gitea源码

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608
  1. // Copyright 2014 The Gogs Authors. All rights reserved.
  2. // Copyright 2021 The Gitea Authors. All rights reserved.
  3. // SPDX-License-Identifier: MIT
  4. package install
  5. import (
  6. "net/http"
  7. "net/mail"
  8. "os"
  9. "os/exec"
  10. "path/filepath"
  11. "slices"
  12. "strconv"
  13. "strings"
  14. "time"
  15. "code.gitea.io/gitea/models/db"
  16. db_install "code.gitea.io/gitea/models/db/install"
  17. system_model "code.gitea.io/gitea/models/system"
  18. user_model "code.gitea.io/gitea/models/user"
  19. "code.gitea.io/gitea/modules/auth/password/hash"
  20. "code.gitea.io/gitea/modules/generate"
  21. "code.gitea.io/gitea/modules/graceful"
  22. "code.gitea.io/gitea/modules/log"
  23. "code.gitea.io/gitea/modules/optional"
  24. "code.gitea.io/gitea/modules/reqctx"
  25. "code.gitea.io/gitea/modules/setting"
  26. "code.gitea.io/gitea/modules/templates"
  27. "code.gitea.io/gitea/modules/timeutil"
  28. "code.gitea.io/gitea/modules/translation"
  29. "code.gitea.io/gitea/modules/user"
  30. "code.gitea.io/gitea/modules/web"
  31. "code.gitea.io/gitea/modules/web/middleware"
  32. "code.gitea.io/gitea/routers/common"
  33. auth_service "code.gitea.io/gitea/services/auth"
  34. "code.gitea.io/gitea/services/context"
  35. "code.gitea.io/gitea/services/forms"
  36. "code.gitea.io/gitea/services/versioned_migration"
  37. "gitea.com/go-chi/session"
  38. )
  39. const (
  40. // tplInstall template for installation page
  41. tplInstall templates.TplName = "install"
  42. tplPostInstall templates.TplName = "post-install"
  43. )
  44. // getSupportedDbTypeNames returns a slice for supported database types and names. The slice is used to keep the order
  45. func getSupportedDbTypeNames() (dbTypeNames []map[string]string) {
  46. for _, t := range setting.SupportedDatabaseTypes {
  47. dbTypeNames = append(dbTypeNames, map[string]string{"type": t, "name": setting.DatabaseTypeNames[t]})
  48. }
  49. return dbTypeNames
  50. }
  51. // Contexter prepare for rendering installation page
  52. func Contexter() func(next http.Handler) http.Handler {
  53. rnd := templates.HTMLRenderer()
  54. dbTypeNames := getSupportedDbTypeNames()
  55. envConfigKeys := setting.CollectEnvConfigKeys()
  56. return func(next http.Handler) http.Handler {
  57. return http.HandlerFunc(func(resp http.ResponseWriter, req *http.Request) {
  58. base := context.NewBaseContext(resp, req)
  59. ctx := context.NewWebContext(base, rnd, session.GetSession(req))
  60. ctx.Data.MergeFrom(middleware.CommonTemplateContextData())
  61. ctx.Data.MergeFrom(reqctx.ContextData{
  62. "Title": ctx.Locale.Tr("install.install"),
  63. "PageIsInstall": true,
  64. "DbTypeNames": dbTypeNames,
  65. "EnvConfigKeys": envConfigKeys,
  66. "CustomConfFile": setting.CustomConf,
  67. "AllLangs": translation.AllLangs(),
  68. "PasswordHashAlgorithms": hash.RecommendedHashAlgorithms,
  69. })
  70. next.ServeHTTP(resp, ctx.Req)
  71. })
  72. }
  73. }
  74. // Install render installation page
  75. func Install(ctx *context.Context) {
  76. if setting.InstallLock {
  77. InstallDone(ctx)
  78. return
  79. }
  80. form := forms.InstallForm{}
  81. // Database settings
  82. form.DbHost = setting.Database.Host
  83. form.DbUser = setting.Database.User
  84. form.DbPasswd = setting.Database.Passwd
  85. form.DbName = setting.Database.Name
  86. form.DbPath = setting.Database.Path
  87. form.DbSchema = setting.Database.Schema
  88. form.SSLMode = setting.Database.SSLMode
  89. curDBType := setting.Database.Type.String()
  90. if !slices.Contains(setting.SupportedDatabaseTypes, curDBType) {
  91. curDBType = "mysql"
  92. }
  93. ctx.Data["CurDbType"] = curDBType
  94. // Application general settings
  95. form.AppName = setting.AppName
  96. form.RepoRootPath = setting.RepoRootPath
  97. form.LFSRootPath = setting.LFS.Storage.Path
  98. // Note(unknown): it's hard for Windows users change a running user,
  99. // so just use current one if config says default.
