mysql.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331
  1. // +build !nomysql
  2. package dataprovider
  3. import (
  4. "context"
  5. "crypto/x509"
  6. "database/sql"
  7. "errors"
  8. "fmt"
  9. "strings"
  10. "time"
  11. // we import go-sql-driver/mysql here to be able to disable MySQL support using a build tag
  12. _ "github.com/go-sql-driver/mysql"
  13. "github.com/drakkan/sftpgo/v2/logger"
  14. "github.com/drakkan/sftpgo/v2/version"
  15. "github.com/drakkan/sftpgo/v2/vfs"
  16. )
  17. const (
  18. mysqlInitialSQL = "CREATE TABLE `{{schema_version}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `version` integer NOT NULL);" +
  19. "CREATE TABLE `{{admins}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `username` varchar(255) NOT NULL UNIQUE, " +
  20. "`description` varchar(512) NULL, `password` varchar(255) NOT NULL, `email` varchar(255) NULL, `status` integer NOT NULL, " +
  21. "`permissions` longtext NOT NULL, `filters` longtext NULL, `additional_info` longtext NULL);" +
  22. "CREATE TABLE `{{folders}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `name` varchar(255) NOT NULL UNIQUE, " +
  23. "`description` varchar(512) NULL, `path` varchar(512) NULL, `used_quota_size` bigint NOT NULL, " +
  24. "`used_quota_files` integer NOT NULL, `last_quota_update` bigint NOT NULL, `filesystem` longtext NULL);" +
  25. "CREATE TABLE `{{users}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `username` varchar(255) NOT NULL UNIQUE, " +
  26. "`status` integer NOT NULL, `expiration_date` bigint NOT NULL, `description` varchar(512) NULL, `password` longtext NULL, " +
  27. "`public_keys` longtext NULL, `home_dir` varchar(512) NOT NULL, `uid` integer NOT NULL, `gid` integer NOT NULL, " +
  28. "`max_sessions` integer NOT NULL, `quota_size` bigint NOT NULL, `quota_files` integer NOT NULL, " +
  29. "`permissions` longtext NOT NULL, `used_quota_size` bigint NOT NULL, `used_quota_files` integer NOT NULL, " +
  30. "`last_quota_update` bigint NOT NULL, `upload_bandwidth` integer NOT NULL, `download_bandwidth` integer NOT NULL, " +
  31. "`last_login` bigint NOT NULL, `filters` longtext NULL, `filesystem` longtext NULL, `additional_info` longtext NULL);" +
  32. "CREATE TABLE `{{folders_mapping}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `virtual_path` varchar(512) NOT NULL, " +
  33. "`quota_size` bigint NOT NULL, `quota_files` integer NOT NULL, `folder_id` integer NOT NULL, `user_id` integer NOT NULL);" +
  34. "ALTER TABLE `{{folders_mapping}}` ADD CONSTRAINT `{{prefix}}unique_mapping` UNIQUE (`user_id`, `folder_id`);" +
  35. "ALTER TABLE `{{folders_mapping}}` ADD CONSTRAINT `{{prefix}}folders_mapping_folder_id_fk_folders_id` FOREIGN KEY (`folder_id`) REFERENCES `{{folders}}` (`id`) ON DELETE CASCADE;" +
  36. "ALTER TABLE `{{folders_mapping}}` ADD CONSTRAINT `{{prefix}}folders_mapping_user_id_fk_users_id` FOREIGN KEY (`user_id`) REFERENCES `{{users}}` (`id`) ON DELETE CASCADE;" +
  37. "INSERT INTO {{schema_version}} (version) VALUES (10);"
  38. mysqlV11SQL = "CREATE TABLE `{{api_keys}}` (`id` integer AUTO_INCREMENT NOT NULL PRIMARY KEY, `name` varchar(255) NOT NULL, `key_id` varchar(50) NOT NULL UNIQUE," +
  39. "`api_key` varchar(255) NOT NULL UNIQUE, `scope` integer NOT NULL, `created_at` bigint NOT NULL, `updated_at` bigint NOT NULL, `last_use_at` bigint NOT NULL, " +
  40. "`expires_at` bigint NOT NULL, `description` longtext NULL, `admin_id` integer NULL, `user_id` integer NULL);" +
  41. "ALTER TABLE `{{api_keys}}` ADD CONSTRAINT `{{prefix}}api_keys_admin_id_fk_admins_id` FOREIGN KEY (`admin_id`) REFERENCES `{{admins}}` (`id`) ON DELETE CASCADE;" +
