2019-09-09 00:48:37 +00:00
|
|
|
<?php
|
|
|
|
|
|
|
|
namespace Pterodactyl\Http\Controllers\Api\Client\Servers;
|
|
|
|
|
2020-04-07 04:03:00 +00:00
|
|
|
use Carbon\CarbonImmutable;
|
2019-09-09 00:48:37 +00:00
|
|
|
use Pterodactyl\Models\Server;
|
|
|
|
use Illuminate\Http\JsonResponse;
|
2020-04-07 04:03:00 +00:00
|
|
|
use Pterodactyl\Services\Nodes\NodeJWTService;
|
2020-12-24 17:20:23 +00:00
|
|
|
use Pterodactyl\Exceptions\Http\HttpForbiddenException;
|
2020-04-17 17:21:15 +00:00
|
|
|
use Pterodactyl\Services\Servers\GetUserPermissionsService;
|
2021-08-05 04:36:57 +00:00
|
|
|
use Pterodactyl\Http\Requests\Api\Client\WebsocketTokenRequest;
|
2019-09-09 00:48:37 +00:00
|
|
|
use Pterodactyl\Http\Controllers\Api\Client\ClientApiController;
|
|
|
|
|
|
|
|
class WebsocketController extends ClientApiController
|
|
|
|
{
|
2021-03-05 17:03:12 +00:00
|
|
|
private NodeJWTService $jwtService;
|
|
|
|
private GetUserPermissionsService $permissionsService;
|
2020-04-17 17:21:15 +00:00
|
|
|
|
2019-09-09 00:48:37 +00:00
|
|
|
/**
|
|
|
|
* WebsocketController constructor.
|
|
|
|
*/
|
2020-04-17 17:21:15 +00:00
|
|
|
public function __construct(
|
|
|
|
NodeJWTService $jwtService,
|
2020-06-28 17:16:15 +00:00
|
|
|
GetUserPermissionsService $permissionsService
|
2020-04-17 17:21:15 +00:00
|
|
|
) {
|
2019-09-09 00:48:37 +00:00
|
|
|
parent::__construct();
|
|
|
|
|
2020-04-07 04:03:00 +00:00
|
|
|
$this->jwtService = $jwtService;
|
2020-04-17 17:21:15 +00:00
|
|
|
$this->permissionsService = $permissionsService;
|
2019-09-09 00:48:37 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2019-09-25 03:20:29 +00:00
|
|
|
* Generates a one-time token that is sent along in every websocket call to the Daemon.
|
|
|
|
* This is a signed JWT that the Daemon then uses the verify the user's identity, and
|
2021-03-05 17:03:12 +00:00
|
|
|
* allows us to continually renew this token and avoid users maintaining sessions wrongly,
|
2019-09-25 03:20:29 +00:00
|
|
|
* as well as ensure that user's only perform actions they're allowed to.
|
2019-09-09 00:48:37 +00:00
|
|
|
*/
|
2021-08-05 04:36:57 +00:00
|
|
|
public function __invoke(WebsocketTokenRequest $request, Server $server): JsonResponse
|
2019-09-09 00:48:37 +00:00
|
|
|
{
|
2021-08-05 04:36:57 +00:00
|
|
|
$permissions = $this->permissionsService->handle($server, $request->user());
|
2020-12-16 23:55:44 +00:00
|
|
|
|
2020-12-24 17:20:23 +00:00
|
|
|
$node = $server->node;
|
2021-01-23 20:33:34 +00:00
|
|
|
if (!is_null($server->transfer)) {
|
2020-12-16 23:55:44 +00:00
|
|
|
// Check if the user has permissions to receive transfer logs.
|
2021-01-23 20:33:34 +00:00
|
|
|
if (!in_array('admin.websocket.transfer', $permissions)) {
|
2020-12-24 17:20:23 +00:00
|
|
|
throw new HttpForbiddenException('You do not have permission to view server transfer logs.');
|
2020-12-16 23:55:44 +00:00
|
|
|
}
|
|
|
|
|
2020-12-17 01:54:01 +00:00
|
|
|
// Redirect the websocket request to the new node if the server has been archived.
|
|
|
|
if ($server->transfer->archived) {
|
|
|
|
$node = $server->transfer->newNode;
|
|
|
|
}
|
2020-12-16 23:55:44 +00:00
|
|
|
}
|
|
|
|
|
2020-04-07 04:03:00 +00:00
|
|
|
$token = $this->jwtService
|
2021-01-06 15:54:50 +00:00
|
|
|
->setExpiresAt(CarbonImmutable::now()->addMinutes(10)->toDateTimeImmutable())
|
2020-04-07 04:03:00 +00:00
|
|
|
->setClaims([
|
|
|
|
'user_id' => $request->user()->id,
|
|
|
|
'server_uuid' => $server->uuid,
|
2020-12-16 23:55:44 +00:00
|
|
|
'permissions' => $permissions,
|
2020-04-07 04:03:00 +00:00
|
|
|
])
|
2021-08-05 04:36:57 +00:00
|
|
|
->handle($node, $request->user()->id . $server->uuid);
|
2019-09-09 00:48:37 +00:00
|
|
|
|
2020-12-16 23:55:44 +00:00
|
|
|
$socket = str_replace(['https://', 'http://'], ['wss://', 'ws://'], $node->getConnectionAddress());
|
2019-09-09 00:48:37 +00:00
|
|
|
|
2020-06-28 17:16:15 +00:00
|
|
|
return new JsonResponse([
|
2019-09-09 00:48:37 +00:00
|
|
|
'data' => [
|
2021-01-06 15:54:50 +00:00
|
|
|
'token' => $token->toString(),
|
2019-09-25 03:20:29 +00:00
|
|
|
'socket' => $socket . sprintf('/api/servers/%s/ws', $server->uuid),
|
2019-09-09 00:48:37 +00:00
|
|
|
],
|
|
|
|
]);
|
|
|
|
}
|
|
|
|
}
|