  100. if setting.IsWindows && setting.RunUser == "git" {
  101. form.RunUser = user.CurrentUsername()
  102. } else {
  103. form.RunUser = setting.RunUser
  104. }
  105. form.Domain = setting.Domain
  106. form.SSHPort = setting.SSH.Port
  107. form.HTTPPort = setting.HTTPPort
  108. form.AppURL = setting.AppURL
  109. form.LogRootPath = setting.Log.RootPath
  110. // E-mail service settings
  111. if setting.MailService != nil {
  112. form.SMTPAddr = setting.MailService.SMTPAddr
  113. form.SMTPPort = setting.MailService.SMTPPort
  114. form.SMTPFrom = setting.MailService.From
  115. form.SMTPUser = setting.MailService.User
  116. form.SMTPPasswd = setting.MailService.Passwd
  117. }
  118. form.RegisterConfirm = setting.Service.RegisterEmailConfirm
  119. form.MailNotify = setting.Service.EnableNotifyMail
  120. // Server and other services settings
  121. form.OfflineMode = setting.OfflineMode
  122. form.DisableGravatar = setting.DisableGravatar // when installing, there is no database connection so that given a default value
  123. form.EnableFederatedAvatar = setting.EnableFederatedAvatar // when installing, there is no database connection so that given a default value
  124. form.EnableOpenIDSignIn = setting.Service.EnableOpenIDSignIn
  125. form.EnableOpenIDSignUp = setting.Service.EnableOpenIDSignUp
  126. form.DisableRegistration = setting.Service.DisableRegistration
  127. form.AllowOnlyExternalRegistration = setting.Service.AllowOnlyExternalRegistration
  128. form.EnableCaptcha = setting.Service.EnableCaptcha
  129. form.RequireSignInView = setting.Service.RequireSignInViewStrict
  130. form.DefaultKeepEmailPrivate = setting.Service.DefaultKeepEmailPrivate
  131. form.DefaultAllowCreateOrganization = setting.Service.DefaultAllowCreateOrganization
  132. form.DefaultEnableTimetracking = setting.Service.DefaultEnableTimetracking
  133. form.NoReplyAddress = setting.Service.NoReplyAddress
  134. form.PasswordAlgorithm = hash.ConfigHashAlgorithm(setting.PasswordHashAlgo)
  135. middleware.AssignForm(form, ctx.Data)
  136. ctx.HTML(http.StatusOK, tplInstall)
  137. }
  138. func checkDatabase(ctx *context.Context, form *forms.InstallForm) bool {
  139. var err error
  140. if (setting.Database.Type == "sqlite3") &&
  141. len(setting.Database.Path) == 0 {
  142. ctx.Data["Err_DbPath"] = true
  143. ctx.RenderWithErr(ctx.Tr("install.err_empty_db_path"), tplInstall, form)
  144. return false
  145. }
  146. // Check if the user is trying to re-install in an installed database
  147. db.UnsetDefaultEngine()
  148. defer db.UnsetDefaultEngine()
  149. if err = db.InitEngine(ctx); err != nil {
  150. if strings.Contains(err.Error(), `Unknown database type: sqlite3`) {
  151. ctx.Data["Err_DbType"] = true
