serve.go 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352
  1. //go:build !noserver
  2. package cmd
  3. import (
  4. "errors"
  5. "fmt"
  6. "io/fs"
  7. "math"
  8. "net"
  9. "net/netip"
  10. "os"
  11. "os/signal"
  12. "strings"
  13. "syscall"
  14. "time"
  15. "heckel.io/ntfy/log"
  16. "github.com/urfave/cli/v2"
  17. "github.com/urfave/cli/v2/altsrc"
  18. "heckel.io/ntfy/server"
  19. "heckel.io/ntfy/util"
  20. )
  21. func init() {
  22. commands = append(commands, cmdServe)
  23. }
  24. const (
  25. defaultServerConfigFile = "/etc/ntfy/server.yml"
  26. )
  27. var flagsServe = append(
  28. flagsDefault,
  29. &cli.StringFlag{Name: "config", Aliases: []string{"c"}, EnvVars: []string{"NTFY_CONFIG_FILE"}, Value: defaultServerConfigFile, DefaultText: defaultServerConfigFile, Usage: "config file"},
  30. altsrc.NewStringFlag(&cli.StringFlag{Name: "base-url", Aliases: []string{"base_url", "B"}, EnvVars: []string{"NTFY_BASE_URL"}, Usage: "externally visible base URL for this host (e.g. https://ntfy.sh)"}),
  31. altsrc.NewStringFlag(&cli.StringFlag{Name: "listen-http", Aliases: []string{"listen_http", "l"}, EnvVars: []string{"NTFY_LISTEN_HTTP"}, Value: server.DefaultListenHTTP, Usage: "ip:port used to as HTTP listen address"}),
  32. altsrc.NewStringFlag(&cli.StringFlag{Name: "listen-https", Aliases: []string{"listen_https", "L"}, EnvVars: []string{"NTFY_LISTEN_HTTPS"}, Usage: "ip:port used to as HTTPS listen address"}),
  33. altsrc.NewStringFlag(&cli.StringFlag{Name: "listen-unix", Aliases: []string{"listen_unix", "U"}, EnvVars: []string{"NTFY_LISTEN_UNIX"}, Usage: "listen on unix socket path"}),
  34. altsrc.NewIntFlag(&cli.IntFlag{Name: "listen-unix-mode", Aliases: []string{"listen_unix_mode"}, EnvVars: []string{"NTFY_LISTEN_UNIX_MODE"}, DefaultText: "system default", Usage: "file permissions of unix socket, e.g. 0700"}),
  35. altsrc.NewStringFlag(&cli.StringFlag{Name: "key-file", Aliases: []string{"key_file", "K"}, EnvVars: []string{"NTFY_KEY_FILE"}, Usage: "private key file, if listen-https is set"}),
  36. altsrc.NewStringFlag(&cli.StringFlag{Name: "cert-file", Aliases: []string{"cert_file", "E"}, EnvVars: []string{"NTFY_CERT_FILE"}, Usage: "certificate file, if listen-https is set"}),
  37. altsrc.NewStringFlag(&cli.StringFlag{Name: "firebase-key-file", Aliases: []string{"firebase_key_file", "F"}, EnvVars: []string{"NTFY_FIREBASE_KEY_FILE"}, Usage: "Firebase credentials file; if set additionally publish to FCM topic"}),
  38. altsrc.NewStringFlag(&cli.StringFlag{Name: "cache-file", Aliases: []string{"cache_file", "C"}, EnvVars: []string{"NTFY_CACHE_FILE"}, Usage: "cache file used for message caching"}),
  39. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "cache-duration", Aliases: []string{"cache_duration", "b"}, EnvVars: []string{"NTFY_CACHE_DURATION"}, Value: server.DefaultCacheDuration, Usage: "buffer messages for this time to allow `since` requests"}),
  40. altsrc.NewIntFlag(&cli.IntFlag{Name: "cache-batch-size", Aliases: []string{"cache_batch_size"}, EnvVars: []string{"NTFY_BATCH_SIZE"}, Usage: "max size of messages to batch together when writing to message cache (if zero, writes are synchronous)"}),
  41. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "cache-batch-timeout", Aliases: []string{"cache_batch_timeout"}, EnvVars: []string{"NTFY_CACHE_BATCH_TIMEOUT"}, Usage: "timeout for batched async writes to the message cache (if zero, writes are synchronous)"}),