  42. "ALTER TABLE `{{api_keys}}` ADD CONSTRAINT `{{prefix}}api_keys_user_id_fk_users_id` FOREIGN KEY (`user_id`) REFERENCES `{{users}}` (`id`) ON DELETE CASCADE;"
  43. mysqlV11DownSQL = "DROP TABLE `{{api_keys}}` CASCADE;"
  44. )
  45. // MySQLProvider auth provider for MySQL/MariaDB database
  46. type MySQLProvider struct {
  47. dbHandle *sql.DB
  48. }
  49. func init() {
  50. version.AddFeature("+mysql")
  51. }
  52. func initializeMySQLProvider() error {
  53. var err error
  54. dbHandle, err := sql.Open("mysql", getMySQLConnectionString(false))
  55. if err == nil {
  56. providerLog(logger.LevelDebug, "mysql database handle created, connection string: %#v, pool size: %v",
  57. getMySQLConnectionString(true), config.PoolSize)
  58. dbHandle.SetMaxOpenConns(config.PoolSize)
  59. if config.PoolSize > 0 {
  60. dbHandle.SetMaxIdleConns(config.PoolSize)
  61. } else {
  62. dbHandle.SetMaxIdleConns(2)
  63. }
  64. dbHandle.SetConnMaxLifetime(240 * time.Second)
  65. provider = &MySQLProvider{dbHandle: dbHandle}
  66. } else {
  67. providerLog(logger.LevelWarn, "error creating mysql database handler, connection string: %#v, error: %v",
  68. getMySQLConnectionString(true), err)
  69. }
  70. return err
  71. }
  72. func getMySQLConnectionString(redactedPwd bool) string {
  73. var connectionString string
  74. if config.ConnectionString == "" {
  75. password := config.Password
  76. if redactedPwd {
  77. password = "[redacted]"
  78. }
  79. connectionString = fmt.Sprintf("%v:%v@tcp([%v]:%v)/%v?charset=utf8&interpolateParams=true&timeout=10s&tls=%v&writeTimeout=10s&readTimeout=10s",
  80. config.Username, password, config.Host, config.Port, config.Name, getSSLMode())
  81. } else {
  82. connectionString = config.ConnectionString
  83. }
  84. return connectionString
  85. }
  86. func (p *MySQLProvider) checkAvailability() error {
  87. return sqlCommonCheckAvailability(p.dbHandle)
  88. }
  89. func (p *MySQLProvider) validateUserAndPass(username, password, ip, protocol string) (User, error) {
  90. return sqlCommonValidateUserAndPass(username, password, ip, protocol, p.dbHandle)
  91. }
  92. func (p *MySQLProvider) validateUserAndTLSCert(username, protocol string, tlsCert *x509.Certificate) (User, error) {
  93. return sqlCommonValidateUserAndTLSCertificate(username, protocol, tlsCert, p.dbHandle)
  94. }
  95. func (p *MySQLProvider) validateUserAndPubKey(username string, publicKey []byte) (User, string, error) {
  96. return sqlCommonValidateUserAndPubKey(username, publicKey, p.dbHandle)
  97. }
  98. func (p *MySQLProvider) updateQuota(username string, filesAdd int, sizeAdd int64, reset bool) error {
  99. return sqlCommonUpdateQuota(username, filesAdd, sizeAdd, reset, p.dbHandle)
  100. }
  101. func (p *MySQLProvider) getUsedQuota(username string) (int, int64, error) {
  102. return sqlCommonGetUsedQuota(username, p.dbHandle)
  103. }
  104. func (p *MySQLProvider) updateLastLogin(username string) error {
  105. return sqlCommonUpdateLastLogin(username, p.dbHandle)
  106. }
  107. func (p *MySQLProvider) userExists(username string) (User, error) {
  108. return sqlCommonGetUserByUsername(username, p.dbHandle)
  109. }
  110. func (p *MySQLProvider) addUser(user *User) error {
  111. return sqlCommonAddUser(user, p.dbHandle)
  112. }
  113. func (p *MySQLProvider) updateUser(user *User) error {
  114. return sqlCommonUpdateUser(user, p.dbHandle)
  115. }
  116. func (p *MySQLProvider) deleteUser(user *User) error {
  117. return sqlCommonDeleteUser(user, p.dbHandle)
  118. }
  119. func (p *MySQLProvider) dumpUsers() ([]User, error) {
  120. return sqlCommonDumpUsers(p.dbHandle)
  121. }
  122. func (p *MySQLProvider) getUsers(limit int, offset int, order string) ([]User, error) {
