gitea源码

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278
  1. // Copyright 2020 The Gitea Authors. All rights reserved.
  2. // SPDX-License-Identifier: MIT
  3. package repo
  4. import (
  5. "bytes"
  6. "errors"
  7. "fmt"
  8. "net/http"
  9. "strings"
  10. "code.gitea.io/gitea/models/db"
  11. "code.gitea.io/gitea/models/organization"
  12. "code.gitea.io/gitea/models/perm"
  13. access_model "code.gitea.io/gitea/models/perm/access"
  14. repo_model "code.gitea.io/gitea/models/repo"
  15. user_model "code.gitea.io/gitea/models/user"
  16. "code.gitea.io/gitea/modules/git"
  17. "code.gitea.io/gitea/modules/graceful"
  18. "code.gitea.io/gitea/modules/lfs"
  19. "code.gitea.io/gitea/modules/log"
  20. base "code.gitea.io/gitea/modules/migration"
  21. "code.gitea.io/gitea/modules/setting"
  22. api "code.gitea.io/gitea/modules/structs"
  23. "code.gitea.io/gitea/modules/util"
  24. "code.gitea.io/gitea/modules/web"
  25. "code.gitea.io/gitea/services/context"
  26. "code.gitea.io/gitea/services/convert"
  27. "code.gitea.io/gitea/services/migrations"
  28. notify_service "code.gitea.io/gitea/services/notify"
  29. repo_service "code.gitea.io/gitea/services/repository"
  30. )
  31. // Migrate migrate remote git repository to gitea
  32. func Migrate(ctx *context.APIContext) {
  33. // swagger:operation POST /repos/migrate repository repoMigrate
  34. // ---
  35. // summary: Migrate a remote git repository
  36. // consumes:
  37. // - application/json
  38. // produces:
  39. // - application/json
  40. // parameters:
  41. // - name: body
  42. // in: body
  43. // schema:
  44. // "$ref": "#/definitions/MigrateRepoOptions"
  45. // responses:
  46. // "201":
  47. // "$ref": "#/responses/Repository"
  48. // "403":
  49. // "$ref": "#/responses/forbidden"
  50. // "409":
  51. // description: The repository with the same name already exists.
  52. // "422":
  53. // "$ref": "#/responses/validationError"
  54. form := web.GetForm(ctx).(*api.MigrateRepoOptions)
  55. // get repoOwner
  56. var (
  57. repoOwner *user_model.User
  58. err error
  59. )
  60. if len(form.RepoOwner) != 0 {
  61. repoOwner, err = user_model.GetUserByName(ctx, form.RepoOwner)
  62. } else if form.RepoOwnerID != 0 {
  63. repoOwner, err = user_model.GetUserByID(ctx, form.RepoOwnerID)
  64. } else {
  65. repoOwner = ctx.Doer
  66. }
  67. if err != nil {
  68. if user_model.IsErrUserNotExist(err) {
  69. ctx.APIError(http.StatusUnprocessableEntity, err)
  70. } else {
  71. ctx.APIErrorInternal(err)
  72. }
  73. return
  74. }
  75. if ctx.HasAPIError() {
  76. ctx.APIError(http.StatusUnprocessableEntity, ctx.GetErrMsg())
  77. return
  78. }
  79. if !ctx.Doer.IsAdmin {
  80. if !repoOwner.IsOrganization() && ctx.Doer.ID != repoOwner.ID {
  81. ctx.APIError(http.StatusForbidden, "Given user is not an organization.")
  82. return
  83. }
  84. if repoOwner.IsOrganization() {
  85. // Check ownership of organization.
  86. isOwner, err := organization.OrgFromUser(repoOwner).IsOwnedBy(ctx, ctx.Doer.ID)
  87. if err != nil {
  88. ctx.APIErrorInternal(err)
  89. return
  90. } else if !isOwner {
  91. ctx.APIError(http.StatusForbidden, "Given user is not owner of organization.")
