2021-12-03 01:58:37 +00:00
|
|
|
package domain
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"net"
|
2021-12-25 18:53:49 +00:00
|
|
|
"net/url"
|
2021-12-03 01:58:37 +00:00
|
|
|
"strings"
|
|
|
|
"testing"
|
|
|
|
|
|
|
|
"github.com/stretchr/testify/require"
|
|
|
|
http "github.com/valyala/fasthttp"
|
2021-12-25 18:53:49 +00:00
|
|
|
"golang.org/x/xerrors"
|
2021-12-03 01:58:37 +00:00
|
|
|
)
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
// Me is a URL user identifier.
|
2021-12-03 01:58:37 +00:00
|
|
|
type Me struct {
|
2021-12-25 18:53:49 +00:00
|
|
|
me *http.URI
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
func NewMe(raw string) (*Me, error) {
|
|
|
|
me := http.AcquireURI()
|
|
|
|
if err := me.Parse(nil, []byte(raw)); err != nil {
|
|
|
|
return nil, Error{
|
|
|
|
Code: "invalid_request",
|
|
|
|
Description: err.Error(),
|
|
|
|
URI: "https://indieauth.net/source/#user-profile-url",
|
|
|
|
Frame: xerrors.Caller(1),
|
|
|
|
}
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
scheme := string(me.Scheme())
|
2021-12-03 01:58:37 +00:00
|
|
|
if scheme != "http" && scheme != "https" {
|
2021-12-25 18:53:49 +00:00
|
|
|
return nil, Error{
|
|
|
|
Code: "invalid_request",
|
|
|
|
Description: "profile URL MUST have either an https or http scheme",
|
|
|
|
URI: "https://indieauth.net/source/#user-profile-url",
|
|
|
|
Frame: xerrors.Caller(1),
|
|
|
|
}
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
path := string(me.PathOriginal())
|
2021-12-03 01:58:37 +00:00
|
|
|
if path == "" || strings.Contains(path, "/.") || strings.Contains(path, "/..") {
|
2021-12-25 18:53:49 +00:00
|
|
|
return nil, Error{
|
|
|
|
Code: "invalid_request",
|
|
|
|
Description: "profile URL MUST contain a path component (/ is a valid path), MUST NOT " +
|
|
|
|
"contain single-dot or double-dot path segments",
|
|
|
|
URI: "https://indieauth.net/source/#user-profile-url",
|
|
|
|
Frame: xerrors.Caller(1),
|
|
|
|
}
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
if me.Hash() != nil {
|
|
|
|
return nil, Error{
|
|
|
|
Code: "invalid_request",
|
|
|
|
Description: "profile URL MUST NOT contain a fragment component",
|
|
|
|
URI: "https://indieauth.net/source/#user-profile-url",
|
|
|
|
Frame: xerrors.Caller(1),
|
|
|
|
}
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
if me.Username() != nil || me.Password() != nil {
|
|
|
|
return nil, Error{
|
|
|
|
Code: "invalid_request",
|
|
|
|
Description: "profile URL MUST NOT contain a username or password component",
|
|
|
|
URI: "https://indieauth.net/source/#user-profile-url",
|
|
|
|
Frame: xerrors.Caller(1),
|
|
|
|
}
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
domain := string(me.Host())
|
|
|
|
if domain == "" {
|
|
|
|
return nil, Error{
|
|
|
|
Code: "invalid_request",
|
|
|
|
Description: "profile host name MUST be a domain name",
|
|
|
|
URI: "https://indieauth.net/source/#user-profile-url",
|
|
|
|
Frame: xerrors.Caller(1),
|
|
|
|
}
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
if _, port, _ := net.SplitHostPort(domain); port != "" {
|
|
|
|
return nil, Error{
|
|
|
|
Code: "invalid_request",
|
|
|
|
Description: "profile MUST NOT contain a port",
|
|
|
|
URI: "https://indieauth.net/source/#user-profile-url",
|
|
|
|
Frame: xerrors.Caller(1),
|
|
|
|
}
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
if net.ParseIP(domain) != nil {
|
|
|
|
return nil, Error{
|
|
|
|
Code: "invalid_request",
|
|
|
|
Description: "profile MUST NOT be ipv4 or ipv6 addresses",
|
|
|
|
URI: "https://indieauth.net/source/#user-profile-url",
|
|
|
|
Frame: xerrors.Caller(1),
|
|
|
|
}
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
return &Me{me: me}, nil
|
|
|
|
}
|
2021-12-03 01:58:37 +00:00
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
// TestMe returns a valid random generated Me for tests.
|
|
|
|
func TestMe(tb testing.TB) *Me {
|
|
|
|
tb.Helper()
|
|
|
|
|
|
|
|
me, err := NewMe("https://user.example.net/")
|
|
|
|
require.NoError(tb, err)
|
|
|
|
|
|
|
|
return me
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
// UnmarshalForm parses the value of the form key into the Me domain.
|
|
|
|
func (m *Me) UnmarshalForm(v []byte) (err error) {
|
|
|
|
me, err := NewMe(string(v))
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("UnmarshalForm: %w", err)
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
2021-12-25 18:53:49 +00:00
|
|
|
defer http.ReleaseURI(me.me) //nolint: wsl
|
2021-12-03 01:58:37 +00:00
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
me.me.CopyTo(m.me)
|
|
|
|
|
|
|
|
return nil
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
// URI returns copy of parsed Me in *fasthttp.URI representation.
|
2021-12-03 01:58:37 +00:00
|
|
|
// This copy MUST be released via fasthttp.ReleaseURI.
|
2021-12-25 18:53:49 +00:00
|
|
|
func (m *Me) URI() *http.URI {
|
2021-12-03 01:58:37 +00:00
|
|
|
u := http.AcquireURI()
|
2021-12-25 18:53:49 +00:00
|
|
|
m.me.CopyTo(u)
|
2021-12-03 01:58:37 +00:00
|
|
|
|
|
|
|
return u
|
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
// URL returns copy of parsed Me in *url.URL representation.
|
|
|
|
func (m *Me) URL() *url.URL {
|
|
|
|
return &url.URL{
|
|
|
|
Scheme: string(m.me.Scheme()),
|
|
|
|
Host: string(m.me.Host()),
|
|
|
|
Path: string(m.me.Path()),
|
|
|
|
RawPath: string(m.me.PathOriginal()),
|
|
|
|
RawQuery: string(m.me.QueryString()),
|
|
|
|
Fragment: string(m.me.Hash()),
|
|
|
|
}
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|
|
|
|
|
2021-12-25 18:53:49 +00:00
|
|
|
// String returns string representation of Me.
|
|
|
|
func (m Me) String() string {
|
|
|
|
return m.me.String()
|
2021-12-03 01:58:37 +00:00
|
|
|
}
|