publicApi.ts 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152
  1. import * as express from 'express'
  2. import { acceptPendingDataObjects } from '../../runtime/extrinsics'
  3. import {
  4. UploadTokenRequest,
  5. UploadTokenBody,
  6. createUploadToken,
  7. verifyTokenSignature,
  8. } from '../../helpers/auth'
  9. import { hashFile } from '../../../services/helpers/hashing'
  10. import { KeyringPair } from '@polkadot/keyring/types'
  11. import { ApiPromise } from '@polkadot/api'
  12. import { parseBagId } from '../../../services/helpers/bagIdParser'
  13. import fs from 'fs'
  14. import { Membership } from '@joystream/types/members'
  15. const fsPromises = fs.promises
  16. interface UploadRequest {
  17. dataObjectId: number
  18. storageBucketId: number
  19. bagId: string
  20. }
  21. export async function upload(
  22. req: express.Request,
  23. res: express.Response
  24. ): Promise<void> {
  25. const uploadRequest: UploadRequest = req.body
  26. try {
  27. const fileObj = getFileObject(req)
  28. const hash = await hashFile(fileObj.path)
  29. const newPath = fileObj.path.replace(fileObj.filename, hash)
  30. // Overwrites existing file.
  31. await fsPromises.rename(fileObj.path, newPath)
  32. const api = getApi(res)
  33. const bagId = parseBagId(api, uploadRequest.bagId)
  34. await acceptPendingDataObjects(
  35. api,
  36. bagId,
  37. getAccount(res),
  38. getWorkerId(res),
  39. uploadRequest.storageBucketId,
  40. [uploadRequest.dataObjectId]
  41. )
  42. res.status(201).json({
  43. file: 'received',
  44. })
  45. } catch (err) {
  46. res.status(410).json({
  47. type: 'upload',
  48. message: err.toString(),
  49. })
  50. }
  51. }
  52. export async function authToken(
  53. req: express.Request,
  54. res: express.Response
  55. ): Promise<void> {
  56. try {
  57. const account = getAccount(res)
  58. const tokenRequest = getTokenRequest(req)
  59. const api = getApi(res)
  60. await validateTokenRequest(api, tokenRequest)
  61. const tokenBody: UploadTokenBody = {
  62. timestamp: Date.now(),
  63. ...tokenRequest.data,
  64. }
  65. const signedToken = createUploadToken(tokenBody, account)
  66. res.status(201).json({
  67. token: signedToken,
  68. })
  69. } catch (err) {
  70. res.status(410).json({
  71. type: 'authtoken',
  72. message: err.toString(),
  73. })
  74. }
  75. }
  76. function getFileObject(req: express.Request): Express.Multer.File {
  77. if (req.file) {
  78. return req.file
  79. }
  80. const files = req.files as Express.Multer.File[]
  81. if (files && files.length > 0) {
  82. return files[0]
  83. }
  84. throw new Error('No file uploaded')
  85. }
  86. function getWorkerId(res: express.Response): number {
  87. if (res.locals.workerId || res.locals.workerId === 0) {
  88. return res.locals.workerId
  89. }
  90. throw new Error('No Joystream worker ID loaded.')
  91. }
  92. function getAccount(res: express.Response): KeyringPair {
  93. if (res.locals.storageProviderAccount) {
  94. return res.locals.storageProviderAccount
  95. }
  96. throw new Error('No Joystream account loaded.')
  97. }
  98. function getApi(res: express.Response): ApiPromise {
  99. if (res.locals.api) {
  100. return res.locals.api
  101. }
  102. throw new Error('No Joystream API loaded.')
  103. }
  104. function getTokenRequest(req: express.Request): UploadTokenRequest {
  105. const tokenRequest = req.body as UploadTokenRequest
  106. if (tokenRequest) {
  107. return tokenRequest
  108. }
  109. throw new Error('No token request provided.')
  110. }
  111. async function validateTokenRequest(
  112. api: ApiPromise,
  113. tokenRequest: UploadTokenRequest
  114. ): Promise<void> {
  115. const result = verifyTokenSignature(tokenRequest, tokenRequest.data.accountId)
  116. if (!result) {
  117. throw new Error('Invalid upload token request signature.')
  118. }
  119. const membership = (await api.query.members.membershipById(
  120. tokenRequest.data.memberId
  121. )) as Membership
  122. if (
  123. membership.controller_account.toString() !== tokenRequest.data.accountId
  124. ) {
  125. throw new Error(`Provided controller account and member id don't match.`)
  126. }
  127. }