  92. return
  93. }
  94. }
  95. }
  96. remoteAddr, err := git.ParseRemoteAddr(form.CloneAddr, form.AuthUsername, form.AuthPassword)
  97. if err == nil {
  98. err = migrations.IsMigrateURLAllowed(remoteAddr, ctx.Doer)
  99. }
  100. if err != nil {
  101. handleRemoteAddrError(ctx, err)
  102. return
  103. }
  104. gitServiceType := convert.ToGitServiceType(form.Service)
  105. if form.Mirror && setting.Mirror.DisableNewPull {
  106. ctx.APIError(http.StatusForbidden, errors.New("the site administrator has disabled the creation of new pull mirrors"))
  107. return
  108. }
  109. if setting.Repository.DisableMigrations {
  110. ctx.APIError(http.StatusForbidden, errors.New("the site administrator has disabled migrations"))
  111. return
  112. }
  113. form.LFS = form.LFS && setting.LFS.StartServer
  114. if form.LFS && len(form.LFSEndpoint) > 0 {
  115. ep := lfs.DetermineEndpoint("", form.LFSEndpoint)
  116. if ep == nil {
  117. ctx.APIErrorInternal(errors.New("the LFS endpoint is not valid"))
  118. return
  119. }
  120. err = migrations.IsMigrateURLAllowed(ep.String(), ctx.Doer)
  121. if err != nil {
  122. handleRemoteAddrError(ctx, err)
  123. return
  124. }
  125. }
  126. opts := migrations.MigrateOptions{
  127. CloneAddr: remoteAddr,
  128. RepoName: form.RepoName,
  129. Description: form.Description,
  130. Private: form.Private || setting.Repository.ForcePrivate,
  131. Mirror: form.Mirror,
  132. LFS: form.LFS,
  133. LFSEndpoint: form.LFSEndpoint,
  134. AuthUsername: form.AuthUsername,
  135. AuthPassword: form.AuthPassword,
  136. AuthToken: form.AuthToken,
  137. Wiki: form.Wiki,
  138. Issues: form.Issues,
  139. Milestones: form.Milestones,
  140. Labels: form.Labels,
  141. Comments: form.Issues || form.PullRequests,
  142. PullRequests: form.PullRequests,
  143. Releases: form.Releases,
  144. GitServiceType: gitServiceType,
  145. MirrorInterval: form.MirrorInterval,
  146. }
  147. if opts.Mirror {
  148. opts.Issues = false
  149. opts.Milestones = false
  150. opts.Labels = false
  151. opts.Comments = false
  152. opts.PullRequests = false
  153. opts.Releases = false
  154. }
  155. if gitServiceType == api.CodeCommitService {
  156. opts.AWSAccessKeyID = form.AWSAccessKeyID
  157. opts.AWSSecretAccessKey = form.AWSSecretAccessKey
  158. }
  159. repo, err := repo_service.CreateRepositoryDirectly(ctx, ctx.Doer, repoOwner, repo_service.CreateRepoOptions{
  160. Name: opts.RepoName,
  161. Description: opts.Description,
  162. OriginalURL: form.CloneAddr,
  163. GitServiceType: gitServiceType,
  164. IsPrivate: opts.Private || setting.Repository.ForcePrivate,
  165. IsMirror: opts.Mirror,
  166. Status: repo_model.RepositoryBeingMigrated,
  167. }, false)
  168. if err != nil {
  169. handleMigrateError(ctx, repoOwner, err)
  170. return
  171. }
  172. opts.MigrateToRepoID = repo.ID
  173. defer func() {
  174. if e := recover(); e != nil {
  175. var buf bytes.Buffer
  176. fmt.Fprintf(&buf, "Handler crashed with error: %v", log.Stack(2))
  177. err = errors.New(buf.String())
  178. }
  179. if err == nil {
  180. notify_service.MigrateRepository(ctx, ctx.Doer, repoOwner, repo)
  181. return
  182. }
  183. if repo != nil {
  184. if errDelete := repo_service.DeleteRepositoryDirectly(ctx, repo.ID); errDelete != nil {
  185. log.Error("DeleteRepository: %v", errDelete)
  186. }
  187. }
  188. }()
  189. if repo, err = migrations.MigrateRepository(graceful.GetManager().HammerContext(), ctx.Doer, repoOwner.Name, opts, nil); err != nil {
  190. handleMigrateError(ctx, repoOwner, err)
  191. return
  192. }
  193. log.Trace("Repository migrated: %s/%s", repoOwner.Name, form.RepoName)
  194. ctx.JSON(http.StatusCreated, convert.ToRepo(ctx, repo, access_model.Permission{AccessMode: perm.AccessModeAdmin}))
  195. }
  196. func handleMigrateError(ctx *context.APIContext, repoOwner *user_model.User, err error) {
  197. switch {
  198. case repo_model.IsErrRepoAlreadyExist(err):
  199. ctx.APIError(http.StatusConflict, "The repository with the same name already exists.")
