parser.go 9.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365
  1. // SPDX-FileCopyrightText: Copyright The Miniflux Authors. All rights reserved.
  2. // SPDX-License-Identifier: Apache-2.0
  3. package config // import "miniflux.app/v2/internal/config"
  4. import (
  5. "bufio"
  6. "bytes"
  7. "crypto/rand"
  8. "errors"
  9. "fmt"
  10. "io"
  11. "log/slog"
  12. "net/url"
  13. "os"
  14. "strconv"
  15. "strings"
  16. "time"
  17. )
  18. type configParser struct {
  19. options *configOptions
  20. }
  21. func NewConfigParser() *configParser {
  22. return &configParser{
  23. options: NewConfigOptions(),
  24. }
  25. }
  26. func (cp *configParser) ParseEnvironmentVariables() (*configOptions, error) {
  27. if err := cp.parseLines(os.Environ()); err != nil {
  28. return nil, err
  29. }
  30. return cp.options, nil
  31. }
  32. func (cp *configParser) ParseFile(filename string) (*configOptions, error) {
  33. fp, err := os.Open(filename)
  34. if err != nil {
  35. return nil, err
  36. }
  37. defer fp.Close()
  38. if err := cp.parseLines(parseFileContent(fp)); err != nil {
  39. return nil, err
  40. }
  41. return cp.options, nil
  42. }
  43. // Validate checks for invalid or incomplete option combinations.
  44. func (c *configOptions) Validate() error {
  45. if c.OAuth2Provider() == "oidc" && c.OAuth2OIDCDiscoveryEndpoint() == "" {
  46. return errors.New("OAUTH2_OIDC_DISCOVERY_ENDPOINT must be configured when using the OIDC provider")
  47. }
  48. if c.DisableLocalAuth() {
  49. switch {
  50. case c.OAuth2Provider() == "" && c.AuthProxyHeader() == "":
  51. return errors.New("DISABLE_LOCAL_AUTH is enabled but neither OAUTH2_PROVIDER nor AUTH_PROXY_HEADER is set. Please enable at least one authentication source")
  52. case c.OAuth2Provider() != "" && !c.IsOAuth2UserCreationAllowed():
  53. return errors.New("DISABLE_LOCAL_AUTH is enabled and an OAUTH2_PROVIDER is configured, but OAUTH2_USER_CREATION is not enabled")
  54. case c.AuthProxyHeader() != "" && !c.IsAuthProxyUserCreationAllowed():
  55. return errors.New("DISABLE_LOCAL_AUTH is enabled and an AUTH_PROXY_HEADER is configured, but AUTH_PROXY_USER_CREATION is not enabled")
  56. }
  57. }
  58. if c.AuthProxyHeader() != "" && len(c.TrustedReverseProxyNetworks()) == 0 {
  59. return errors.New("TRUSTED_REVERSE_PROXY_NETWORKS must be configured when AUTH_PROXY_HEADER is used")
  60. }
  61. if (c.CertFile() != "") != (c.CertKeyFile() != "") {
  62. return errors.New("CERT_FILE and KEY_FILE must both be provided")
  63. }
  64. if c.CertDomain() != "" && c.CertFile() != "" {
  65. return errors.New("CERT_DOMAIN and CERT_FILE/KEY_FILE are mutually exclusive")
  66. }
  67. if (c.MetricsUsername() != "") != (c.MetricsPassword() != "") {
  68. return errors.New("METRICS_USERNAME and METRICS_PASSWORD must both be provided")
  69. }
  70. if c.DatabaseMinConns() > c.DatabaseMaxConns() {
  71. return errors.New("DATABASE_MIN_CONNS must be less than or equal to DATABASE_MAX_CONNS")
  72. }
  73. if c.SchedulerRoundRobinMinInterval() > c.SchedulerRoundRobinMaxInterval() {
