mysql.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396
  1. //go:build !nomysql
  2. // +build !nomysql
  3. package dataprovider
  4. import (
  5. "context"
  6. "crypto/x509"
  7. "database/sql"
  8. "errors"
  9. "fmt"
  10. "strings"
  11. "time"
  12. // we import go-sql-driver/mysql here to be able to disable MySQL support using a build tag
  13. _ "github.com/go-sql-driver/mysql"
  14. "github.com/drakkan/sftpgo/v2/logger"
  15. "github.com/drakkan/sftpgo/v2/version"
  16. "github.com/drakkan/sftpgo/v2/vfs"
  17. )
  18. const (
  19. mysqlInitialSQL = "CREATE TABLE `{{schema_version}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `version` integer NOT NULL);" +
  20. "CREATE TABLE `{{admins}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `username` varchar(255) NOT NULL UNIQUE, " +
  21. "`description` varchar(512) NULL, `password` varchar(255) NOT NULL, `email` varchar(255) NULL, `status` integer NOT NULL, " +
  22. "`permissions` longtext NOT NULL, `filters` longtext NULL, `additional_info` longtext NULL);" +
  23. "CREATE TABLE `{{folders}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `name` varchar(255) NOT NULL UNIQUE, " +
  24. "`description` varchar(512) NULL, `path` varchar(512) NULL, `used_quota_size` bigint NOT NULL, " +
  25. "`used_quota_files` integer NOT NULL, `last_quota_update` bigint NOT NULL, `filesystem` longtext NULL);" +
  26. "CREATE TABLE `{{users}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `username` varchar(255) NOT NULL UNIQUE, " +
  27. "`status` integer NOT NULL, `expiration_date` bigint NOT NULL, `description` varchar(512) NULL, `password` longtext NULL, " +
  28. "`public_keys` longtext NULL, `home_dir` varchar(512) NOT NULL, `uid` integer NOT NULL, `gid` integer NOT NULL, " +
  29. "`max_sessions` integer NOT NULL, `quota_size` bigint NOT NULL, `quota_files` integer NOT NULL, " +
  30. "`permissions` longtext NOT NULL, `used_quota_size` bigint NOT NULL, `used_quota_files` integer NOT NULL, " +
  31. "`last_quota_update` bigint NOT NULL, `upload_bandwidth` integer NOT NULL, `download_bandwidth` integer NOT NULL, " +
  32. "`last_login` bigint NOT NULL, `filters` longtext NULL, `filesystem` longtext NULL, `additional_info` longtext NULL);" +
  33. "CREATE TABLE `{{folders_mapping}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `virtual_path` varchar(512) NOT NULL, " +
  34. "`quota_size` bigint NOT NULL, `quota_files` integer NOT NULL, `folder_id` integer NOT NULL, `user_id` integer NOT NULL);" +
  35. "ALTER TABLE `{{folders_mapping}}` ADD CONSTRAINT `{{prefix}}unique_mapping` UNIQUE (`user_id`, `folder_id`);" +
  36. "ALTER TABLE `{{folders_mapping}}` ADD CONSTRAINT `{{prefix}}folders_mapping_folder_id_fk_folders_id` FOREIGN KEY (`folder_id`) REFERENCES `{{folders}}` (`id`) ON DELETE CASCADE;" +
  37. "ALTER TABLE `{{folders_mapping}}` ADD CONSTRAINT `{{prefix}}folders_mapping_user_id_fk_users_id` FOREIGN KEY (`user_id`) REFERENCES `{{users}}` (`id`) ON DELETE CASCADE;" +
  38. "INSERT INTO {{schema_version}} (version) VALUES (10);"
  39. mysqlV11SQL = "CREATE TABLE `{{api_keys}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `name` varchar(255) NOT NULL, `key_id` varchar(50) NOT NULL UNIQUE," +
  40. "`api_key` varchar(255) NOT NULL UNIQUE, `scope` integer NOT NULL, `created_at` bigint NOT NULL, `updated_at` bigint NOT NULL, `last_use_at` bigint NOT NULL, " +
  41. "`expires_at` bigint NOT NULL, `description` longtext NULL, `admin_id` integer NULL, `user_id` integer NULL);" +
  42. "ALTER TABLE `{{api_keys}}` ADD CONSTRAINT `{{prefix}}api_keys_admin_id_fk_admins_id` FOREIGN KEY (`admin_id`) REFERENCES `{{admins}}` (`id`) ON DELETE CASCADE;" +