  42. altsrc.NewStringFlag(&cli.StringFlag{Name: "cache-startup-queries", Aliases: []string{"cache_startup_queries"}, EnvVars: []string{"NTFY_CACHE_STARTUP_QUERIES"}, Usage: "queries run when the cache database is initialized"}),
  43. altsrc.NewStringFlag(&cli.StringFlag{Name: "auth-file", Aliases: []string{"auth_file", "H"}, EnvVars: []string{"NTFY_AUTH_FILE"}, Usage: "auth database file used for access control"}),
  44. altsrc.NewStringFlag(&cli.StringFlag{Name: "auth-default-access", Aliases: []string{"auth_default_access", "p"}, EnvVars: []string{"NTFY_AUTH_DEFAULT_ACCESS"}, Value: "read-write", Usage: "default permissions if no matching entries in the auth database are found"}),
  45. altsrc.NewStringFlag(&cli.StringFlag{Name: "attachment-cache-dir", Aliases: []string{"attachment_cache_dir"}, EnvVars: []string{"NTFY_ATTACHMENT_CACHE_DIR"}, Usage: "cache directory for attached files"}),
  46. altsrc.NewStringFlag(&cli.StringFlag{Name: "attachment-total-size-limit", Aliases: []string{"attachment_total_size_limit", "A"}, EnvVars: []string{"NTFY_ATTACHMENT_TOTAL_SIZE_LIMIT"}, DefaultText: "5G", Usage: "limit of the on-disk attachment cache"}),
  47. altsrc.NewStringFlag(&cli.StringFlag{Name: "attachment-file-size-limit", Aliases: []string{"attachment_file_size_limit", "Y"}, EnvVars: []string{"NTFY_ATTACHMENT_FILE_SIZE_LIMIT"}, DefaultText: "15M", Usage: "per-file attachment size limit (e.g. 300k, 2M, 100M)"}),
  48. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "attachment-expiry-duration", Aliases: []string{"attachment_expiry_duration", "X"}, EnvVars: []string{"NTFY_ATTACHMENT_EXPIRY_DURATION"}, Value: server.DefaultAttachmentExpiryDuration, DefaultText: "3h", Usage: "duration after which uploaded attachments will be deleted (e.g. 3h, 20h)"}),
  49. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "keepalive-interval", Aliases: []string{"keepalive_interval", "k"}, EnvVars: []string{"NTFY_KEEPALIVE_INTERVAL"}, Value: server.DefaultKeepaliveInterval, Usage: "interval of keepalive messages"}),
  50. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "manager-interval", Aliases: []string{"manager_interval", "m"}, EnvVars: []string{"NTFY_MANAGER_INTERVAL"}, Value: server.DefaultManagerInterval, Usage: "interval of for message pruning and stats printing"}),
  51. altsrc.NewStringFlag(&cli.StringFlag{Name: "web-root", Aliases: []string{"web_root"}, EnvVars: []string{"NTFY_WEB_ROOT"}, Value: "app", Usage: "sets web root to landing page (home), web app (app) or disabled (disable)"}),
  52. altsrc.NewStringFlag(&cli.StringFlag{Name: "upstream-base-url", Aliases: []string{"upstream_base_url"}, EnvVars: []string{"NTFY_UPSTREAM_BASE_URL"}, Value: "", Usage: "forward poll request to an upstream server, this is needed for iOS push notifications for self-hosted servers"}),
  53. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-addr", Aliases: []string{"smtp_sender_addr"}, EnvVars: []string{"NTFY_SMTP_SENDER_ADDR"}, Usage: "SMTP server address (host:port) for outgoing emails"}),
  54. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-user", Aliases: []string{"smtp_sender_user"}, EnvVars: []string{"NTFY_SMTP_SENDER_USER"}, Usage: "SMTP user (if e-mail sending is enabled)"}),
  55. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-pass", Aliases: []string{"smtp_sender_pass"}, EnvVars: []string{"NTFY_SMTP_SENDER_PASS"}, Usage: "SMTP password (if e-mail sending is enabled)"}),
  56. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-from", Aliases: []string{"smtp_sender_from"}, EnvVars: []string{"NTFY_SMTP_SENDER_FROM"}, Usage: "SMTP sender address (if e-mail sending is enabled)"}),
  57. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-server-listen", Aliases: []string{"smtp_server_listen"}, EnvVars: []string{"NTFY_SMTP_SERVER_LISTEN"}, Usage: "SMTP server address (ip:port) for incoming emails, e.g. :25"}),
  58. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-server-domain", Aliases: []string{"smtp_server_domain"}, EnvVars: []string{"NTFY_SMTP_SERVER_DOMAIN"}, Usage: "SMTP domain for incoming e-mail, e.g. ntfy.sh"}),
  59. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-server-addr-prefix", Aliases: []string{"smtp_server_addr_prefix"}, EnvVars: []string{"NTFY_SMTP_SERVER_ADDR_PREFIX"}, Usage: "SMTP email address prefix for topics to prevent spam (e.g. 'ntfy-')"}),
  60. altsrc.NewIntFlag(&cli.IntFlag{Name: "global-topic-limit", Aliases: []string{"global_topic_limit", "T"}, EnvVars: []string{"NTFY_GLOBAL_TOPIC_LIMIT"}, Value: server.DefaultTotalTopicLimit, Usage: "total number of topics allowed"}),
  61. altsrc.NewIntFlag(&cli.IntFlag{Name: "visitor-subscription-limit", Aliases: []string{"visitor_subscription_limit"}, EnvVars: []string{"NTFY_VISITOR_SUBSCRIPTION_LIMIT"}, Value: server.DefaultVisitorSubscriptionLimit, Usage: "number of subscriptions per visitor"}),
  62. altsrc.NewStringFlag(&cli.StringFlag{Name: "visitor-attachment-total-size-limit", Aliases: []string{"visitor_attachment_total_size_limit"}, EnvVars: []string{"NTFY_VISITOR_ATTACHMENT_TOTAL_SIZE_LIMIT"}, Value: "100M", Usage: "total storage limit used for attachments per visitor"}),
  63. altsrc.NewStringFlag(&cli.StringFlag{Name: "visitor-attachment-daily-bandwidth-limit", Aliases: []string{"visitor_attachment_daily_bandwidth_limit"}, EnvVars: []string{"NTFY_VISITOR_ATTACHMENT_DAILY_BANDWIDTH_LIMIT"}, Value: "500M", Usage: "total daily attachment download/upload bandwidth limit per visitor"}),
  64. altsrc.NewIntFlag(&cli.IntFlag{Name: "visitor-request-limit-burst", Aliases: []string{"visitor_request_limit_burst"}, EnvVars: []string{"NTFY_VISITOR_REQUEST_LIMIT_BURST"}, Value: server.DefaultVisitorRequestLimitBurst, Usage: "initial limit of requests per visitor"}),
  65. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "visitor-request-limit-replenish", Aliases: []string{"visitor_request_limit_replenish"}, EnvVars: []string{"NTFY_VISITOR_REQUEST_LIMIT_REPLENISH"}, Value: server.DefaultVisitorRequestLimitReplenish, Usage: "interval at which burst limit is replenished (one per x)"}),
  66. altsrc.NewStringFlag(&cli.StringFlag{Name: "visitor-request-limit-exempt-hosts", Aliases: []string{"visitor_request_limit_exempt_hosts"}, EnvVars: []string{"NTFY_VISITOR_REQUEST_LIMIT_EXEMPT_HOSTS"}, Value: "", Usage: "hostnames and/or IP addresses of hosts that will be exempt from the visitor request limit"}),
  67. altsrc.NewIntFlag(&cli.IntFlag{Name: "visitor-email-limit-burst", Aliases: []string{"visitor_email_limit_burst"}, EnvVars: []string{"NTFY_VISITOR_EMAIL_LIMIT_BURST"}, Value: server.DefaultVisitorEmailLimitBurst, Usage: "initial limit of e-mails per visitor"}),
