forked from patrickhener/goshs
-
Notifications
You must be signed in to change notification settings - Fork 0
/
main.go
245 lines (211 loc) · 6.86 KB
/
main.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
package main
import (
"flag"
"fmt"
"math/rand"
"os"
"os/signal"
"path/filepath"
"strings"
"syscall"
"time"
"github.com/patrickhener/goshs/httpserver"
"github.com/patrickhener/goshs/logger"
"github.com/patrickhener/goshs/utils"
)
const goshsVersion = "v0.3.6"
var (
port = 8000
ip = "0.0.0.0"
cli = false
webroot = "."
ssl = false
selfsigned = false
myKey = ""
myCert = ""
basicAuth = ""
webdav = false
webdavPort = 8001
uploadOnly = false
readOnly = false
verbose = false
silent = false
dropuser = ""
)
// Man page
func usage() func() {
return func() {
fmt.Printf(`
goshs %s
Usage: %s [options]
Web server options:
-i, --ip The ip/if-name to listen on (default: 0.0.0.0)
-p, --port The port to listen on (default: 8000)
-d, --dir The web root directory (default: current working path)
-w, --webdav Also serve using webdav protocol (default: false)
-wp, --webdav-port The port to listen on for webdav (default: 8001)
-ro, --read-only Read only mode, no upload possible (default: false)
-uo, --upload-only Upload only mode, no download possible (default: false)
-si, --silent Running without dir listing (default: false)
-c, --cli Enable cli (only with auth and tls) (default: false)
TLS options:
-s, --ssl Use TLS
-ss, --self-signed Use a self-signed certificate
-sk, --server-key Path to server key
-sc, --server-cert Path to server certificate
Authentication options:
-b, --basic-auth Use basic authentication (user:pass - user can be empty)
-H, --hash Hash a password for file based ACLs
Misc options:
-u --user Drop privs to user (unix only) (default: current user)
-V --verbose Activate verbose log output (default: false)
-v Print the current goshs version
Usage examples:
Start with default values: ./goshs
Start with wevdav support: ./goshs -w
Start with different port: ./goshs -p 8080
Start with self-signed cert: ./goshs -s -ss
Start with custom cert: ./goshs -s -sk <path to key> -sc <path to cert>
Start with basic auth: ./goshs -b secret-user:$up3r$3cur3
Start with basic auth empty user: ./goshs -b :$up3r$3cur3
Start with cli enabled: ./goshs -b secret-user:$up3r$3cur3 -s -ss -c
`, goshsVersion, os.Args[0])
}
}
// Flag handling
func init() {
wd, _ := os.Getwd()
// flags
flag.StringVar(&ip, "i", ip, "ip")
flag.StringVar(&ip, "ip", ip, "ip")
flag.IntVar(&port, "p", port, "port")
flag.IntVar(&port, "port", port, "port")
flag.StringVar(&webroot, "d", wd, "web root")
flag.StringVar(&webroot, "dir", wd, "web root")
flag.BoolVar(&ssl, "s", ssl, "tls")
flag.BoolVar(&ssl, "ssl", ssl, "tls")
flag.BoolVar(&selfsigned, "ss", selfsigned, "self-signed")
flag.BoolVar(&selfsigned, "self-signed", selfsigned, "self-signed")
flag.StringVar(&myKey, "sk", myKey, "server key")
flag.StringVar(&myKey, "server-key", myKey, "server key")
flag.StringVar(&myCert, "sc", myCert, "server cert")
flag.StringVar(&myCert, "server-cert", myCert, "server cert")
flag.StringVar(&basicAuth, "b", basicAuth, "basic auth")
flag.StringVar(&basicAuth, "basic-auth", basicAuth, "basic auth")
flag.BoolVar(&webdav, "w", webdav, "enable webdav")
flag.BoolVar(&webdav, "webdav", webdav, "enable webdav")