  43. "ALTER TABLE `{{api_keys}}` ADD CONSTRAINT `{{prefix}}api_keys_user_id_fk_users_id` FOREIGN KEY (`user_id`) REFERENCES `{{users}}` (`id`) ON DELETE CASCADE;"
  44. mysqlV11DownSQL = "DROP TABLE `{{api_keys}}` CASCADE;"
  45. mysqlV12SQL = "ALTER TABLE `{{admins}}` ADD COLUMN `created_at` bigint DEFAULT 0 NOT NULL;" +
  46. "ALTER TABLE `{{admins}}` ALTER COLUMN `created_at` DROP DEFAULT;" +
  47. "ALTER TABLE `{{admins}}` ADD COLUMN `updated_at` bigint DEFAULT 0 NOT NULL;" +
  48. "ALTER TABLE `{{admins}}` ALTER COLUMN `updated_at` DROP DEFAULT;" +
  49. "ALTER TABLE `{{admins}}` ADD COLUMN `last_login` bigint DEFAULT 0 NOT NULL;" +
  50. "ALTER TABLE `{{admins}}` ALTER COLUMN `last_login` DROP DEFAULT;" +
  51. "ALTER TABLE `{{users}}` ADD COLUMN `created_at` bigint DEFAULT 0 NOT NULL;" +
  52. "ALTER TABLE `{{users}}` ALTER COLUMN `created_at` DROP DEFAULT;" +
  53. "ALTER TABLE `{{users}}` ADD COLUMN `updated_at` bigint DEFAULT 0 NOT NULL;" +
  54. "ALTER TABLE `{{users}}` ALTER COLUMN `updated_at` DROP DEFAULT;" +
  55. "CREATE INDEX `{{prefix}}users_updated_at_idx` ON `{{users}}` (`updated_at`);"
  56. mysqlV12DownSQL = "ALTER TABLE `{{admins}}` DROP COLUMN `updated_at`;" +
  57. "ALTER TABLE `{{admins}}` DROP COLUMN `created_at`;" +
  58. "ALTER TABLE `{{admins}}` DROP COLUMN `last_login`;" +
  59. "ALTER TABLE `{{users}}` DROP COLUMN `created_at`;" +
  60. "ALTER TABLE `{{users}}` DROP COLUMN `updated_at`;"
  61. )
  62. // MySQLProvider auth provider for MySQL/MariaDB database
  63. type MySQLProvider struct {
  64. dbHandle *sql.DB
  65. }
  66. func init() {
  67. version.AddFeature("+mysql")
  68. }
  69. func initializeMySQLProvider() error {
  70. var err error
  71. dbHandle, err := sql.Open("mysql", getMySQLConnectionString(false))
  72. if err == nil {
  73. providerLog(logger.LevelDebug, "mysql database handle created, connection string: %#v, pool size: %v",
  74. getMySQLConnectionString(true), config.PoolSize)
  75. dbHandle.SetMaxOpenConns(config.PoolSize)
  76. if config.PoolSize > 0 {
  77. dbHandle.SetMaxIdleConns(config.PoolSize)
  78. } else {
  79. dbHandle.SetMaxIdleConns(2)
  80. }
  81. dbHandle.SetConnMaxLifetime(240 * time.Second)
  82. provider = &MySQLProvider{dbHandle: dbHandle}
  83. } else {
  84. providerLog(logger.LevelWarn, "error creating mysql database handler, connection string: %#v, error: %v",
  85. getMySQLConnectionString(true), err)
  86. }
  87. return err
  88. }
  89. func getMySQLConnectionString(redactedPwd bool) string {
  90. var connectionString string
  91. if config.ConnectionString == "" {
  92. password := config.Password
  93. if redactedPwd {
  94. password = "[redacted]"
  95. }
  96. connectionString = fmt.Sprintf("%v:%v@tcp([%v]:%v)/%v?charset=utf8&interpolateParams=true&timeout=10s&tls=%v&writeTimeout=10s&readTimeout=10s",
  97. config.Username, password, config.Host, config.Port, config.Name, getSSLMode())
  98. } else {
  99. connectionString = config.ConnectionString
  100. }
  101. return connectionString
  102. }
  103. func (p *MySQLProvider) checkAvailability() error {
  104. return sqlCommonCheckAvailability(p.dbHandle)
  105. }
  106. func (p *MySQLProvider) validateUserAndPass(username, password, ip, protocol string) (User, error) {
  107. return sqlCommonValidateUserAndPass(username, password, ip, protocol, p.dbHandle)
  108. }
  109. func (p *MySQLProvider) validateUserAndTLSCert(username, protocol string, tlsCert *x509.Certificate) (User, error) {
  110. return sqlCommonValidateUserAndTLSCertificate(username, protocol, tlsCert, p.dbHandle)
  111. }
