refactor: use slots and strongly typed properties

This commit is contained in:
2026-04-20 10:48:58 +02:00
parent fc7d3cb0e8
commit 5fb10ffb9d
10 changed files with 161 additions and 91 deletions
+75 -45
View File
@@ -9,10 +9,14 @@ import re
import tarfile
import typing
from . import STAPLER_ASCII, data_dir, logs, project
from . import STAPLER_ASCII, logs, project
from .data_dir import DataDir
if typing.TYPE_CHECKING:
from . import cert_manager, params, registry, token_manager
from .cert_manager import CertManager
from .params import Parameters
from .registry import Registry
from .token_manager import TokenManager
class BaseHandler(abc.ABC, http.server.BaseHTTPRequestHandler):
@@ -20,12 +24,14 @@ class BaseHandler(abc.ABC, http.server.BaseHTTPRequestHandler):
def __init__(
self,
*args: typing.Any,
params: params.Parameters,
params: Parameters,
**kwargs: dict[str, typing.Any],
) -> None:
self.logger = logging.getLogger(self.__class__.__name__)
self.default_host = params.host.split(":", maxsplit=2)[0]
self.out_size = 0
self.logger: logging.Logger = logging.getLogger(self.__class__.__name__)
self.default_host: str = params.host.split(":", maxsplit=2)[0]
self.out_size: int = 0
self._host: str | None = None
self._in_size: int | None = None
super().__init__(*args, **kwargs)
@typing.override
@@ -74,7 +80,7 @@ class BaseHandler(abc.ABC, http.server.BaseHTTPRequestHandler):
code = color + str(code.value) + logs.TermColor.RESET
if size == "" and self.out_size > 0:
size = str(self.out_size)
args = (code, self.address_string(), self._get_host(), self.requestline)
args = (code, self.address_string(), self.host, self.requestline)
fmt = "%s - %s - %s - %s"
if size != "":
args = (*args, size)
@@ -117,10 +123,22 @@ class BaseHandler(abc.ABC, http.server.BaseHTTPRequestHandler):
self.end_headers()
self.close_connection = True
@property
def host(self) -> str:
if self._host is None:
self._host = self._get_host()
return self._host
def _get_host(self) -> str:
host = self._get_header("Host", self.default_host)
return host.split(":", maxsplit=2)[0]
@property
def in_size(self) -> int:
if self._in_size is None:
self._in_size = self._get_length()
return self._in_size
def _get_length(self) -> int:
return int(self._get_header("Content-Length", "0"))
@@ -137,10 +155,10 @@ class BaseHandler(abc.ABC, http.server.BaseHTTPRequestHandler):
)
def _pre_log_request(self) -> None: # pragma: no cover
args = ("...", self.address_string(), self._get_host(), self.requestline)
args = ("...", self.address_string(), self.host, self.requestline)
fmt = "%s - %s - %s - %s"
if (size := self._get_length()) > 0:
args = (*args, size)
if self.in_size > 0:
args = (*args, self.in_size)
fmt += " - %s"
self.logger.debug(fmt, *args)
@@ -163,21 +181,39 @@ class RequestHandler(http.server.SimpleHTTPRequestHandler, BaseHandler):
def __init__(
self,
*args: typing.Any,
params: params.Parameters,
registry: registry.Registry,
cert_manager: cert_manager.CertManager,
token_manager: token_manager.TokenManager,
params: Parameters,
registry: Registry,
cert_manager: CertManager,
token_manager: TokenManager,
**kwargs: dict[str, typing.Any],
) -> None:
self.logger = logging.getLogger(self.__class__.__name__)
self.token_manager = token_manager
self.data_dir = data_dir.DataDir(params.data_dir)
self.max_size_bytes = params.max_size_bytes
self.registry = registry
self.cert_manager = cert_manager
self.certbot_www = os.path.realpath(params.certbot_www)
self.logger: logging.Logger = logging.getLogger(self.__class__.__name__)
self.token_manager: TokenManager = token_manager
self.data_dir: DataDir = DataDir(params.data_dir)
self.max_size_bytes: int = params.max_size_bytes
self.registry: Registry = registry
self.cert_manager: CertManager = cert_manager
self.certbot_www: str = os.path.realpath(params.certbot_www)
self._token: str | None = None
self._target_host: str | None = None
super().__init__(*args, directory=params.data_dir, **kwargs, params=params) # ty:ignore[unknown-argument]
@property
def token(self) -> str:
if self._token is None:
self._token = self._get_header(self.TOKEN_HEADER)
return self._token
@property
def target_host(self) -> str:
if self._target_host is None:
self._target_host = self._get_header(self.HOST_HEADER).lower()