  68. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "visitor-email-limit-replenish", Aliases: []string{"visitor_email_limit_replenish"}, EnvVars: []string{"NTFY_VISITOR_EMAIL_LIMIT_REPLENISH"}, Value: server.DefaultVisitorEmailLimitReplenish, Usage: "interval at which burst limit is replenished (one per x)"}),
  69. altsrc.NewBoolFlag(&cli.BoolFlag{Name: "behind-proxy", Aliases: []string{"behind_proxy", "P"}, EnvVars: []string{"NTFY_BEHIND_PROXY"}, Value: false, Usage: "if set, use X-Forwarded-For header to determine visitor IP address (for rate limiting)"}),
  70. altsrc.NewBoolFlag(&cli.BoolFlag{Name: "enable-signup", Aliases: []string{"enable_signup"}, EnvVars: []string{"NTFY_ENABLE_SIGNUP"}, Value: false, Usage: "xxx"}),
  71. altsrc.NewBoolFlag(&cli.BoolFlag{Name: "enable-login", Aliases: []string{"enable_login"}, EnvVars: []string{"NTFY_ENABLE_LOGIN"}, Value: false, Usage: "xxx"}),
  72. )
  73. var cmdServe = &cli.Command{
  74. Name: "serve",
  75. Usage: "Run the ntfy server",
  76. UsageText: "ntfy serve [OPTIONS..]",
  77. Action: execServe,
  78. Category: categoryServer,
  79. Flags: flagsServe,
  80. Before: initConfigFileInputSourceFunc("config", flagsServe, initLogFunc),
  81. Description: `Run the ntfy server and listen for incoming requests
  82. The command will load the configuration from /etc/ntfy/server.yml. Config options can
  83. be overridden using the command line options.
  84. Examples:
  85. ntfy serve # Starts server in the foreground (on port 80)
  86. ntfy serve --listen-http :8080 # Starts server with alternate port`,
  87. }
  88. func execServe(c *cli.Context) error {
  89. if c.NArg() > 0 {
  90. return errors.New("no arguments expected, see 'ntfy serve --help' for help")
  91. }
  92. // Read all the options
  93. config := c.String("config")
  94. baseURL := c.String("base-url")
  95. listenHTTP := c.String("listen-http")
  96. listenHTTPS := c.String("listen-https")
  97. listenUnix := c.String("listen-unix")
  98. listenUnixMode := c.Int("listen-unix-mode")
  99. keyFile := c.String("key-file")
  100. certFile := c.String("cert-file")
  101. firebaseKeyFile := c.String("firebase-key-file")
  102. cacheFile := c.String("cache-file")
  103. cacheDuration := c.Duration("cache-duration")
  104. cacheStartupQueries := c.String("cache-startup-queries")
  105. cacheBatchSize := c.Int("cache-batch-size")
  106. cacheBatchTimeout := c.Duration("cache-batch-timeout")
  107. authFile := c.String("auth-file")
  108. authDefaultAccess := c.String("auth-default-access")
  109. attachmentCacheDir := c.String("attachment-cache-dir")
  110. attachmentTotalSizeLimitStr := c.String("attachment-total-size-limit")
  111. attachmentFileSizeLimitStr := c.String("attachment-file-size-limit")
  112. attachmentExpiryDuration := c.Duration("attachment-expiry-duration")
  113. keepaliveInterval := c.Duration("keepalive-interval")
  114. managerInterval := c.Duration("manager-interval")
  115. webRoot := c.String("web-root")
  116. upstreamBaseURL := c.String("upstream-base-url")
  117. smtpSenderAddr := c.String("smtp-sender-addr")
  118. smtpSenderUser := c.String("smtp-sender-user")
  119. smtpSenderPass := c.String("smtp-sender-pass")
  120. smtpSenderFrom := c.String("smtp-sender-from")
  121. smtpServerListen := c.String("smtp-server-listen")
  122. smtpServerDomain := c.String("smtp-server-domain")
  123. smtpServerAddrPrefix := c.String("smtp-server-addr-prefix")
  124. totalTopicLimit := c.Int("global-topic-limit")
