Você não pode selecionar mais de 25 tópicos Os tópicos devem começar com uma letra ou um número, podem incluir traços ('-') e podem ter até 35 caracteres.
 
 
 
 
 
 

96 linhas
3.3 KiB

  1. # Copyright 2014-2016 OpenMarket Ltd
  2. # Copyright 2020-2021 The Matrix.org Foundation C.I.C.
  3. #
  4. # Licensed under the Apache License, Version 2.0 (the "License");
  5. # you may not use this file except in compliance with the License.
  6. # You may obtain a copy of the License at
  7. #
  8. # http://www.apache.org/licenses/LICENSE-2.0
  9. #
  10. # Unless required by applicable law or agreed to in writing, software
  11. # distributed under the License is distributed on an "AS IS" BASIS,
  12. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. # See the License for the specific language governing permissions and
  14. # limitations under the License.
  15. import logging
  16. import re
  17. from typing import TYPE_CHECKING, Optional
  18. from synapse.http.server import set_corp_headers, set_cors_headers
  19. from synapse.http.servlet import RestServlet, parse_boolean, parse_integer
  20. from synapse.http.site import SynapseRequest
  21. from synapse.media._base import (
  22. DEFAULT_MAX_TIMEOUT_MS,
  23. MAXIMUM_ALLOWED_MAX_TIMEOUT_MS,
  24. respond_404,
  25. )
  26. from synapse.util.stringutils import parse_and_validate_server_name
  27. if TYPE_CHECKING:
  28. from synapse.media.media_repository import MediaRepository
  29. from synapse.server import HomeServer
  30. logger = logging.getLogger(__name__)
  31. class DownloadResource(RestServlet):
  32. PATTERNS = [
  33. re.compile(
  34. "/_matrix/media/(r0|v3|v1)/download/(?P<server_name>[^/]*)/(?P<media_id>[^/]*)(/(?P<file_name>[^/]*))?$"
  35. )
  36. ]
  37. def __init__(self, hs: "HomeServer", media_repo: "MediaRepository"):
  38. super().__init__()
  39. self.media_repo = media_repo
  40. self._is_mine_server_name = hs.is_mine_server_name
  41. async def on_GET(
  42. self,
  43. request: SynapseRequest,
  44. server_name: str,
  45. media_id: str,
  46. file_name: Optional[str] = None,
  47. ) -> None:
  48. # Validate the server name, raising if invalid
  49. parse_and_validate_server_name(server_name)
  50. set_cors_headers(request)
  51. set_corp_headers(request)
  52. request.setHeader(
  53. b"Content-Security-Policy",
  54. b"sandbox;"
  55. b" default-src 'none';"
  56. b" script-src 'none';"
  57. b" plugin-types application/pdf;"
  58. b" style-src 'unsafe-inline';"
  59. b" media-src 'self';"
  60. b" object-src 'self';",
  61. )
  62. # Limited non-standard form of CSP for IE11
  63. request.setHeader(b"X-Content-Security-Policy", b"sandbox;")
  64. request.setHeader(b"Referrer-Policy", b"no-referrer")
  65. max_timeout_ms = parse_integer(
  66. request, "timeout_ms", default=DEFAULT_MAX_TIMEOUT_MS
  67. )
  68. max_timeout_ms = min(max_timeout_ms, MAXIMUM_ALLOWED_MAX_TIMEOUT_MS)
  69. if self._is_mine_server_name(server_name):
  70. await self.media_repo.get_local_media(
  71. request, media_id, file_name, max_timeout_ms
  72. )
  73. else:
  74. allow_remote = parse_boolean(request, "allow_remote", default=True)
  75. if not allow_remote:
  76. logger.info(
  77. "Rejecting request for remote media %s/%s due to allow_remote",
  78. server_name,
  79. media_id,
  80. )
  81. respond_404(request)
  82. return
  83. await self.media_repo.get_remote_media(
  84. request, server_name, media_id, file_name, max_timeout_ms
  85. )