  123. return sqlCommonGetUsers(limit, offset, order, p.dbHandle)
  124. }
  125. func (p *MySQLProvider) dumpFolders() ([]vfs.BaseVirtualFolder, error) {
  126. return sqlCommonDumpFolders(p.dbHandle)
  127. }
  128. func (p *MySQLProvider) getFolders(limit, offset int, order string) ([]vfs.BaseVirtualFolder, error) {
  129. return sqlCommonGetFolders(limit, offset, order, p.dbHandle)
  130. }
  131. func (p *MySQLProvider) getFolderByName(name string) (vfs.BaseVirtualFolder, error) {
  132. ctx, cancel := context.WithTimeout(context.Background(), defaultSQLQueryTimeout)
  133. defer cancel()
  134. return sqlCommonGetFolderByName(ctx, name, p.dbHandle)
  135. }
  136. func (p *MySQLProvider) addFolder(folder *vfs.BaseVirtualFolder) error {
  137. return sqlCommonAddFolder(folder, p.dbHandle)
  138. }
  139. func (p *MySQLProvider) updateFolder(folder *vfs.BaseVirtualFolder) error {
  140. return sqlCommonUpdateFolder(folder, p.dbHandle)
  141. }
  142. func (p *MySQLProvider) deleteFolder(folder *vfs.BaseVirtualFolder) error {
  143. return sqlCommonDeleteFolder(folder, p.dbHandle)
  144. }
  145. func (p *MySQLProvider) updateFolderQuota(name string, filesAdd int, sizeAdd int64, reset bool) error {
  146. return sqlCommonUpdateFolderQuota(name, filesAdd, sizeAdd, reset, p.dbHandle)
  147. }
  148. func (p *MySQLProvider) getUsedFolderQuota(name string) (int, int64, error) {
  149. return sqlCommonGetFolderUsedQuota(name, p.dbHandle)
  150. }
  151. func (p *MySQLProvider) adminExists(username string) (Admin, error) {
  152. return sqlCommonGetAdminByUsername(username, p.dbHandle)
  153. }
  154. func (p *MySQLProvider) addAdmin(admin *Admin) error {
  155. return sqlCommonAddAdmin(admin, p.dbHandle)
  156. }
  157. func (p *MySQLProvider) updateAdmin(admin *Admin) error {
  158. return sqlCommonUpdateAdmin(admin, p.dbHandle)
  159. }
  160. func (p *MySQLProvider) deleteAdmin(admin *Admin) error {
  161. return sqlCommonDeleteAdmin(admin, p.dbHandle)
  162. }
  163. func (p *MySQLProvider) getAdmins(limit int, offset int, order string) ([]Admin, error) {
  164. return sqlCommonGetAdmins(limit, offset, order, p.dbHandle)
  165. }
  166. func (p *MySQLProvider) dumpAdmins() ([]Admin, error) {
  167. return sqlCommonDumpAdmins(p.dbHandle)
  168. }
  169. func (p *MySQLProvider) validateAdminAndPass(username, password, ip string) (Admin, error) {
  170. return sqlCommonValidateAdminAndPass(username, password, ip, p.dbHandle)
  171. }
  172. func (p *MySQLProvider) apiKeyExists(keyID string) (APIKey, error) {
  173. return sqlCommonGetAPIKeyByID(keyID, p.dbHandle)
  174. }
  175. func (p *MySQLProvider) addAPIKey(apiKey *APIKey) error {
  176. return sqlCommonAddAPIKey(apiKey, p.dbHandle)
  177. }
  178. func (p *MySQLProvider) updateAPIKey(apiKey *APIKey) error {
  179. return sqlCommonUpdateAPIKey(apiKey, p.dbHandle)
  180. }
  181. func (p *MySQLProvider) deleteAPIKeys(apiKey *APIKey) error {
  182. return sqlCommonDeleteAPIKey(apiKey, p.dbHandle)
  183. }
  184. func (p *MySQLProvider) getAPIKeys(limit int, offset int, order string) ([]APIKey, error) {
  185. return sqlCommonGetAPIKeys(limit, offset, order, p.dbHandle)
  186. }
  187. func (p *MySQLProvider) dumpAPIKeys() ([]APIKey, error) {
  188. return sqlCommonDumpAPIKeys(p.dbHandle)
  189. }
  190. func (p *MySQLProvider) updateAPIKeyLastUse(keyID string) error {
  191. return sqlCommonUpdateAPIKeyLastUse(keyID, p.dbHandle)
  192. }
  193. func (p *MySQLProvider) close() error {
  194. return p.dbHandle.Close()
  195. }
  196. func (p *MySQLProvider) reloadConfig() error {
  197. return nil
  198. }
  199. // initializeDatabase creates the initial database structure
  200. func (p *MySQLProvider) initializeDatabase() error {