  152. ctx.RenderWithErr(ctx.Tr("install.sqlite3_not_available", "https://docs.gitea.com/installation/install-from-binary"), tplInstall, form)
  153. } else {
  154. ctx.Data["Err_DbSetting"] = true
  155. ctx.RenderWithErr(ctx.Tr("install.invalid_db_setting", err), tplInstall, form)
  156. }
  157. return false
  158. }
  159. err = db_install.CheckDatabaseConnection(ctx)
  160. if err != nil {
  161. ctx.Data["Err_DbSetting"] = true
  162. ctx.RenderWithErr(ctx.Tr("install.invalid_db_setting", err), tplInstall, form)
  163. return false
  164. }
  165. hasPostInstallationUser, err := db_install.HasPostInstallationUsers(ctx)
  166. if err != nil {
  167. ctx.Data["Err_DbSetting"] = true
  168. ctx.RenderWithErr(ctx.Tr("install.invalid_db_table", "user", err), tplInstall, form)
  169. return false
  170. }
  171. dbMigrationVersion, err := db_install.GetMigrationVersion(ctx)
  172. if err != nil {
  173. ctx.Data["Err_DbSetting"] = true
  174. ctx.RenderWithErr(ctx.Tr("install.invalid_db_table", "version", err), tplInstall, form)
  175. return false
  176. }
  177. if hasPostInstallationUser && dbMigrationVersion > 0 {
  178. log.Error("The database is likely to have been used by Gitea before, database migration version=%d", dbMigrationVersion)
  179. confirmed := form.ReinstallConfirmFirst && form.ReinstallConfirmSecond && form.ReinstallConfirmThird
  180. if !confirmed {
  181. ctx.Data["Err_DbInstalledBefore"] = true
  182. ctx.RenderWithErr(ctx.Tr("install.reinstall_error"), tplInstall, form)
  183. return false
  184. }
  185. log.Info("User confirmed re-installation of Gitea into a pre-existing database")
  186. }
  187. if hasPostInstallationUser || dbMigrationVersion > 0 {
  188. log.Info("Gitea will be installed in a database with: hasPostInstallationUser=%v, dbMigrationVersion=%v", hasPostInstallationUser, dbMigrationVersion)
  189. }
  190. return true
  191. }
  192. // SubmitInstall response for submit install items
  193. func SubmitInstall(ctx *context.Context) {
  194. if setting.InstallLock {
  195. InstallDone(ctx)
  196. return
  197. }
  198. var err error
  199. form := *web.GetForm(ctx).(*forms.InstallForm)
  200. // fix form values
  201. if form.AppURL != "" && form.AppURL[len(form.AppURL)-1] != '/' {
  202. form.AppURL += "/"
  203. }
  204. ctx.Data["CurDbType"] = form.DbType
  205. if ctx.HasError() {
  206. ctx.Data["Err_SMTP"] = ctx.Data["Err_SMTPUser"] != nil
  207. ctx.Data["Err_Admin"] = ctx.Data["Err_AdminName"] != nil || ctx.Data["Err_AdminPasswd"] != nil || ctx.Data["Err_AdminEmail"] != nil
  208. ctx.HTML(http.StatusOK, tplInstall)
  209. return
  210. }
  211. if _, err = exec.LookPath("git"); err != nil {
  212. ctx.RenderWithErr(ctx.Tr("install.test_git_failed", err), tplInstall, &form)
  213. return
  214. }
  215. // ---- Basic checks are passed, now test configuration.
  216. // Test database setting.
