer)
  271. @log_request_content
  272. @check_rights
  273. def do_PUT(self):
  274. """Manage PUT request."""
  275. item_name = xmlutils.name_from_path(self.path, self._calendar)
  276. item = self._calendar.get_item(item_name)
  277. if (not item and not self.headers.get("If-Match")) or \
  278. (item and self.headers.get("If-Match", item.etag) == item.etag):
  279. # PUT allowed in 3 cases
  280. # Case 1: No item and no ETag precondition: Add new item
  281. # Case 2: Item and ETag precondition verified: Modify item
  282. # Case 3: Item and no Etag precondition: Force modifying item
  283. ical_request = self._decode(self._content)
  284. xmlutils.put(self.path, ical_request, self._calendar)
  285. etag = self._calendar.get_item(item_name).etag
  286. self.send_response(client.CREATED)
  287. self.send_header("ETag", etag)
  288. self.end_headers()
  289. else:
  290. # PUT rejected in all other cases
  291. self.send_response(client.PRECONDITION_FAILED)
  292. @log_request_content
  293. @check_rights
  294. def do_REPORT(self):
  295. """Manage REPORT request."""
  296. self._answer = xmlutils.report(self.path, self._content, self._calendar)
  297. self.send_response(client.MULTI_STATUS)
  298. self.send_header("Content-Length", len(self._answer))
  299. self.end_headers()
  300. self.wfile.write(self._answer)
  301. # pylint: enable=C0103