server_twilio.go 7.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222
  1. package server
  2. import (
  3. "bytes"
  4. "encoding/xml"
  5. "fmt"
  6. "io"
  7. "net/http"
  8. "net/url"
  9. "strings"
  10. "text/template"
  11. "heckel.io/ntfy/v2/log"
  12. "heckel.io/ntfy/v2/user"
  13. "heckel.io/ntfy/v2/util"
  14. )
  15. const (
  16. // defaultTwilioCallFormat is the default TwiML format used for Twilio calls.
  17. // It can be overridden in the server configuration's twilio-call-format field.
  18. //
  19. // The format uses Go template syntax with the following fields:
  20. // {{.Topic}}, {{.Title}}, {{.Message}}, {{.Priority}}, {{.Tags}}, {{.Sender}}
  21. // String fields are automatically XML-escaped.
  22. defaultTwilioCallFormat = `
  23. <Response>
  24. <Pause length="1"/>
  25. <Say loop="3">
  26. You have a message from notify on topic {{.Topic}}. Message:
  27. <break time="1s"/>
  28. {{.Message}}
  29. <break time="1s"/>
  30. End of message.
  31. <break time="1s"/>
  32. This message was sent by user {{.Sender}}. It will be repeated three times.
  33. To unsubscribe from calls like this, remove your phone number in the notify web app.
  34. <break time="3s"/>
  35. </Say>
  36. <Say>Goodbye.</Say>
  37. </Response>`
  38. )
  39. // twilioCallData holds the data passed to the Twilio call format template
  40. type twilioCallData struct {
  41. Topic string
  42. Title string
  43. Message string
  44. Priority int
  45. Tags []string
  46. Sender string
  47. }
  48. // convertPhoneNumber checks if the given phone number is verified for the given user, and if so, returns the verified
  49. // phone number. It also converts a boolean string ("yes", "1", "true") to the first verified phone number.
  50. // If the user is anonymous, it will return an error.
  51. func (s *Server) convertPhoneNumber(u *user.User, phoneNumber string) (string, *errHTTP) {
  52. if u == nil {
  53. return "", errHTTPBadRequestAnonymousCallsNotAllowed
  54. }
  55. phoneNumbers, err := s.userManager.PhoneNumbers(u.ID)
  56. if err != nil {
  57. return "", errHTTPInternalError
  58. } else if len(phoneNumbers) == 0 {
  59. return "", errHTTPBadRequestPhoneNumberNotVerified
  60. }
  61. if toBool(phoneNumber) {
  62. return phoneNumbers[0], nil
  63. } else if util.Contains(phoneNumbers, phoneNumber) {
  64. return phoneNumber, nil
  65. }
  66. for _, p := range phoneNumbers {
  67. if p == phoneNumber {
  68. return phoneNumber, nil
  69. }
  70. }
  71. return "", errHTTPBadRequestPhoneNumberNotVerified
  72. }
  73. // callPhone calls the Twilio API to make a phone call to the given phone number, using the given message.
  74. // Failures will be logged, but not returned to the caller.
  75. func (s *Server) callPhone(v *visitor, r *http.Request, m *message, to string) {
  76. u, sender := v.User(), m.Sender.String()
  77. if u != nil {
  78. sender = u.Name
  79. }
  80. templateStr := defaultTwilioCallFormat
  81. if s.config.TwilioCallFormat != "" {
  82. templateStr = s.config.TwilioCallFormat
  83. }
  84. tmpl, err := template.New("twiml").Parse(templateStr)
  85. if err != nil {
  86. logvrm(v, r, m).Tag(tagTwilio).Err(err).Warn("Error parsing Twilio call format template")
  87. minc(metricCallsMadeFailure)
  88. return
  89. }
  90. tags := make([]string, len(m.Tags))
  91. for i, tag := range m.Tags {
  92. tags[i] = xmlEscapeText(tag)
  93. }
  94. templateData := &twilioCallData{
  95. Topic: xmlEscapeText(m.Topic),
  96. Title: xmlEscapeText(m.Title),
  97. Message: xmlEscapeText(m.Message),
  98. Priority: m.Priority,
  99. Tags: tags,
  100. Sender: xmlEscapeText(sender),
  101. }
  102. var bodyBuf bytes.Buffer
  103. if err := tmpl.Execute(&bodyBuf, templateData); err != nil {
  104. logvrm(v, r, m).Tag(tagTwilio).Err(err).Warn("Error executing Twilio call format template")
  105. minc(metricCallsMadeFailure)
  106. return
  107. }
  108. body := bodyBuf.String()
  109. data := url.Values{}
  110. data.Set("From", s.config.TwilioPhoneNumber)
  111. data.Set("To", to)
  112. data.Set("Twiml", body)
  113. ev := logvrm(v, r, m).Tag(tagTwilio).Field("twilio_to", to).FieldIf("twilio_body", body, log.TraceLevel).Debug("Sending Twilio request")
  114. response, err := s.callPhoneInternal(data)
  115. if err != nil {