  112. func (p *MySQLProvider) validateUserAndPubKey(username string, publicKey []byte) (User, string, error) {
  113. return sqlCommonValidateUserAndPubKey(username, publicKey, p.dbHandle)
  114. }
  115. func (p *MySQLProvider) updateQuota(username string, filesAdd int, sizeAdd int64, reset bool) error {
  116. return sqlCommonUpdateQuota(username, filesAdd, sizeAdd, reset, p.dbHandle)
  117. }
  118. func (p *MySQLProvider) getUsedQuota(username string) (int, int64, error) {
  119. return sqlCommonGetUsedQuota(username, p.dbHandle)
  120. }
  121. func (p *MySQLProvider) setUpdatedAt(username string) {
  122. sqlCommonSetUpdatedAt(username, p.dbHandle)
  123. }
  124. func (p *MySQLProvider) updateLastLogin(username string) error {
  125. return sqlCommonUpdateLastLogin(username, p.dbHandle)
  126. }
  127. func (p *MySQLProvider) updateAdminLastLogin(username string) error {
  128. return sqlCommonUpdateAdminLastLogin(username, p.dbHandle)
  129. }
  130. func (p *MySQLProvider) userExists(username string) (User, error) {
  131. return sqlCommonGetUserByUsername(username, p.dbHandle)
  132. }
  133. func (p *MySQLProvider) addUser(user *User) error {
  134. return sqlCommonAddUser(user, p.dbHandle)
  135. }
  136. func (p *MySQLProvider) updateUser(user *User) error {
  137. return sqlCommonUpdateUser(user, p.dbHandle)
  138. }
  139. func (p *MySQLProvider) deleteUser(user *User) error {
  140. return sqlCommonDeleteUser(user, p.dbHandle)
  141. }
  142. func (p *MySQLProvider) dumpUsers() ([]User, error) {
  143. return sqlCommonDumpUsers(p.dbHandle)
  144. }
  145. func (p *MySQLProvider) getRecentlyUpdatedUsers(after int64) ([]User, error) {
  146. return sqlCommonGetRecentlyUpdatedUsers(after, p.dbHandle)
  147. }
  148. func (p *MySQLProvider) getUsers(limit int, offset int, order string) ([]User, error) {
  149. return sqlCommonGetUsers(limit, offset, order, p.dbHandle)
  150. }
  151. func (p *MySQLProvider) dumpFolders() ([]vfs.BaseVirtualFolder, error) {
  152. return sqlCommonDumpFolders(p.dbHandle)
  153. }
  154. func (p *MySQLProvider) getFolders(limit, offset int, order string) ([]vfs.BaseVirtualFolder, error) {
  155. return sqlCommonGetFolders(limit, offset, order, p.dbHandle)
  156. }
  157. func (p *MySQLProvider) getFolderByName(name string) (vfs.BaseVirtualFolder, error) {
  158. ctx, cancel := context.WithTimeout(context.Background(), defaultSQLQueryTimeout)
  159. defer cancel()
  160. return sqlCommonGetFolderByName(ctx, name, p.dbHandle)
  161. }
  162. func (p *MySQLProvider) addFolder(folder *vfs.BaseVirtualFolder) error {
  163. return sqlCommonAddFolder(folder, p.dbHandle)
  164. }
  165. func (p *MySQLProvider) updateFolder(folder *vfs.BaseVirtualFolder) error {
  166. return sqlCommonUpdateFolder(folder, p.dbHandle)
  167. }
  168. func (p *MySQLProvider) deleteFolder(folder *vfs.BaseVirtualFolder) error {
  169. return sqlCommonDeleteFolder(folder, p.dbHandle)
  170. }
  171. func (p *MySQLProvider) updateFolderQuota(name string, filesAdd int, sizeAdd int64, reset bool) error {
  172. return sqlCommonUpdateFolderQuota(name, filesAdd, sizeAdd, reset, p.dbHandle)
  173. }
  174. func (p *MySQLProvider) getUsedFolderQuota(name string) (int, int64, error) {
  175. return sqlCommonGetFolderUsedQuota(name, p.dbHandle)
  176. }
  177. func (p *MySQLProvider) adminExists(username string) (Admin, error) {
  178. return sqlCommonGetAdminByUsername(username, p.dbHandle)
  179. }
  180. func (p *MySQLProvider) addAdmin(admin *Admin) error {
  181. return sqlCommonAddAdmin(admin, p.dbHandle)
  182. }
  183. func (p *MySQLProvider) updateAdmin(admin *Admin) error {
  184. return sqlCommonUpdateAdmin(admin, p.dbHandle)