  200. case repo_model.IsErrRepoFilesAlreadyExist(err):
  201. ctx.APIError(http.StatusConflict, "Files already exist for this repository. Adopt them or delete them.")
  202. case migrations.IsRateLimitError(err):
  203. ctx.APIError(http.StatusUnprocessableEntity, "Remote visit addressed rate limitation.")
  204. case migrations.IsTwoFactorAuthError(err):
  205. ctx.APIError(http.StatusUnprocessableEntity, "Remote visit required two factors authentication.")
  206. case repo_model.IsErrReachLimitOfRepo(err):
  207. ctx.APIError(http.StatusUnprocessableEntity, fmt.Sprintf("You have already reached your limit of %d repositories.", repoOwner.MaxCreationLimit()))
  208. case db.IsErrNameReserved(err):
  209. ctx.APIError(http.StatusUnprocessableEntity, fmt.Sprintf("The username '%s' is reserved.", err.(db.ErrNameReserved).Name))
  210. case db.IsErrNameCharsNotAllowed(err):
  211. ctx.APIError(http.StatusUnprocessableEntity, fmt.Sprintf("The username '%s' contains invalid characters.", err.(db.ErrNameCharsNotAllowed).Name))
  212. case db.IsErrNamePatternNotAllowed(err):
  213. ctx.APIError(http.StatusUnprocessableEntity, fmt.Sprintf("The pattern '%s' is not allowed in a username.", err.(db.ErrNamePatternNotAllowed).Pattern))
  214. case git.IsErrInvalidCloneAddr(err):
  215. ctx.APIError(http.StatusUnprocessableEntity, err)
  216. case base.IsErrNotSupported(err):
  217. ctx.APIError(http.StatusUnprocessableEntity, err)
  218. default:
  219. err = util.SanitizeErrorCredentialURLs(err)
  220. if strings.Contains(err.Error(), "Authentication failed") ||
  221. strings.Contains(err.Error(), "Bad credentials") ||
  222. strings.Contains(err.Error(), "could not read Username") {
  223. ctx.APIError(http.StatusUnprocessableEntity, fmt.Sprintf("Authentication failed: %v.", err))
  224. } else if strings.Contains(err.Error(), "fatal:") {
  225. ctx.APIError(http.StatusUnprocessableEntity, fmt.Sprintf("Migration failed: %v.", err))
  226. } else {
  227. ctx.APIErrorInternal(err)
  228. }
  229. }
  230. }
  231. func handleRemoteAddrError(ctx *context.APIContext, err error) {
  232. if git.IsErrInvalidCloneAddr(err) {
  233. addrErr := err.(*git.ErrInvalidCloneAddr)
  234. switch {
  235. case addrErr.IsURLError:
  236. ctx.APIError(http.StatusUnprocessableEntity, err)
  237. case addrErr.IsPermissionDenied:
  238. if addrErr.LocalPath {
  239. ctx.APIError(http.StatusUnprocessableEntity, "You are not allowed to import local repositories.")
  240. } else {
  241. ctx.APIError(http.StatusUnprocessableEntity, "You can not import from disallowed hosts.")
  242. }
  243. case addrErr.IsInvalidPath:
  244. ctx.APIError(http.StatusUnprocessableEntity, "Invalid local path, it does not exist or not a directory.")
  245. default:
  246. ctx.APIErrorInternal(fmt.Errorf("unknown error type (ErrInvalidCloneAddr): %w", err))
  247. }
  248. } else {
  249. ctx.APIErrorInternal(err)
  250. }
  251. }