  125. visitorSubscriptionLimit := c.Int("visitor-subscription-limit")
  126. visitorAttachmentTotalSizeLimitStr := c.String("visitor-attachment-total-size-limit")
  127. visitorAttachmentDailyBandwidthLimitStr := c.String("visitor-attachment-daily-bandwidth-limit")
  128. visitorRequestLimitBurst := c.Int("visitor-request-limit-burst")
  129. visitorRequestLimitReplenish := c.Duration("visitor-request-limit-replenish")
  130. visitorRequestLimitExemptHosts := util.SplitNoEmpty(c.String("visitor-request-limit-exempt-hosts"), ",")
  131. visitorEmailLimitBurst := c.Int("visitor-email-limit-burst")
  132. visitorEmailLimitReplenish := c.Duration("visitor-email-limit-replenish")
  133. behindProxy := c.Bool("behind-proxy")
  134. enableSignup := c.Bool("enable-signup")
  135. enableLogin := c.Bool("enable-login")
  136. // Check values
  137. if firebaseKeyFile != "" && !util.FileExists(firebaseKeyFile) {
  138. return errors.New("if set, FCM key file must exist")
  139. } else if keepaliveInterval < 5*time.Second {
  140. return errors.New("keepalive interval cannot be lower than five seconds")
  141. } else if managerInterval < 5*time.Second {
  142. return errors.New("manager interval cannot be lower than five seconds")
  143. } else if cacheDuration > 0 && cacheDuration < managerInterval {
  144. return errors.New("cache duration cannot be lower than manager interval")
  145. } else if keyFile != "" && !util.FileExists(keyFile) {
  146. return errors.New("if set, key file must exist")
  147. } else if certFile != "" && !util.FileExists(certFile) {
  148. return errors.New("if set, certificate file must exist")
  149. } else if listenHTTPS != "" && (keyFile == "" || certFile == "") {
  150. return errors.New("if listen-https is set, both key-file and cert-file must be set")
  151. } else if smtpSenderAddr != "" && (baseURL == "" || smtpSenderUser == "" || smtpSenderPass == "" || smtpSenderFrom == "") {
  152. return errors.New("if smtp-sender-addr is set, base-url, smtp-sender-user, smtp-sender-pass and smtp-sender-from must also be set")
  153. } else if smtpServerListen != "" && smtpServerDomain == "" {
  154. return errors.New("if smtp-server-listen is set, smtp-server-domain must also be set")
  155. } else if attachmentCacheDir != "" && baseURL == "" {
  156. return errors.New("if attachment-cache-dir is set, base-url must also be set")
  157. } else if baseURL != "" && !strings.HasPrefix(baseURL, "http://") && !strings.HasPrefix(baseURL, "https://") {
  158. return errors.New("if set, base-url must start with http:// or https://")
  159. } else if baseURL != "" && strings.HasSuffix(baseURL, "/") {
  160. return errors.New("if set, base-url must not end with a slash (/)")
  161. } else if !util.Contains([]string{"read-write", "read-only", "write-only", "deny-all"}, authDefaultAccess) {
  162. return errors.New("if set, auth-default-access must start set to 'read-write', 'read-only', 'write-only' or 'deny-all'")
  163. } else if !util.Contains([]string{"app", "home", "disable"}, webRoot) {
  164. return errors.New("if set, web-root must be 'home' or 'app'")
  165. } else if upstreamBaseURL != "" && !strings.HasPrefix(upstreamBaseURL, "http://") && !strings.HasPrefix(upstreamBaseURL, "https://") {
  166. return errors.New("if set, upstream-base-url must start with http:// or https://")
  167. } else if upstreamBaseURL != "" && strings.HasSuffix(upstreamBaseURL, "/") {