  185. }
  186. func (p *MySQLProvider) deleteAdmin(admin *Admin) error {
  187. return sqlCommonDeleteAdmin(admin, p.dbHandle)
  188. }
  189. func (p *MySQLProvider) getAdmins(limit int, offset int, order string) ([]Admin, error) {
  190. return sqlCommonGetAdmins(limit, offset, order, p.dbHandle)
  191. }
  192. func (p *MySQLProvider) dumpAdmins() ([]Admin, error) {
  193. return sqlCommonDumpAdmins(p.dbHandle)
  194. }
  195. func (p *MySQLProvider) validateAdminAndPass(username, password, ip string) (Admin, error) {
  196. return sqlCommonValidateAdminAndPass(username, password, ip, p.dbHandle)
  197. }
  198. func (p *MySQLProvider) apiKeyExists(keyID string) (APIKey, error) {
  199. return sqlCommonGetAPIKeyByID(keyID, p.dbHandle)
  200. }
  201. func (p *MySQLProvider) addAPIKey(apiKey *APIKey) error {
  202. return sqlCommonAddAPIKey(apiKey, p.dbHandle)
  203. }
  204. func (p *MySQLProvider) updateAPIKey(apiKey *APIKey) error {
  205. return sqlCommonUpdateAPIKey(apiKey, p.dbHandle)
  206. }
  207. func (p *MySQLProvider) deleteAPIKeys(apiKey *APIKey) error {
  208. return sqlCommonDeleteAPIKey(apiKey, p.dbHandle)
  209. }
  210. func (p *MySQLProvider) getAPIKeys(limit int, offset int, order string) ([]APIKey, error) {
  211. return sqlCommonGetAPIKeys(limit, offset, order, p.dbHandle)
  212. }
  213. func (p *MySQLProvider) dumpAPIKeys() ([]APIKey, error) {
  214. return sqlCommonDumpAPIKeys(p.dbHandle)
  215. }
  216. func (p *MySQLProvider) updateAPIKeyLastUse(keyID string) error {
  217. return sqlCommonUpdateAPIKeyLastUse(keyID, p.dbHandle)
  218. }
  219. func (p *MySQLProvider) close() error {
  220. return p.dbHandle.Close()
  221. }
  222. func (p *MySQLProvider) reloadConfig() error {
  223. return nil
  224. }
  225. // initializeDatabase creates the initial database structure
  226. func (p *MySQLProvider) initializeDatabase() error {
  227. dbVersion, err := sqlCommonGetDatabaseVersion(p.dbHandle, false)
  228. if err == nil && dbVersion.Version > 0 {
  229. return ErrNoInitRequired
  230. }
  231. initialSQL := strings.ReplaceAll(mysqlInitialSQL, "{{schema_version}}", sqlTableSchemaVersion)
  232. initialSQL = strings.ReplaceAll(initialSQL, "{{admins}}", sqlTableAdmins)
  233. initialSQL = strings.ReplaceAll(initialSQL, "{{folders}}", sqlTableFolders)
  234. initialSQL = strings.ReplaceAll(initialSQL, "{{users}}", sqlTableUsers)
  235. initialSQL = strings.ReplaceAll(initialSQL, "{{folders_mapping}}", sqlTableFoldersMapping)
  236. initialSQL = strings.ReplaceAll(initialSQL, "{{prefix}}", config.SQLTablesPrefix)
  237. return sqlCommonExecSQLAndUpdateDBVersion(p.dbHandle, strings.Split(initialSQL, ";"), 10)
  238. }
  239. func (p *MySQLProvider) migrateDatabase() error {
  240. dbVersion, err := sqlCommonGetDatabaseVersion(p.dbHandle, true)
  241. if err != nil {
  242. return err
  243. }
  244. switch version := dbVersion.Version; {
  245. case version == sqlDatabaseVersion:
  246. providerLog(logger.LevelDebug, "sql database is up to date, current version: %v", version)
  247. return ErrNoInitRequired
  248. case version < 10:
  249. err = fmt.Errorf("database version %v is too old, please see the upgrading docs", version)
  250. providerLog(logger.LevelError, "%v", err)
  251. logger.ErrorToConsole("%v", err)
  252. return err
  253. case version == 10:
  254. return updateMySQLDatabaseFromV10(p.dbHandle)
  255. case version == 11:
  256. return updateMySQLDatabaseFromV11(p.dbHandle)
  257. default:
  258. if version > sqlDatabaseVersion {
  259. providerLog(logger.LevelWarn, "database version %v is newer than the supported one: %v", version,