  201. dbVersion, err := sqlCommonGetDatabaseVersion(p.dbHandle, false)
  202. if err == nil && dbVersion.Version > 0 {
  203. return ErrNoInitRequired
  204. }
  205. initialSQL := strings.ReplaceAll(mysqlInitialSQL, "{{schema_version}}", sqlTableSchemaVersion)
  206. initialSQL = strings.ReplaceAll(initialSQL, "{{admins}}", sqlTableAdmins)
  207. initialSQL = strings.ReplaceAll(initialSQL, "{{folders}}", sqlTableFolders)
  208. initialSQL = strings.ReplaceAll(initialSQL, "{{users}}", sqlTableUsers)
  209. initialSQL = strings.ReplaceAll(initialSQL, "{{folders_mapping}}", sqlTableFoldersMapping)
  210. initialSQL = strings.ReplaceAll(initialSQL, "{{prefix}}", config.SQLTablesPrefix)
  211. return sqlCommonExecSQLAndUpdateDBVersion(p.dbHandle, strings.Split(initialSQL, ";"), 10)
  212. }
  213. func (p *MySQLProvider) migrateDatabase() error {
  214. dbVersion, err := sqlCommonGetDatabaseVersion(p.dbHandle, true)
  215. if err != nil {
  216. return err
  217. }
  218. switch version := dbVersion.Version; {
  219. case version == sqlDatabaseVersion:
  220. providerLog(logger.LevelDebug, "sql database is up to date, current version: %v", version)
  221. return ErrNoInitRequired
  222. case version < 10:
  223. err = fmt.Errorf("database version %v is too old, please see the upgrading docs", version)
  224. providerLog(logger.LevelError, "%v", err)
  225. logger.ErrorToConsole("%v", err)
  226. return err
  227. case version == 10:
  228. return updateMySQLDatabaseFromV10(p.dbHandle)
  229. default:
  230. if version > sqlDatabaseVersion {
  231. providerLog(logger.LevelWarn, "database version %v is newer than the supported one: %v", version,
  232. sqlDatabaseVersion)
  233. logger.WarnToConsole("database version %v is newer than the supported one: %v", version,
  234. sqlDatabaseVersion)
  235. return nil
  236. }
  237. return fmt.Errorf("database version not handled: %v", version)
  238. }
  239. }
  240. func (p *MySQLProvider) revertDatabase(targetVersion int) error {
  241. dbVersion, err := sqlCommonGetDatabaseVersion(p.dbHandle, true)
  242. if err != nil {
  243. return err
  244. }
  245. if dbVersion.Version == targetVersion {
  246. return errors.New("current version match target version, nothing to do")
  247. }
  248. switch dbVersion.Version {
  249. case 11:
  250. return downgradeMySQLDatabaseFromV11(p.dbHandle)
  251. default:
  252. return fmt.Errorf("database version not handled: %v", dbVersion.Version)
  253. }
  254. }
  255. func updateMySQLDatabaseFromV10(dbHandle *sql.DB) error {
  256. return updateMySQLDatabaseFrom10To11(dbHandle)
  257. }
  258. func downgradeMySQLDatabaseFromV11(dbHandle *sql.DB) error {
  259. return downgradeMySQLDatabaseFrom11To10(dbHandle)
  260. }
  261. func updateMySQLDatabaseFrom10To11(dbHandle *sql.DB) error {
  262. logger.InfoToConsole("updating database version: 10 -> 11")
  263. providerLog(logger.LevelInfo, "updating database version: 10 -> 11")
  264. sql := strings.ReplaceAll(mysqlV11SQL, "{{users}}", sqlTableUsers)
  265. sql = strings.ReplaceAll(sql, "{{admins}}", sqlTableAdmins)
  266. sql = strings.ReplaceAll(sql, "{{api_keys}}", sqlTableAPIKeys)
  267. sql = strings.ReplaceAll(sql, "{{prefix}}", config.SQLTablesPrefix)
  268. return sqlCommonExecSQLAndUpdateDBVersion(dbHandle, strings.Split(sql, ";"), 11)
  269. }
  270. func downgradeMySQLDatabaseFrom11To10(dbHandle *sql.DB) error {
  271. logger.InfoToConsole("downgrading database version: 11 -> 10")
  272. providerLog(logger.LevelInfo, "downgrading database version: 11 -> 10")
  273. sql := strings.ReplaceAll(mysqlV11DownSQL, "{{api_keys}}", sqlTableAPIKeys)
  274. return sqlCommonExecSQLAndUpdateDBVersion(dbHandle, strings.Split(sql, ";"), 10)
  275. }