  74. return errors.New("SCHEDULER_ROUND_ROBIN_MIN_INTERVAL must be less than or equal to SCHEDULER_ROUND_ROBIN_MAX_INTERVAL")
  75. }
  76. if c.SchedulerEntryFrequencyMinInterval() > c.SchedulerEntryFrequencyMaxInterval() {
  77. return errors.New("SCHEDULER_ENTRY_FREQUENCY_MIN_INTERVAL must be less than or equal to SCHEDULER_ENTRY_FREQUENCY_MAX_INTERVAL")
  78. }
  79. return nil
  80. }
  81. func (cp *configParser) postParsing() error {
  82. // Parse basePath and rootURL based on BASE_URL
  83. baseURL := cp.options.options["BASE_URL"].parsedStringValue
  84. baseURL = strings.TrimSuffix(baseURL, "/")
  85. parsedURL, err := url.Parse(baseURL)
  86. if err != nil {
  87. return fmt.Errorf("invalid BASE_URL: %v", err)
  88. }
  89. scheme := strings.ToLower(parsedURL.Scheme)
  90. if scheme != "https" && scheme != "http" {
  91. return errors.New("BASE_URL scheme must be http or https")
  92. }
  93. cp.options.options["BASE_URL"].parsedStringValue = baseURL
  94. cp.options.basePath = parsedURL.Path
  95. parsedURL.Path = ""
  96. cp.options.rootURL = parsedURL.String()
  97. // Parse YouTube embed domain based on YOUTUBE_EMBED_URL_OVERRIDE
  98. youTubeEmbedURLOverride := cp.options.options["YOUTUBE_EMBED_URL_OVERRIDE"].parsedStringValue
  99. if youTubeEmbedURLOverride != "" {
  100. parsedYouTubeEmbedURL, err := url.Parse(youTubeEmbedURLOverride)
  101. if err != nil {
  102. return fmt.Errorf("invalid YOUTUBE_EMBED_URL_OVERRIDE: %v", err)
  103. }
  104. cp.options.youTubeEmbedDomain = parsedYouTubeEmbedURL.Hostname()
  105. }
  106. // Generate a media proxy private key if not set
  107. if len(cp.options.options["MEDIA_PROXY_PRIVATE_KEY"].parsedBytesValue) == 0 {
  108. randomKey := make([]byte, 16)
  109. rand.Read(randomKey)
  110. cp.options.options["MEDIA_PROXY_PRIVATE_KEY"].parsedBytesValue = randomKey
  111. }
  112. // Override LISTEN_ADDR with PORT if set (for compatibility reasons)
  113. if cp.options.Port() != "" {
  114. cp.options.options["LISTEN_ADDR"].parsedStringList = []string{":" + cp.options.Port()}
  115. cp.options.options["LISTEN_ADDR"].rawValue = ":" + cp.options.Port()
  116. }
  117. return nil
  118. }
  119. func (cp *configParser) parseLines(lines []string) error {
  120. for lineNum, line := range lines {
  121. key, value, ok := strings.Cut(line, "=")
  122. if !ok {
  123. return fmt.Errorf("unable to parse configuration, invalid format on line %d", lineNum)
  124. }
  125. key, value = strings.TrimSpace(key), strings.TrimSpace(value)
  126. if err := cp.parseLine(key, value); err != nil {
  127. return err
  128. }
  129. }
  130. if err := cp.postParsing(); err != nil {
  131. return err
  132. }
  133. return nil
  134. }
  135. func (cp *configParser) parseLine(key, value string) error {
  136. field, exists := cp.options.options[key]
  137. if !exists {
  138. if key == "FILTER_ENTRY_MAX_AGE_DAYS" {
  139. slog.Warn("Configuration option FILTER_ENTRY_MAX_AGE_DAYS is deprecated; use user filter rule max-age:<duration> instead")
  140. }
  141. // Ignore unknown configuration keys to avoid parsing unrelated environment variables.