  168. return errors.New("if set, upstream-base-url must not end with a slash (/)")
  169. } else if upstreamBaseURL != "" && baseURL == "" {
  170. return errors.New("if upstream-base-url is set, base-url must also be set")
  171. } else if upstreamBaseURL != "" && baseURL != "" && baseURL == upstreamBaseURL {
  172. return errors.New("base-url and upstream-base-url cannot be identical, you'll likely want to set upstream-base-url to https://ntfy.sh, see https://ntfy.sh/docs/config/#ios-instant-notifications")
  173. }
  174. webRootIsApp := webRoot == "app"
  175. enableWeb := webRoot != "disable"
  176. // Default auth permissions
  177. authDefaultRead := authDefaultAccess == "read-write" || authDefaultAccess == "read-only"
  178. authDefaultWrite := authDefaultAccess == "read-write" || authDefaultAccess == "write-only"
  179. // Special case: Unset default
  180. if listenHTTP == "-" {
  181. listenHTTP = ""
  182. }
  183. // Convert sizes to bytes
  184. attachmentTotalSizeLimit, err := parseSize(attachmentTotalSizeLimitStr, server.DefaultAttachmentTotalSizeLimit)
  185. if err != nil {
  186. return err
  187. }
  188. attachmentFileSizeLimit, err := parseSize(attachmentFileSizeLimitStr, server.DefaultAttachmentFileSizeLimit)
  189. if err != nil {
  190. return err
  191. }
  192. visitorAttachmentTotalSizeLimit, err := parseSize(visitorAttachmentTotalSizeLimitStr, server.DefaultVisitorAttachmentTotalSizeLimit)
  193. if err != nil {
  194. return err
  195. }
  196. visitorAttachmentDailyBandwidthLimit, err := parseSize(visitorAttachmentDailyBandwidthLimitStr, server.DefaultVisitorAttachmentDailyBandwidthLimit)
  197. if err != nil {
  198. return err
  199. } else if visitorAttachmentDailyBandwidthLimit > math.MaxInt {
  200. return fmt.Errorf("config option visitor-attachment-daily-bandwidth-limit must be lower than %d", math.MaxInt)
  201. }
  202. // Resolve hosts
  203. visitorRequestLimitExemptIPs := make([]netip.Prefix, 0)
  204. for _, host := range visitorRequestLimitExemptHosts {
  205. ips, err := parseIPHostPrefix(host)
  206. if err != nil {
  207. log.Warn("cannot resolve host %s: %s, ignoring visitor request exemption", host, err.Error())
  208. continue
  209. }
  210. visitorRequestLimitExemptIPs = append(visitorRequestLimitExemptIPs, ips...)
  211. }
  212. // Run server
  213. conf := server.NewConfig()
  214. conf.BaseURL = baseURL
  215. conf.ListenHTTP = listenHTTP
  216. conf.ListenHTTPS = listenHTTPS
  217. conf.ListenUnix = listenUnix
  218. conf.ListenUnixMode = fs.FileMode(listenUnixMode)
  219. conf.KeyFile = keyFile
  220. conf.CertFile = certFile
  221. conf.FirebaseKeyFile = firebaseKeyFile
  222. conf.CacheFile = cacheFile
  223. conf.CacheDuration = cacheDuration
  224. conf.CacheStartupQueries = cacheStartupQueries
  225. conf.CacheBatchSize = cacheBatchSize
  226. conf.CacheBatchTimeout = cacheBatchTimeout
  227. conf.AuthFile = authFile
  228. conf.AuthDefaultRead = authDefaultRead
  229. conf.AuthDefaultWrite = authDefaultWrite
  230. conf.AttachmentCacheDir = attachmentCacheDir
  231. conf.AttachmentTotalSizeLimit = attachmentTotalSizeLimit
  232. conf.AttachmentFileSizeLimit = attachmentFileSizeLimit
  233. conf.AttachmentExpiryDuration = attachmentExpiryDuration
  234. conf.KeepaliveInterval = keepaliveInterval
  235. conf.ManagerInterval = managerInterval
  236. conf.WebRootIsApp = webRootIsApp