  260. sqlDatabaseVersion)
  261. logger.WarnToConsole("database version %v is newer than the supported one: %v", version,
  262. sqlDatabaseVersion)
  263. return nil
  264. }
  265. return fmt.Errorf("database version not handled: %v", version)
  266. }
  267. }
  268. func (p *MySQLProvider) revertDatabase(targetVersion int) error {
  269. dbVersion, err := sqlCommonGetDatabaseVersion(p.dbHandle, true)
  270. if err != nil {
  271. return err
  272. }
  273. if dbVersion.Version == targetVersion {
  274. return errors.New("current version match target version, nothing to do")
  275. }
  276. switch dbVersion.Version {
  277. case 12:
  278. return downgradeMySQLDatabaseFromV12(p.dbHandle)
  279. case 11:
  280. return downgradeMySQLDatabaseFromV11(p.dbHandle)
  281. default:
  282. return fmt.Errorf("database version not handled: %v", dbVersion.Version)
  283. }
  284. }
  285. func updateMySQLDatabaseFromV10(dbHandle *sql.DB) error {
  286. if err := updateMySQLDatabaseFrom10To11(dbHandle); err != nil {
  287. return err
  288. }
  289. return updateMySQLDatabaseFromV11(dbHandle)
  290. }
  291. func updateMySQLDatabaseFromV11(dbHandle *sql.DB) error {
  292. return updateMySQLDatabaseFrom11To12(dbHandle)
  293. }
  294. func downgradeMySQLDatabaseFromV12(dbHandle *sql.DB) error {
  295. if err := downgradeMySQLDatabaseFrom12To11(dbHandle); err != nil {
  296. return err
  297. }
  298. return downgradeMySQLDatabaseFromV11(dbHandle)
  299. }
  300. func downgradeMySQLDatabaseFromV11(dbHandle *sql.DB) error {
  301. return downgradeMySQLDatabaseFrom11To10(dbHandle)
  302. }
  303. func updateMySQLDatabaseFrom11To12(dbHandle *sql.DB) error {
  304. logger.InfoToConsole("updating database version: 11 -> 12")
  305. providerLog(logger.LevelInfo, "updating database version: 11 -> 12")
  306. sql := strings.ReplaceAll(mysqlV12SQL, "{{users}}", sqlTableUsers)
  307. sql = strings.ReplaceAll(sql, "{{admins}}", sqlTableAdmins)
  308. sql = strings.ReplaceAll(sql, "{{prefix}}", config.SQLTablesPrefix)
  309. return sqlCommonExecSQLAndUpdateDBVersion(dbHandle, strings.Split(sql, ";"), 12)
  310. }
  311. func downgradeMySQLDatabaseFrom12To11(dbHandle *sql.DB) error {
  312. logger.InfoToConsole("downgrading database version: 12 -> 11")
  313. providerLog(logger.LevelInfo, "downgrading database version: 12 -> 11")
  314. sql := strings.ReplaceAll(mysqlV12DownSQL, "{{users}}", sqlTableUsers)
  315. sql = strings.ReplaceAll(sql, "{{admins}}", sqlTableAdmins)
  316. sql = strings.ReplaceAll(sql, "{{prefix}}", config.SQLTablesPrefix)
  317. return sqlCommonExecSQLAndUpdateDBVersion(dbHandle, strings.Split(sql, ";"), 11)
  318. }
  319. func updateMySQLDatabaseFrom10To11(dbHandle *sql.DB) error {
  320. logger.InfoToConsole("updating database version: 10 -> 11")
  321. providerLog(logger.LevelInfo, "updating database version: 10 -> 11")
  322. sql := strings.ReplaceAll(mysqlV11SQL, "{{users}}", sqlTableUsers)
  323. sql = strings.ReplaceAll(sql, "{{admins}}", sqlTableAdmins)
  324. sql = strings.ReplaceAll(sql, "{{api_keys}}", sqlTableAPIKeys)
  325. sql = strings.ReplaceAll(sql, "{{prefix}}", config.SQLTablesPrefix)
  326. return sqlCommonExecSQLAndUpdateDBVersion(dbHandle, strings.Split(sql, ";"), 11)
  327. }
  328. func downgradeMySQLDatabaseFrom11To10(dbHandle *sql.DB) error {
  329. logger.InfoToConsole("downgrading database version: 11 -> 10")
  330. providerLog(logger.LevelInfo, "downgrading database version: 11 -> 10")
  331. sql := strings.ReplaceAll(mysqlV11DownSQL, "{{api_keys}}", sqlTableAPIKeys)
  332. return sqlCommonExecSQLAndUpdateDBVersion(dbHandle, strings.Split(sql, ";"), 10)
  333. }