  142. return nil
  143. }
  144. // Validate the option if a validator is provided
  145. if field.validator != nil {
  146. if err := field.validator(value); err != nil {
  147. return fmt.Errorf("invalid value for key %s: %v", key, err)
  148. }
  149. }
  150. // Convert the raw value based on its type
  151. switch field.valueType {
  152. case stringType:
  153. field.parsedStringValue = parseStringValue(value, field.parsedStringValue)
  154. field.rawValue = value
  155. case stringListType:
  156. field.parsedStringList = parseStringListValue(value, field.parsedStringList)
  157. field.rawValue = value
  158. case boolType:
  159. parsedValue, err := parseBoolValue(value, field.parsedBoolValue)
  160. if err != nil {
  161. return fmt.Errorf("invalid boolean value for key %s: %v", key, err)
  162. }
  163. field.parsedBoolValue = parsedValue
  164. field.rawValue = value
  165. case intType:
  166. field.parsedIntValue = parseIntValue(value, field.parsedIntValue)
  167. field.rawValue = value
  168. case int64Type:
  169. field.parsedInt64Value = ParsedInt64Value(value, field.parsedInt64Value)
  170. field.rawValue = value
  171. case secondType:
  172. field.parsedDuration = parseDurationValue(value, time.Second, field.parsedDuration)
  173. field.rawValue = value
  174. case minuteType:
  175. field.parsedDuration = parseDurationValue(value, time.Minute, field.parsedDuration)
  176. field.rawValue = value
  177. case hourType:
  178. field.parsedDuration = parseDurationValue(value, time.Hour, field.parsedDuration)
  179. field.rawValue = value
  180. case dayType:
  181. field.parsedDuration = parseDurationValue(value, time.Hour*24, field.parsedDuration)
  182. field.rawValue = value
  183. case urlType:
  184. parsedURL, err := parseURLValue(value, field.parsedURLValue)
  185. if err != nil {
  186. return fmt.Errorf("invalid URL for key %s: %v", key, err)
  187. }
  188. field.parsedURLValue = parsedURL
  189. field.rawValue = value
  190. case secretFileType:
  191. secretValue, err := readSecretFileValue(value)
  192. if err != nil {
  193. return fmt.Errorf("error reading secret file for key %s: %v", key, err)
  194. }
  195. if field.targetKey != "" {
  196. if targetField, ok := cp.options.options[field.targetKey]; ok {
  197. targetField.parsedStringValue = secretValue
  198. targetField.rawValue = secretValue
  199. }
  200. }
  201. field.rawValue = value
  202. case bytesType:
  203. if value != "" {
  204. field.parsedBytesValue = []byte(value)
  205. field.rawValue = value
  206. }
  207. }
  208. return nil
  209. }
  210. func parseStringValue(value string, fallback string) string {
  211. if value == "" {
  212. return fallback
  213. }
  214. return value
  215. }
  216. func parseBoolValue(value string, fallback bool) (bool, error) {
  217. if value == "" {
  218. return fallback, nil
  219. }
  220. value = strings.ToLower(value)
  221. if value == "1" || value == "yes" || value == "true" || value == "on" {
  222. return true, nil
  223. }
  224. if value == "0" || value == "no" || value == "false" || value == "off" {
  225. return false, nil
  226. }
  227. return false, fmt.Errorf("invalid boolean value: %q", value)
  228. }
  229. func parseIntValue(value string, fallback int) int {
  230. if value == "" {
  231. return fallback
  232. }
  233. v, err := strconv.Atoi(value)
  234. if err != nil {
  235. return fallback
  236. }
  237. return v
  238. }
  239. func ParsedInt64Value(value string, fallback int64) int64 {
  240. if value == "" {
  241. return fallback
  242. }
  243. v, err := strconv.ParseInt(value, 10, 64)
  244. if err != nil {
  245. return fallback
  246. }
  247. return v
  248. }
  249. func parseStringListValue(value string, fallback []string) []string {
  250. if value == "" {
  251. return fallback
  252. }
  253. var strList []string
  254. present := make(map[string]bool)
  255. for item := range strings.SplitSeq(value, ",") {
  256. if itemValue := strings.TrimSpace(item); itemValue != "" {
  257. if !present[itemValue] {
  258. present[itemValue] = true
  259. strList = append(strList, itemValue)
  260. }
  261. }
  262. }
  263. return strList
  264. }
  265. func parseDurationValue(value string, unit time.Duration, fallback time.Duration) time.Duration {
  266. if value == "" {
  267. return fallback
  268. }
  269. v, err := strconv.Atoi(value)
  270. if err != nil {
  271. return fallback
  272. }
  273. return time.Duration(v) * unit
  274. }
  275. func parseURLValue(value string, fallback *url.URL) (*url.URL, error) {
  276. if value == "" {
  277. return fallback, nil
  278. }
  279. parsedURL, err := url.Parse(value)
  280. if err != nil {
  281. return fallback, err
  282. }
  283. return parsedURL, nil
  284. }
  285. func readSecretFileValue(filename string) (string, error) {
  286. data, err := os.ReadFile(filename)
  287. if err != nil {
  288. return "", err
  289. }
  290. value := string(bytes.TrimSpace(data))
  291. if value == "" {
  292. return "", errors.New("secret file is empty")
  293. }
  294. return value, nil
  295. }
  296. func parseFileContent(r io.Reader) (lines []string) {
  297. scanner := bufio.NewScanner(r)
  298. for scanner.Scan() {
  299. line := strings.TrimSpace(scanner.Text())
  300. if !strings.HasPrefix(line, "#") && strings.Index(line, "=") > 0 {
  301. lines = append(lines, line)
  302. }
  303. }
  304. return lines
  305. }