2011-06-20 12:44:04 +02:00
|
|
|
/**
|
|
|
|
* This is the Socket.IO Router. It routes the Messages between the
|
|
|
|
* components of the Server. The components are at the moment: pad and timeslider
|
|
|
|
*/
|
|
|
|
|
|
|
|
/*
|
2011-08-11 16:26:41 +02:00
|
|
|
* 2011 Peter 'Pita' Martischka (Primary Technology Ltd)
|
2011-06-20 12:44:04 +02:00
|
|
|
*
|
|
|
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
* you may not use this file except in compliance with the License.
|
|
|
|
* You may obtain a copy of the License at
|
|
|
|
*
|
|
|
|
* http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
*
|
|
|
|
* Unless required by applicable law or agreed to in writing, software
|
|
|
|
* distributed under the License is distributed on an "AS-IS" BASIS,
|
|
|
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
* See the License for the specific language governing permissions and
|
|
|
|
* limitations under the License.
|
|
|
|
*/
|
|
|
|
|
2011-12-04 16:50:02 +01:00
|
|
|
var ERR = require("async-stacktrace");
|
2011-07-31 19:25:51 +02:00
|
|
|
var log4js = require('log4js');
|
|
|
|
var messageLogger = log4js.getLogger("message");
|
2011-08-16 16:53:09 +02:00
|
|
|
var securityManager = require("../db/SecurityManager");
|
2013-04-24 12:19:41 +02:00
|
|
|
var settings = require('../utils/Settings');
|
2011-07-31 19:25:51 +02:00
|
|
|
|
2011-06-20 12:44:04 +02:00
|
|
|
/**
|
|
|
|
* Saves all components
|
|
|
|
* key is the component name
|
|
|
|
* value is the component module
|
|
|
|
*/
|
|
|
|
var components = {};
|
|
|
|
|
|
|
|
var socket;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* adds a component
|
|
|
|
*/
|
|
|
|
exports.addComponent = function(moduleName, module)
|
|
|
|
{
|
|
|
|
//save the component
|
|
|
|
components[moduleName] = module;
|
|
|
|
|
|
|
|
//give the module the socket
|
|
|
|
module.setSocketIO(socket);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* sets the socket.io and adds event functions for routing
|
|
|
|
*/
|
2013-04-15 20:29:06 +02:00
|
|
|
exports.setSocketIO = function(_socket) {
|
2011-06-20 12:44:04 +02:00
|
|
|
//save this socket internaly
|
|
|
|
socket = _socket;
|
|
|
|
|
2011-06-23 15:08:18 +02:00
|
|
|
socket.sockets.on('connection', function(client)
|
2011-06-20 12:44:04 +02:00
|
|
|
{
|
2013-04-24 12:19:41 +02:00
|
|
|
if(settings.trustProxy && client.handshake.headers['x-forwarded-for'] !== undefined){
|
|
|
|
client.set('remoteAddress', client.handshake.headers['x-forwarded-for']);
|
|
|
|
}
|
|
|
|
else{
|
|
|
|
client.set('remoteAddress', client.handshake.address.address);
|
|
|
|
}
|
2011-08-16 16:53:09 +02:00
|
|
|
var clientAuthorized = false;
|
|
|
|
|
2011-07-11 15:56:45 +02:00
|
|
|
//wrap the original send function to log the messages
|
|
|
|
client._send = client.send;
|
2013-04-15 20:29:06 +02:00
|
|
|
client.send = function(message) {
|
2013-02-10 16:03:49 +01:00
|
|
|
messageLogger.debug("to " + client.id + ": " + stringifyWithoutPassword(message));
|
2011-07-11 15:56:45 +02:00
|
|
|
client._send(message);
|
|
|
|
}
|
|
|
|
|
2011-06-20 12:44:04 +02:00
|
|
|
//tell all components about this connect
|
2013-04-15 20:29:06 +02:00
|
|
|
for(var i in components) {
|
2011-06-20 12:44:04 +02:00
|
|
|
components[i].handleConnect(client);
|
2013-04-15 20:29:06 +02:00
|
|
|
}
|
|
|
|
|
2011-08-16 16:53:09 +02:00
|
|
|
client.on('message', function(message)
|
|
|
|
{
|
2013-04-15 20:29:06 +02:00
|
|
|
if(message.protocolVersion && message.protocolVersion != 2) {
|
2011-08-16 16:53:09 +02:00
|
|
|
messageLogger.warn("Protocolversion header is not correct:" + stringifyWithoutPassword(message));
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
//client is authorized, everything ok
|
2013-04-15 20:29:06 +02:00
|
|
|
if(clientAuthorized) {
|
|
|
|
handleMessage(client, message);
|
|
|
|
} else { //try to authorize the client
|
|
|
|
if(message.padId !== undefined && message.sessionID !== undefined && message.token !== undefined && message.password !== undefined) {
|
|
|
|
//this message has everything to try an authorization
|
|
|
|
securityManager.checkAccess (message.padId, message.sessionID, message.token, message.password,
|
|
|
|
function(err, statusObject) {
|
|
|
|
ERR(err);
|
|
|
|
|
|
|
|
//access was granted, mark the client as authorized and handle the message
|
|
|
|
if(statusObject.accessStatus == "grant") {
|
|
|
|
clientAuthorized = true;
|
|
|
|
handleMessage(client, message);
|
|
|
|
}
|
|
|
|
//no access, send the client a message that tell him why
|
|
|
|
else {
|
|
|
|
messageLogger.warn("Authentication try failed:" + stringifyWithoutPassword(message));
|
|
|
|
client.json.send({accessStatus: statusObject.accessStatus});
|
|
|
|
}
|
2011-08-16 16:53:09 +02:00
|
|
|
}
|
2013-04-15 20:29:06 +02:00
|
|
|
);
|
|
|
|
} else { //drop message
|
2011-11-19 20:21:23 +01:00
|
|
|
messageLogger.warn("Dropped message cause of bad permissions:" + stringifyWithoutPassword(message));
|
2011-08-16 16:53:09 +02:00
|
|
|
}
|
2011-06-20 12:44:04 +02:00
|
|
|
}
|
|
|
|
});
|
|
|
|
|
|
|
|
client.on('disconnect', function()
|
|
|
|
{
|
2011-08-16 16:53:09 +02:00
|
|
|
//tell all components about this disconnect
|
2011-06-20 12:44:04 +02:00
|
|
|
for(var i in components)
|
|
|
|
{
|
|
|
|
components[i].handleDisconnect(client);
|
|
|
|
}
|
|
|
|
});
|
|
|
|
});
|
|
|
|
}
|
2011-08-16 16:53:09 +02:00
|
|
|
|
2013-04-15 20:29:06 +02:00
|
|
|
//try to handle the message of this client
|
|
|
|
function handleMessage(client, message)
|
|
|
|
{
|
|
|
|
|
|
|
|
if(message.component && components[message.component]) {
|
|
|
|
//check if component is registered in the components array
|
|
|
|
if(components[message.component]) {
|
|
|
|
messageLogger.debug("from " + client.id + ": " + stringifyWithoutPassword(message));
|
|
|
|
components[message.component].handleMessage(client, message);
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
messageLogger.error("Can't route the message:" + stringifyWithoutPassword(message));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2011-08-16 16:53:09 +02:00
|
|
|
//returns a stringified representation of a message, removes the password
|
|
|
|
//this ensures there are no passwords in the log
|
|
|
|
function stringifyWithoutPassword(message)
|
|
|
|
{
|
|
|
|
var newMessage = {};
|
|
|
|
|
|
|
|
for(var i in message)
|
|
|
|
{
|
|
|
|
if(i == "password" && message[i] != null)
|
|
|
|
newMessage["password"] = "xxx";
|
|
|
|
else
|
|
|
|
newMessage[i]=message[i];
|
|
|
|
}
|
|
|
|
|
|
|
|
return JSON.stringify(newMessage);
|
|
|
|
}
|