  217. setting.Database.Type = setting.DatabaseType(form.DbType)
  218. setting.Database.Host = form.DbHost
  219. setting.Database.User = form.DbUser
  220. setting.Database.Passwd = form.DbPasswd
  221. setting.Database.Name = form.DbName
  222. setting.Database.Schema = form.DbSchema
  223. setting.Database.SSLMode = form.SSLMode
  224. setting.Database.Path = form.DbPath
  225. setting.Database.LogSQL = !setting.IsProd
  226. if !checkDatabase(ctx, &form) {
  227. return
  228. }
  229. // Prepare AppDataPath, it is very important for Gitea
  230. if err = setting.PrepareAppDataPath(); err != nil {
  231. ctx.RenderWithErr(ctx.Tr("install.invalid_app_data_path", err), tplInstall, &form)
  232. return
  233. }
  234. // Test repository root path.
  235. form.RepoRootPath = strings.ReplaceAll(form.RepoRootPath, "\\", "/")
  236. if err = os.MkdirAll(form.RepoRootPath, os.ModePerm); err != nil {
  237. ctx.Data["Err_RepoRootPath"] = true
  238. ctx.RenderWithErr(ctx.Tr("install.invalid_repo_path", err), tplInstall, &form)
  239. return
  240. }
  241. // Test LFS root path if not empty, empty meaning disable LFS
  242. if form.LFSRootPath != "" {
  243. form.LFSRootPath = strings.ReplaceAll(form.LFSRootPath, "\\", "/")
  244. if err := os.MkdirAll(form.LFSRootPath, os.ModePerm); err != nil {
  245. ctx.Data["Err_LFSRootPath"] = true
  246. ctx.RenderWithErr(ctx.Tr("install.invalid_lfs_path", err), tplInstall, &form)
  247. return
  248. }
  249. }
  250. // Test log root path.
  251. form.LogRootPath = strings.ReplaceAll(form.LogRootPath, "\\", "/")
  252. if err = os.MkdirAll(form.LogRootPath, os.ModePerm); err != nil {
  253. ctx.Data["Err_LogRootPath"] = true
  254. ctx.RenderWithErr(ctx.Tr("install.invalid_log_root_path", err), tplInstall, &form)
  255. return
  256. }
  257. currentUser, match := setting.IsRunUserMatchCurrentUser(form.RunUser)
  258. if !match {
  259. ctx.Data["Err_RunUser"] = true
  260. ctx.RenderWithErr(ctx.Tr("install.run_user_not_match", form.RunUser, currentUser), tplInstall, &form)
  261. return
  262. }
  263. // Check logic loophole between disable self-registration and no admin account.
  264. if form.DisableRegistration && len(form.AdminName) == 0 {
  265. ctx.Data["Err_Services"] = true
  266. ctx.Data["Err_Admin"] = true
  267. ctx.RenderWithErr(ctx.Tr("install.no_admin_and_disable_registration"), tplInstall, form)
  268. return
  269. }
  270. // Check admin user creation
  271. if len(form.AdminName) > 0 {
  272. // Ensure AdminName is valid
  273. if err := user_model.IsUsableUsername(form.AdminName); err != nil {
  274. ctx.Data["Err_Admin"] = true
  275. ctx.Data["Err_AdminName"] = true
  276. if db.IsErrNameReserved(err) {
  277. ctx.RenderWithErr(ctx.Tr("install.err_admin_name_is_reserved"), tplInstall, form)
  278. return
  279. } else if db.IsErrNamePatternNotAllowed(err) {
  280. ctx.RenderWithErr(ctx.Tr("install.err_admin_name_pattern_not_allowed"), tplInstall, form)
  281. return
  282. }
  283. ctx.RenderWithErr(ctx.Tr("install.err_admin_name_is_invalid"), tplInstall, form)
  284. return
  285. }
  286. // Check Admin email
  287. if len(form.AdminEmail) == 0 {
  288. ctx.Data["Err_Admin"] = true
  289. ctx.Data["Err_AdminEmail"] = true
  290. ctx.RenderWithErr(ctx.Tr("install.err_empty_admin_email"), tplInstall, form)
  291. return
  292. }
  293. // Check admin password.
  294. if len(form.AdminPasswd) == 0 {
  295. ctx.Data["Err_Admin"] = true
  296. ctx.Data["Err_AdminPasswd"] = true
  297. ctx.RenderWithErr(ctx.Tr("install.err_empty_admin_password"), tplInstall, form)
  298. return
  299. }
  300. if form.AdminPasswd != form.AdminConfirmPasswd {
  301. ctx.Data["Err_Admin"] = true
  302. ctx.Data["Err_AdminPasswd"] = true
  303. ctx.RenderWithErr(ctx.Tr("form.password_not_match"), tplInstall, form)
  304. return
  305. }
  306. }
  307. // Init the engine with migration
  308. if err = db.InitEngineWithMigration(ctx, versioned_migration.Migrate); err != nil {
  309. db.UnsetDefaultEngine()
  310. ctx.Data["Err_DbSetting"] = true
  311. ctx.RenderWithErr(ctx.Tr("install.invalid_db_setting", err), tplInstall, &form)
  312. return
  313. }
  314. // Save settings.
  315. cfg, err := setting.NewConfigProviderFromFile(setting.CustomConf)
  316. if err != nil {
  317. log.Error("Failed to load custom conf '%s': %v", setting.CustomConf, err)
  318. }
  319. cfg.Section("").Key("APP_NAME").SetValue(form.AppName)
  320. cfg.Section("").Key("RUN_USER").SetValue(form.RunUser)
  321. cfg.Section("").Key("WORK_PATH").SetValue(setting.AppWorkPath)
  322. cfg.Section("").Key("RUN_MODE").SetValue("prod")
  323. cfg.Section("database").Key("DB_TYPE").SetValue(setting.Database.Type.String())
  324. cfg.Section("database").Key("HOST").SetValue(setting.Database.Host)
  325. cfg.Section("database").Key("NAME").SetValue(setting.Database.Name)
  326. cfg.Section("database").Key("USER").SetValue(setting.Database.User)
  327. cfg.Section("database").Key("PASSWD").SetValue(setting.Database.Passwd)
  328. cfg.Section("database").Key("SCHEMA").SetValue(setting.Database.Schema)
  329. cfg.Section("database").Key("SSL_MODE").SetValue(setting.Database.SSLMode)
  330. cfg.Section("database").Key("PATH").SetValue(setting.Database.Path)
  331. cfg.Section("database").Key("LOG_SQL").SetValue("false") // LOG_SQL is rarely helpful
  332. cfg.Section("repository").Key("ROOT").SetValue(form.RepoRootPath)
  333. cfg.Section("server").Key("SSH_DOMAIN").SetValue(form.Domain)
  334. cfg.Section("server").Key("DOMAIN").SetValue(form.Domain)
  335. cfg.Section("server").Key("HTTP_PORT").SetValue(form.HTTPPort)
  336. cfg.Section("server").Key("ROOT_URL").SetValue(form.AppURL)
  337. cfg.Section("server").Key("APP_DATA_PATH").SetValue(setting.AppDataPath)
  338. if form.SSHPort == 0 {
  339. cfg.Section("server").Key("DISABLE_SSH").SetValue("true")
  340. } else {
  341. cfg.Section("server").Key("DISABLE_SSH").SetValue("false")
  342. cfg.Section("server").Key("SSH_PORT").SetValue(strconv.Itoa(form.SSHPort))
  343. }
  344. if form.LFSRootPath != "" {
  345. cfg.Section("server").Key("LFS_START_SERVER").SetValue("true")
  346. cfg.Section("lfs").Key("PATH").SetValue(form.LFSRootPath)
  347. var lfsJwtSecret string
  348. if _, lfsJwtSecret, err = generate.NewJwtSecretWithBase64(); err != nil {
  349. ctx.RenderWithErr(ctx.Tr("install.lfs_jwt_secret_failed", err), tplInstall, &form)
  350. return
  351. }
  352. cfg.Section("server").Key("LFS_JWT_SECRET").SetValue(lfsJwtSecret)
  353. } else {
  354. cfg.Section("server").Key("LFS_START_SERVER").SetValue("false")
  355. }
  356. if len(strings.TrimSpace(form.SMTPAddr)) > 0 {
  357. if _, err := mail.ParseAddress(form.SMTPFrom); err != nil {
  358. ctx.RenderWithErr(ctx.Tr("install.smtp_from_invalid"), tplInstall, &form)
  359. return
  360. }
  361. cfg.Section("mailer").Key("ENABLED").SetValue("true")
  362. cfg.Section("mailer").Key("SMTP_ADDR").SetValue(form.SMTPAddr)
  363. cfg.Section("mailer").Key("SMTP_PORT").SetValue(form.SMTPPort)
  364. cfg.Section("mailer").Key("FROM").SetValue(form.SMTPFrom)
  365. cfg.Section("mailer").Key("USER").SetValue(form.SMTPUser)
  366. cfg.Section("mailer").Key("PASSWD").SetValue(form.SMTPPasswd)
  367. } else {
  368. cfg.Section("mailer").Key("ENABLED").SetValue("false")
  369. }
  370. cfg.Section("service").Key("REGISTER_EMAIL_CONFIRM").SetValue(strconv.FormatBool(form.RegisterConfirm))
  371. cfg.Section("service").Key("ENABLE_NOTIFY_MAIL").SetValue(strconv.FormatBool(form.MailNotify))
  372. cfg.Section("server").Key("OFFLINE_MODE").SetValue(strconv.FormatBool(form.OfflineMode))
  373. if err := system_model.SetSettings(ctx, map[string]string{
  374. setting.Config().Picture.DisableGravatar.DynKey(): strconv.FormatBool(form.DisableGravatar),
  375. setting.Config().Picture.EnableFederatedAvatar.DynKey(): strconv.FormatBool(form.EnableFederatedAvatar),
  376. }); err != nil {
  377. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  378. return
  379. }
  380. cfg.Section("openid").Key("ENABLE_OPENID_SIGNIN").SetValue(strconv.FormatBool(form.EnableOpenIDSignIn))
  381. cfg.Section("openid").Key("ENABLE_OPENID_SIGNUP").SetValue(strconv.FormatBool(form.EnableOpenIDSignUp))
  382. cfg.Section("service").Key("DISABLE_REGISTRATION").SetValue(strconv.FormatBool(form.DisableRegistration))
  383. cfg.Section("service").Key("ALLOW_ONLY_EXTERNAL_REGISTRATION").SetValue(strconv.FormatBool(form.AllowOnlyExternalRegistration))
  384. cfg.Section("service").Key("ENABLE_CAPTCHA").SetValue(strconv.FormatBool(form.EnableCaptcha))
  385. cfg.Section("service").Key("REQUIRE_SIGNIN_VIEW").SetValue(strconv.FormatBool(form.RequireSignInView))
  386. cfg.Section("service").Key("DEFAULT_KEEP_EMAIL_PRIVATE").SetValue(strconv.FormatBool(form.DefaultKeepEmailPrivate))
  387. cfg.Section("service").Key("DEFAULT_ALLOW_CREATE_ORGANIZATION").SetValue(strconv.FormatBool(form.DefaultAllowCreateOrganization))
  388. cfg.Section("service").Key("DEFAULT_ENABLE_TIMETRACKING").SetValue(strconv.FormatBool(form.DefaultEnableTimetracking))
  389. cfg.Section("service").Key("NO_REPLY_ADDRESS").SetValue(form.NoReplyAddress)
  390. cfg.Section("cron.update_checker").Key("ENABLED").SetValue(strconv.FormatBool(form.EnableUpdateChecker))
  391. cfg.Section("session").Key("PROVIDER").SetValue("file")
  392. cfg.Section("log").Key("MODE").MustString("console")
  393. cfg.Section("log").Key("LEVEL").SetValue(setting.Log.Level.String())