flag.IntVar(&webdavPort, "wp", webdavPort, "webdav port")
flag.IntVar(&webdavPort, "webdav-port", webdavPort, "webdav port")
flag.BoolVar(&uploadOnly, "uo", uploadOnly, "upload only")
flag.BoolVar(&uploadOnly, "upload-only", uploadOnly, "upload only")
flag.BoolVar(&readOnly, "ro", readOnly, "read only")
flag.BoolVar(&readOnly, "read-only", readOnly, "read only")
flag.BoolVar(&verbose, "V", verbose, "verbose")
flag.BoolVar(&verbose, "verbose", verbose, "verbose")
flag.BoolVar(&silent, "si", silent, "silent")
flag.BoolVar(&silent, "silent", silent, "silent")
flag.StringVar(&dropuser, "u", dropuser, "user")
flag.StringVar(&dropuser, "user", dropuser, "user")
flag.BoolVar(&cli, "c", cli, "cli")
flag.BoolVar(&cli, "cli", cli, "cli")
hash := flag.Bool("H", false, "hash")
hashLong := flag.Bool("hash", false, "hash")
version := flag.Bool("v", false, "goshs version")
flag.Usage = usage()
flag.Parse()
if *version {
fmt.Printf("goshs version is: %+v\n", goshsVersion)
os.Exit(0)
}
if *hash || *hashLong {
utils.HashPassword()
os.Exit(1)
}
// Check if interface name was provided as -i
// If so, resolve to ip address of interface
if !strings.Contains(ip, ".") {
addr, err := utils.GetInterfaceIpv4Addr(ip)
if err != nil {
logger.Fatal(err)
os.Exit(-1)
}
if addr == "" {
logger.Fatal("IP address cannot be found for provided interface")
os.Exit(-1)
}
ip = addr
}
// Sanity check for upload only vs read only
if uploadOnly && readOnly {
logger.Fatal("You can only select either 'upload only' or 'read only', not both.")
}
// Sanity check if cli mode is combined with auth and tls
if cli && (!ssl || basicAuth == "") {
logger.Fatal("With cli mode you need to enable basic auth and tls for security reasons.")
}
if webdav {
logger.Warn("upload/read-only mode deactivated due to use of 'webdav' mode")
uploadOnly = false
readOnly = false
}
// Abspath for webroot
var err error
// Trim trailing / for linux/mac and \ for windows
webroot = strings.TrimSuffix(webroot, "/")
webroot = strings.TrimSuffix(webroot, "\\")
if !filepath.IsAbs(webroot) {
webroot, err = filepath.Abs(filepath.Join(wd, webroot))
if err != nil {
logger.Fatalf("Webroot cannot be constructed: %+v", err)
}
}
}
// Sanity checks if basic auth has the right format
func parseBasicAuth() (string, string) {
auth := strings.SplitN(basicAuth, ":", 2)
if len(auth) < 2 {
fmt.Println("Wrong basic auth format. Please provide user:password separated by a colon")
os.Exit(-1)
}
user := auth[0]
pass := auth[1]
return user, pass
}
func main() {
user := ""
pass := ""
// check for basic auth
if basicAuth != "" {
user, pass = parseBasicAuth()
}
done := make(chan os.Signal, 1)
signal.Notify(done, os.Interrupt, syscall.SIGINT, syscall.SIGTERM)
// Random Seed generation (used for CA serial)
rand.Seed(time.Now().UnixNano())
// Setup the custom file server
server := &httpserver.FileServer{
IP: ip,
Port: port,
CLI: cli,
Webroot: webroot,
SSL: ssl,
SelfSigned: selfsigned,
MyCert: myCert,
MyKey: myKey,
User: user,
Pass: pass,
DropUser: dropuser,
UploadOnly: uploadOnly,
ReadOnly: readOnly,
Silent: silent,
Verbose: verbose,
Version: goshsVersion,
}
go server.Start("web")
if webdav {
server.WebdavPort = webdavPort
go server.Start("webdav")
}
<-done
logger.Infof("Received CTRL+C, exiting...")
}