return self._target_host
@property
def has_target_host(self) -> bool:
return len(self.target_host) > 0
@typing.override
def do_HEAD(self) -> None:
self._pre_log_request()
@@ -186,7 +222,7 @@ class RequestHandler(http.server.SimpleHTTPRequestHandler, BaseHandler):
@typing.override
def do_GET(self) -> None:
self._pre_log_request()
if self.path == "/" and self._get_host() == self.default_host:
if self.path == "/" and self.host == self.default_host:
return self.send_basic_body(self.server_signature())
super().do_GET()
return None
@@ -195,30 +231,25 @@ class RequestHandler(http.server.SimpleHTTPRequestHandler, BaseHandler):
self._pre_log_request()
if (sub_path := self.__check_update_request()) is None:
return None
host: str | None = (
self._get_header(self.HOST_HEADER).lower()
if self._has_header(self.HOST_HEADER)
else None
)
if host is not None and not self.__valid_host(host):
if self.has_target_host and not self.__valid_host(self.target_host):
return self.send_error(
http.HTTPStatus.BAD_REQUEST, "Invalid requested host"
)
if (
host is not None
and (page := self.registry.get_from_host(host)) is not None
self.has_target_host
and (page := self.registry.get_from_host(self.target_host)) is not None
and page.path != sub_path
):
return self.send_error(http.HTTPStatus.FORBIDDEN, "Host already taken")
if (content_length := self._get_length()) == 0:
if self.in_size == 0:
return self.send_error(http.HTTPStatus.LENGTH_REQUIRED, "No body found")
if content_length > self.max_size_bytes:
if self.in_size > self.max_size_bytes:
return self.send_error(
http.HTTPStatus.CONTENT_TOO_LARGE,
"Archive too large",
)
try:
file_bytes = io.BytesIO(self.rfile.read(content_length))
file_bytes = io.BytesIO(self.rfile.read(self.in_size))
self.data_dir.extract_tar_bytes(sub_path, file_bytes)
except tarfile.TarError:
return self.send_error(http.HTTPStatus.BAD_REQUEST, "Invalid tar archive")
@@ -229,9 +260,11 @@ class RequestHandler(http.server.SimpleHTTPRequestHandler, BaseHandler):
f"Resource /{sub_path}/ updated",
)
self.registry.add(sub_path)
self.token_manager.set_token(self._get_header(self.TOKEN_HEADER), sub_path)
if host is not None and self.cert_manager.create_or_update(host):
self.registry.set_host(sub_path, host)
self.token_manager.set_token(self.token, sub_path)
if self.has_target_host and self.cert_manager.create_or_update(
self.target_host
):
self.registry.set_host(sub_path, self.target_host)
return None
def do_DELETE(self) -> None:
@@ -261,14 +294,12 @@ class RequestHandler(http.server.SimpleHTTPRequestHandler, BaseHandler):
def translate_path(self, path: str) -> str:
if path.startswith(self.CERTBOT_CHALLENGE_PATH):
return self.certbot_www + path
host = self._get_host()
if (
host != self.default_host
and (page := self.registry.get_from_host(host := self._get_host()))
is not None
self.host != self.default_host
and (page := self.registry.get_from_host(self.host)) is not None
):
path = f"/{page.path}" + path
elif host != self.default_host:
elif self.host != self.default_host:
return ""
elif (
path not in self.AUTHORIZED_PATHS
@@ -283,14 +314,13 @@ class RequestHandler(http.server.SimpleHTTPRequestHandler, BaseHandler):
if not self._has_header(self.TOKEN_HEADER):
self.send_error(http.HTTPStatus.BAD_REQUEST, "No X-Token header in request")
return None
token = self._get_header(self.TOKEN_HEADER)
if not self.token_manager.is_valid(token):
if not self.token_manager.is_valid(self.token):
self.send_error(http.HTTPStatus.UNAUTHORIZED, "Invalid token")
return None
if (sub_path := self.__get_subpath(self.path, self.UPDATE_PATH_REGEX)) is None:
self.send_error(http.HTTPStatus.BAD_REQUEST, "Invalid path")
return None
if not self.token_manager.is_valid_for_path(token, sub_path):
if not self.token_manager.is_valid_for_path(self.token, sub_path):
self.send_error(http.HTTPStatus.FORBIDDEN, "Path forbidden for this token")
return None
return sub_path
@@ -314,7 +344,7 @@ class UpgradeHandler(BaseHandler):
self._pre_log_request()
self.send_status_only(
http.HTTPStatus.MOVED_PERMANENTLY,
headers={"Location": f"https://{self._get_host()}{self.path.lower()}"},
headers={"Location": f"https://{self.host}{self.path.lower()}"},
)
def do_GET(self) -> None: