serve.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206
  1. package cmd
  2. import (
  3. "errors"
  4. "fmt"
  5. "github.com/urfave/cli/v2"
  6. "github.com/urfave/cli/v2/altsrc"
  7. "heckel.io/ntfy/server"
  8. "heckel.io/ntfy/util"
  9. "log"
  10. "math"
  11. "time"
  12. )
  13. var flagsServe = []cli.Flag{
  14. &cli.StringFlag{Name: "config", Aliases: []string{"c"}, EnvVars: []string{"NTFY_CONFIG_FILE"}, Value: "/etc/ntfy/server.yml", DefaultText: "/etc/ntfy/server.yml", Usage: "config file"},
  15. altsrc.NewStringFlag(&cli.StringFlag{Name: "base-url", Aliases: []string{"B"}, EnvVars: []string{"NTFY_BASE_URL"}, Usage: "externally visible base URL for this host (e.g. https://ntfy.sh)"}),
  16. altsrc.NewStringFlag(&cli.StringFlag{Name: "listen-http", Aliases: []string{"l"}, EnvVars: []string{"NTFY_LISTEN_HTTP"}, Value: server.DefaultListenHTTP, Usage: "ip:port used to as HTTP listen address"}),
  17. altsrc.NewStringFlag(&cli.StringFlag{Name: "listen-https", Aliases: []string{"L"}, EnvVars: []string{"NTFY_LISTEN_HTTPS"}, Usage: "ip:port used to as HTTPS listen address"}),
  18. altsrc.NewStringFlag(&cli.StringFlag{Name: "listen-unix", Aliases: []string{"U"}, EnvVars: []string{"NTFY_LISTEN_UNIX"}, Usage: "listen on unix socket path"}),
  19. altsrc.NewStringFlag(&cli.StringFlag{Name: "key-file", Aliases: []string{"K"}, EnvVars: []string{"NTFY_KEY_FILE"}, Usage: "private key file, if listen-https is set"}),
  20. altsrc.NewStringFlag(&cli.StringFlag{Name: "cert-file", Aliases: []string{"E"}, EnvVars: []string{"NTFY_CERT_FILE"}, Usage: "certificate file, if listen-https is set"}),
  21. altsrc.NewStringFlag(&cli.StringFlag{Name: "firebase-key-file", Aliases: []string{"F"}, EnvVars: []string{"NTFY_FIREBASE_KEY_FILE"}, Usage: "Firebase credentials file; if set additionally publish to FCM topic"}),
  22. altsrc.NewStringFlag(&cli.StringFlag{Name: "cache-file", Aliases: []string{"C"}, EnvVars: []string{"NTFY_CACHE_FILE"}, Usage: "cache file used for message caching"}),
  23. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "cache-duration", Aliases: []string{"b"}, EnvVars: []string{"NTFY_CACHE_DURATION"}, Value: server.DefaultCacheDuration, Usage: "buffer messages for this time to allow `since` requests"}),
  24. altsrc.NewStringFlag(&cli.StringFlag{Name: "attachment-cache-dir", EnvVars: []string{"NTFY_ATTACHMENT_CACHE_DIR"}, Usage: "cache directory for attached files"}),
  25. altsrc.NewStringFlag(&cli.StringFlag{Name: "attachment-total-size-limit", Aliases: []string{"A"}, EnvVars: []string{"NTFY_ATTACHMENT_TOTAL_SIZE_LIMIT"}, DefaultText: "5G", Usage: "limit of the on-disk attachment cache"}),
  26. altsrc.NewStringFlag(&cli.StringFlag{Name: "attachment-file-size-limit", Aliases: []string{"Y"}, EnvVars: []string{"NTFY_ATTACHMENT_FILE_SIZE_LIMIT"}, DefaultText: "15M", Usage: "per-file attachment size limit (e.g. 300k, 2M, 100M)"}),
  27. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "attachment-expiry-duration", Aliases: []string{"X"}, EnvVars: []string{"NTFY_ATTACHMENT_EXPIRY_DURATION"}, Value: server.DefaultAttachmentExpiryDuration, DefaultText: "3h", Usage: "duration after which uploaded attachments will be deleted (e.g. 3h, 20h)"}),
  28. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "keepalive-interval", Aliases: []string{"k"}, EnvVars: []string{"NTFY_KEEPALIVE_INTERVAL"}, Value: server.DefaultKeepaliveInterval, Usage: "interval of keepalive messages"}),
  29. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "manager-interval", Aliases: []string{"m"}, EnvVars: []string{"NTFY_MANAGER_INTERVAL"}, Value: server.DefaultManagerInterval, Usage: "interval of for message pruning and stats printing"}),
  30. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-addr", EnvVars: []string{"NTFY_SMTP_SENDER_ADDR"}, Usage: "SMTP server address (host:port) for outgoing emails"}),
  31. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-user", EnvVars: []string{"NTFY_SMTP_SENDER_USER"}, Usage: "SMTP user (if e-mail sending is enabled)"}),
  32. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-pass", EnvVars: []string{"NTFY_SMTP_SENDER_PASS"}, Usage: "SMTP password (if e-mail sending is enabled)"}),
  33. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-from", EnvVars: []string{"NTFY_SMTP_SENDER_FROM"}, Usage: "SMTP sender address (if e-mail sending is enabled)"}),
  34. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-server-listen", EnvVars: []string{"NTFY_SMTP_SERVER_LISTEN"}, Usage: "SMTP server address (ip:port) for incoming emails, e.g. :25"}),
  35. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-server-domain", EnvVars: []string{"NTFY_SMTP_SERVER_DOMAIN"}, Usage: "SMTP domain for incoming e-mail, e.g. ntfy.sh"}),
  36. altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-server-addr-prefix", EnvVars: []string{"NTFY_SMTP_SERVER_ADDR_PREFIX"}, Usage: "SMTP email address prefix for topics to prevent spam (e.g. 'ntfy-')"}),
  37. altsrc.NewIntFlag(&cli.IntFlag{Name: "global-topic-limit", Aliases: []string{"T"}, EnvVars: []string{"NTFY_GLOBAL_TOPIC_LIMIT"}, Value: server.DefaultTotalTopicLimit, Usage: "total number of topics allowed"}),
  38. altsrc.NewIntFlag(&cli.IntFlag{Name: "visitor-subscription-limit", EnvVars: []string{"NTFY_VISITOR_SUBSCRIPTION_LIMIT"}, Value: server.DefaultVisitorSubscriptionLimit, Usage: "number of subscriptions per visitor"}),
  39. altsrc.NewStringFlag(&cli.StringFlag{Name: "visitor-attachment-total-size-limit", EnvVars: []string{"NTFY_VISITOR_ATTACHMENT_TOTAL_SIZE_LIMIT"}, Value: "100M", Usage: "total storage limit used for attachments per visitor"}),
  40. altsrc.NewStringFlag(&cli.StringFlag{Name: "visitor-attachment-daily-bandwidth-limit", EnvVars: []string{"NTFY_VISITOR_ATTACHMENT_DAILY_BANDWIDTH_LIMIT"}, Value: "500M", Usage: "total daily attachment download/upload bandwidth limit per visitor"}),
  41. altsrc.NewIntFlag(&cli.IntFlag{Name: "visitor-request-limit-burst", EnvVars: []string{"NTFY_VISITOR_REQUEST_LIMIT_BURST"}, Value: server.DefaultVisitorRequestLimitBurst, Usage: "initial limit of requests per visitor"}),
  42. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "visitor-request-limit-replenish", EnvVars: []string{"NTFY_VISITOR_REQUEST_LIMIT_REPLENISH"}, Value: server.DefaultVisitorRequestLimitReplenish, Usage: "interval at which burst limit is replenished (one per x)"}),
  43. altsrc.NewIntFlag(&cli.IntFlag{Name: "visitor-email-limit-burst", EnvVars: []string{"NTFY_VISITOR_EMAIL_LIMIT_BURST"}, Value: server.DefaultVisitorEmailLimitBurst, Usage: "initial limit of e-mails per visitor"}),
  44. altsrc.NewDurationFlag(&cli.DurationFlag{Name: "visitor-email-limit-replenish", EnvVars: []string{"NTFY_VISITOR_EMAIL_LIMIT_REPLENISH"}, Value: server.DefaultVisitorEmailLimitReplenish, Usage: "interval at which burst limit is replenished (one per x)"}),
  45. altsrc.NewBoolFlag(&cli.BoolFlag{Name: "behind-proxy", Aliases: []string{"P"}, EnvVars: []string{"NTFY_BEHIND_PROXY"}, Value: false, Usage: "if set, use X-Forwarded-For header to determine visitor IP address (for rate limiting)"}),
  46. }
  47. var cmdServe = &cli.Command{
  48. Name: "serve",
  49. Usage: "Run the ntfy server",
  50. UsageText: "ntfy serve [OPTIONS..]",
  51. Action: execServe,
  52. Flags: flagsServe,
  53. Before: initConfigFileInputSource("config", flagsServe),
  54. Description: `Run the ntfy server and listen for incoming requests
  55. The command will load the configuration from /etc/ntfy/server.yml. Config options can
  56. be overridden using the command line options.
  57. Examples:
  58. ntfy serve # Starts server in the foreground (on port 80)
  59. ntfy serve --listen-http :8080 # Starts server with alternate port`,
  60. }
  61. func execServe(c *cli.Context) error {
  62. if c.NArg() > 0 {
  63. return errors.New("no arguments expected, see 'ntfy serve --help' for help")
  64. }
  65. // Read all the options
  66. baseURL := c.String("base-url")
  67. listenHTTP := c.String("listen-http")
  68. listenHTTPS := c.String("listen-https")
  69. listenUnix := c.String("listen-unix")
  70. keyFile := c.String("key-file")
  71. certFile := c.String("cert-file")
  72. firebaseKeyFile := c.String("firebase-key-file")
  73. cacheFile := c.String("cache-file")
  74. cacheDuration := c.Duration("cache-duration")
  75. attachmentCacheDir := c.String("attachment-cache-dir")
  76. attachmentTotalSizeLimitStr := c.String("attachment-total-size-limit")
  77. attachmentFileSizeLimitStr := c.String("attachment-file-size-limit")
  78. attachmentExpiryDuration := c.Duration("attachment-expiry-duration")
  79. keepaliveInterval := c.Duration("keepalive-interval")
  80. managerInterval := c.Duration("manager-interval")
  81. smtpSenderAddr := c.String("smtp-sender-addr")
  82. smtpSenderUser := c.String("smtp-sender-user")
  83. smtpSenderPass := c.String("smtp-sender-pass")
  84. smtpSenderFrom := c.String("smtp-sender-from")
  85. smtpServerListen := c.String("smtp-server-listen")
  86. smtpServerDomain := c.String("smtp-server-domain")
  87. smtpServerAddrPrefix := c.String("smtp-server-addr-prefix")
  88. totalTopicLimit := c.Int("global-topic-limit")
  89. visitorSubscriptionLimit := c.Int("visitor-subscription-limit")
  90. visitorAttachmentTotalSizeLimitStr := c.String("visitor-attachment-total-size-limit")
  91. visitorAttachmentDailyBandwidthLimitStr := c.String("visitor-attachment-daily-bandwidth-limit")
  92. visitorRequestLimitBurst := c.Int("visitor-request-limit-burst")
  93. visitorRequestLimitReplenish := c.Duration("visitor-request-limit-replenish")
  94. visitorEmailLimitBurst := c.Int("visitor-email-limit-burst")
  95. visitorEmailLimitReplenish := c.Duration("visitor-email-limit-replenish")
  96. behindProxy := c.Bool("behind-proxy")
  97. // Check values
  98. if firebaseKeyFile != "" && !util.FileExists(firebaseKeyFile) {
  99. return errors.New("if set, FCM key file must exist")
  100. } else if keepaliveInterval < 5*time.Second {
  101. return errors.New("keepalive interval cannot be lower than five seconds")
  102. } else if managerInterval < 5*time.Second {
  103. return errors.New("manager interval cannot be lower than five seconds")
  104. } else if cacheDuration > 0 && cacheDuration < managerInterval {
  105. return errors.New("cache duration cannot be lower than manager interval")
  106. } else if keyFile != "" && !util.FileExists(keyFile) {
  107. return errors.New("if set, key file must exist")
  108. } else if certFile != "" && !util.FileExists(certFile) {
  109. return errors.New("if set, certificate file must exist")
  110. } else if listenHTTPS != "" && (keyFile == "" || certFile == "") {
  111. return errors.New("if listen-https is set, both key-file and cert-file must be set")
  112. } else if smtpSenderAddr != "" && (baseURL == "" || smtpSenderUser == "" || smtpSenderPass == "" || smtpSenderFrom == "") {
  113. return errors.New("if smtp-sender-addr is set, base-url, smtp-sender-user, smtp-sender-pass and smtp-sender-from must also be set")