  237. conf.UpstreamBaseURL = upstreamBaseURL
  238. conf.SMTPSenderAddr = smtpSenderAddr
  239. conf.SMTPSenderUser = smtpSenderUser
  240. conf.SMTPSenderPass = smtpSenderPass
  241. conf.SMTPSenderFrom = smtpSenderFrom
  242. conf.SMTPServerListen = smtpServerListen
  243. conf.SMTPServerDomain = smtpServerDomain
  244. conf.SMTPServerAddrPrefix = smtpServerAddrPrefix
  245. conf.TotalTopicLimit = totalTopicLimit
  246. conf.VisitorSubscriptionLimit = visitorSubscriptionLimit
  247. conf.VisitorAttachmentTotalSizeLimit = visitorAttachmentTotalSizeLimit
  248. conf.VisitorAttachmentDailyBandwidthLimit = int(visitorAttachmentDailyBandwidthLimit)
  249. conf.VisitorRequestLimitBurst = visitorRequestLimitBurst
  250. conf.VisitorRequestLimitReplenish = visitorRequestLimitReplenish
  251. conf.VisitorRequestExemptIPAddrs = visitorRequestLimitExemptIPs
  252. conf.VisitorEmailLimitBurst = visitorEmailLimitBurst
  253. conf.VisitorEmailLimitReplenish = visitorEmailLimitReplenish
  254. conf.BehindProxy = behindProxy
  255. conf.EnableWeb = enableWeb
  256. conf.EnableSignup = enableSignup
  257. conf.EnableLogin = enableLogin
  258. conf.Version = c.App.Version
  259. // Set up hot-reloading of config
  260. go sigHandlerConfigReload(config)
  261. // Run server
  262. s, err := server.New(conf)
  263. if err != nil {
  264. log.Fatal(err)
  265. } else if err := s.Run(); err != nil {
  266. log.Fatal(err)
  267. }
  268. log.Info("Exiting.")
  269. return nil
  270. }
  271. func parseSize(s string, defaultValue int64) (v int64, err error) {
  272. if s == "" {
  273. return defaultValue, nil
  274. }
  275. v, err = util.ParseSize(s)
  276. if err != nil {
  277. return 0, err
  278. }
  279. return v, nil
  280. }
  281. func sigHandlerConfigReload(config string) {
  282. sigs := make(chan os.Signal, 1)
  283. signal.Notify(sigs, syscall.SIGHUP)
  284. for range sigs {
  285. log.Info("Partially hot reloading configuration ...")
  286. inputSource, err := newYamlSourceFromFile(config, flagsServe)
  287. if err != nil {
  288. log.Warn("Hot reload failed: %s", err.Error())
  289. continue
  290. }
  291. reloadLogLevel(inputSource)
  292. }
  293. }
  294. func parseIPHostPrefix(host string) (prefixes []netip.Prefix, err error) {
  295. // Try parsing as prefix, e.g. 10.0.1.0/24
  296. prefix, err := netip.ParsePrefix(host)
  297. if err == nil {
  298. prefixes = append(prefixes, prefix.Masked())
  299. return prefixes, nil
  300. }
  301. // Not a prefix, parse as host or IP (LookupHost passes through an IP as is)
  302. ips, err := net.LookupHost(host)
  303. if err != nil {
  304. return nil, err
  305. }
  306. for _, ipStr := range ips {
  307. ip, err := netip.ParseAddr(ipStr)
  308. if err == nil {
  309. prefix, err := ip.Prefix(ip.BitLen())
  310. if err != nil {
  311. return nil, fmt.Errorf("%s successfully parsed but unable to make prefix: %s", ip.String(), err.Error())
  312. }
  313. prefixes = append(prefixes, prefix.Masked())
  314. }
  315. }
  316. return
  317. }
  318. func reloadLogLevel(inputSource altsrc.InputSourceContext) {
  319. newLevelStr, err := inputSource.String("log-level")
  320. if err != nil {
  321. log.Warn("Cannot load log level: %s", err.Error())
  322. return
  323. }
  324. newLevel := log.ToLevel(newLevelStr)
  325. log.SetLevel(newLevel)
  326. log.Info("Log level is %s", newLevel.String())
  327. }