  116. ev.Field("twilio_response", response).Err(err).Warn("Error sending Twilio request")
  117. minc(metricCallsMadeFailure)
  118. return
  119. }
  120. ev.FieldIf("twilio_response", response, log.TraceLevel).Debug("Received successful Twilio response")
  121. minc(metricCallsMadeSuccess)
  122. }
  123. func (s *Server) callPhoneInternal(data url.Values) (string, error) {
  124. requestURL := fmt.Sprintf("%s/2010-04-01/Accounts/%s/Calls.json", s.config.TwilioCallsBaseURL, s.config.TwilioAccount)
  125. req, err := http.NewRequest(http.MethodPost, requestURL, strings.NewReader(data.Encode()))
  126. if err != nil {
  127. return "", err
  128. }
  129. req.Header.Set("User-Agent", "ntfy/"+s.config.Version)
  130. req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
  131. req.Header.Set("Authorization", util.BasicAuth(s.config.TwilioAccount, s.config.TwilioAuthToken))
  132. resp, err := http.DefaultClient.Do(req)
  133. if err != nil {
  134. return "", err
  135. }
  136. response, err := io.ReadAll(resp.Body)
  137. if err != nil {
  138. return "", err
  139. }
  140. return string(response), nil
  141. }
  142. func (s *Server) verifyPhoneNumber(v *visitor, r *http.Request, phoneNumber, channel string) error {
  143. ev := logvr(v, r).Tag(tagTwilio).Field("twilio_to", phoneNumber).Field("twilio_channel", channel).Debug("Sending phone verification")
  144. data := url.Values{}
  145. data.Set("To", phoneNumber)
  146. data.Set("Channel", channel)
  147. requestURL := fmt.Sprintf("%s/v2/Services/%s/Verifications", s.config.TwilioVerifyBaseURL, s.config.TwilioVerifyService)
  148. req, err := http.NewRequest(http.MethodPost, requestURL, strings.NewReader(data.Encode()))
  149. if err != nil {
  150. return err
  151. }
  152. req.Header.Set("User-Agent", "ntfy/"+s.config.Version)
  153. req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
  154. req.Header.Set("Authorization", util.BasicAuth(s.config.TwilioAccount, s.config.TwilioAuthToken))
  155. resp, err := http.DefaultClient.Do(req)
  156. if err != nil {
  157. return err
  158. }
  159. response, err := io.ReadAll(resp.Body)
  160. if err != nil {
  161. ev.Err(err).Warn("Error sending Twilio phone verification request")
  162. return err
  163. }
  164. ev.FieldIf("twilio_response", string(response), log.TraceLevel).Debug("Received Twilio phone verification response")
  165. return nil
  166. }
  167. func (s *Server) verifyPhoneNumberCheck(v *visitor, r *http.Request, phoneNumber, code string) error {
  168. ev := logvr(v, r).Tag(tagTwilio).Field("twilio_to", phoneNumber).Debug("Checking phone verification")
  169. data := url.Values{}
  170. data.Set("To", phoneNumber)
  171. data.Set("Code", code)
  172. requestURL := fmt.Sprintf("%s/v2/Services/%s/VerificationCheck", s.config.TwilioVerifyBaseURL, s.config.TwilioVerifyService)
  173. req, err := http.NewRequest(http.MethodPost, requestURL, strings.NewReader(data.Encode()))
  174. if err != nil {
  175. return err
  176. }
  177. req.Header.Set("User-Agent", "ntfy/"+s.config.Version)
  178. req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
  179. req.Header.Set("Authorization", util.BasicAuth(s.config.TwilioAccount, s.config.TwilioAuthToken))
  180. resp, err := http.DefaultClient.Do(req)
  181. if err != nil {
  182. return err
  183. } else if resp.StatusCode != http.StatusOK {
  184. if ev.IsTrace() {
  185. response, err := io.ReadAll(resp.Body)
  186. if err != nil {
  187. return err
  188. }
  189. ev.Field("twilio_response", string(response))
  190. }
  191. ev.Warn("Twilio phone verification failed with status code %d", resp.StatusCode)
  192. if resp.StatusCode == http.StatusNotFound {
  193. return errHTTPGonePhoneVerificationExpired
  194. }
  195. return errHTTPInternalError
  196. }
  197. response, err := io.ReadAll(resp.Body)
  198. if err != nil {
  199. return err
  200. }
  201. if ev.IsTrace() {
  202. ev.Field("twilio_response", string(response)).Trace("Received successful Twilio phone verification response")
  203. } else if ev.IsDebug() {
  204. ev.Debug("Received successful Twilio phone verification response")
  205. }
  206. return nil
  207. }
  208. func xmlEscapeText(text string) string {
  209. var buf bytes.Buffer
  210. _ = xml.EscapeText(&buf, []byte(text))
  211. return buf.String()
  212. }