  114. } else if smtpServerListen != "" && smtpServerDomain == "" {
  115. return errors.New("if smtp-server-listen is set, smtp-server-domain must also be set")
  116. } else if attachmentCacheDir != "" && baseURL == "" {
  117. return errors.New("if attachment-cache-dir is set, base-url must also be set")
  118. }
  119. // Special case: Unset default
  120. if listenHTTP == "-" {
  121. listenHTTP = ""
  122. }
  123. // Convert sizes to bytes
  124. attachmentTotalSizeLimit, err := parseSize(attachmentTotalSizeLimitStr, server.DefaultAttachmentTotalSizeLimit)
  125. if err != nil {
  126. return err
  127. }
  128. attachmentFileSizeLimit, err := parseSize(attachmentFileSizeLimitStr, server.DefaultAttachmentFileSizeLimit)
  129. if err != nil {
  130. return err
  131. }
  132. visitorAttachmentTotalSizeLimit, err := parseSize(visitorAttachmentTotalSizeLimitStr, server.DefaultVisitorAttachmentTotalSizeLimit)
  133. if err != nil {
  134. return err
  135. }
  136. visitorAttachmentDailyBandwidthLimit, err := parseSize(visitorAttachmentDailyBandwidthLimitStr, server.DefaultVisitorAttachmentDailyBandwidthLimit)
  137. if err != nil {
  138. return err
  139. } else if visitorAttachmentDailyBandwidthLimit > math.MaxInt {
  140. return fmt.Errorf("config option visitor-attachment-daily-bandwidth-limit must be lower than %d", math.MaxInt)
  141. }
  142. // Run server
  143. conf := server.NewConfig()
  144. conf.BaseURL = baseURL
  145. conf.ListenHTTP = listenHTTP
  146. conf.ListenHTTPS = listenHTTPS
  147. conf.ListenUnix = listenUnix
  148. conf.KeyFile = keyFile
  149. conf.CertFile = certFile
  150. conf.FirebaseKeyFile = firebaseKeyFile
  151. conf.CacheFile = cacheFile
  152. conf.CacheDuration = cacheDuration
  153. conf.AttachmentCacheDir = attachmentCacheDir
  154. conf.AttachmentTotalSizeLimit = attachmentTotalSizeLimit
  155. conf.AttachmentFileSizeLimit = attachmentFileSizeLimit
  156. conf.AttachmentExpiryDuration = attachmentExpiryDuration
  157. conf.KeepaliveInterval = keepaliveInterval
  158. conf.ManagerInterval = managerInterval
  159. conf.SMTPSenderAddr = smtpSenderAddr
  160. conf.SMTPSenderUser = smtpSenderUser
  161. conf.SMTPSenderPass = smtpSenderPass
  162. conf.SMTPSenderFrom = smtpSenderFrom
  163. conf.SMTPServerListen = smtpServerListen
  164. conf.SMTPServerDomain = smtpServerDomain
  165. conf.SMTPServerAddrPrefix = smtpServerAddrPrefix
  166. conf.TotalTopicLimit = totalTopicLimit
  167. conf.VisitorSubscriptionLimit = visitorSubscriptionLimit
  168. conf.VisitorAttachmentTotalSizeLimit = visitorAttachmentTotalSizeLimit
  169. conf.VisitorAttachmentDailyBandwidthLimit = int(visitorAttachmentDailyBandwidthLimit)
  170. conf.VisitorRequestLimitBurst = visitorRequestLimitBurst
  171. conf.VisitorRequestLimitReplenish = visitorRequestLimitReplenish
  172. conf.VisitorEmailLimitBurst = visitorEmailLimitBurst
  173. conf.VisitorEmailLimitReplenish = visitorEmailLimitReplenish
  174. conf.BehindProxy = behindProxy
  175. s, err := server.New(conf)
  176. if err != nil {
  177. log.Fatalln(err)
  178. }
  179. if err := s.Run(); err != nil {
  180. log.Fatalln(err)
  181. }
  182. log.Printf("Exiting.")
  183. return nil
  184. }
  185. func parseSize(s string, defaultValue int64) (v int64, err error) {
  186. if s == "" {
  187. return defaultValue, nil
  188. }
  189. v, err = util.ParseSize(s)
  190. if err != nil {
  191. return 0, err
  192. }
  193. return v, nil
  194. }