  394. cfg.Section("log").Key("ROOT_PATH").SetValue(form.LogRootPath)
  395. cfg.Section("repository.pull-request").Key("DEFAULT_MERGE_STYLE").SetValue("merge")
  396. cfg.Section("repository.signing").Key("DEFAULT_TRUST_MODEL").SetValue("committer")
  397. cfg.Section("security").Key("INSTALL_LOCK").SetValue("true")
  398. // the internal token could be read from INTERNAL_TOKEN or INTERNAL_TOKEN_URI (the file is guaranteed to be non-empty)
  399. // if there is no InternalToken, generate one and save to security.INTERNAL_TOKEN
  400. if setting.InternalToken == "" {
  401. var internalToken string
  402. if internalToken, err = generate.NewInternalToken(); err != nil {
  403. ctx.RenderWithErr(ctx.Tr("install.internal_token_failed", err), tplInstall, &form)
  404. return
  405. }
  406. cfg.Section("security").Key("INTERNAL_TOKEN").SetValue(internalToken)
  407. }
  408. // FIXME: at the moment, no matter oauth2 is enabled or not, it must generate a "oauth2 JWT_SECRET"
  409. // see the "loadOAuth2From" in "setting/oauth2.go"
  410. if !cfg.Section("oauth2").HasKey("JWT_SECRET") && !cfg.Section("oauth2").HasKey("JWT_SECRET_URI") {
  411. _, jwtSecretBase64, err := generate.NewJwtSecretWithBase64()
  412. if err != nil {
  413. ctx.RenderWithErr(ctx.Tr("install.secret_key_failed", err), tplInstall, &form)
  414. return
  415. }
  416. cfg.Section("oauth2").Key("JWT_SECRET").SetValue(jwtSecretBase64)
  417. }
  418. // if there is already a SECRET_KEY, we should not overwrite it, otherwise the encrypted data will not be able to be decrypted
  419. if setting.SecretKey == "" {
  420. var secretKey string
  421. if secretKey, err = generate.NewSecretKey(); err != nil {
  422. ctx.RenderWithErr(ctx.Tr("install.secret_key_failed", err), tplInstall, &form)
  423. return
  424. }
  425. cfg.Section("security").Key("SECRET_KEY").SetValue(secretKey)
  426. }
  427. if len(form.PasswordAlgorithm) > 0 {
  428. var algorithm *hash.PasswordHashAlgorithm
  429. setting.PasswordHashAlgo, algorithm = hash.SetDefaultPasswordHashAlgorithm(form.PasswordAlgorithm)
  430. if algorithm == nil {
  431. ctx.RenderWithErr(ctx.Tr("install.invalid_password_algorithm"), tplInstall, &form)
  432. return
  433. }
  434. cfg.Section("security").Key("PASSWORD_HASH_ALGO").SetValue(form.PasswordAlgorithm)
  435. }
  436. log.Info("Save settings to custom config file %s", setting.CustomConf)
  437. err = os.MkdirAll(filepath.Dir(setting.CustomConf), os.ModePerm)
  438. if err != nil {
  439. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  440. return
  441. }
  442. setting.EnvironmentToConfig(cfg, os.Environ())
  443. if err = cfg.SaveTo(setting.CustomConf); err != nil {
  444. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  445. return
  446. }
  447. // unset default engine before reload database setting
  448. db.UnsetDefaultEngine()
  449. // ---- All checks are passed
  450. // Reload settings (and re-initialize database connection)
  451. setting.InitCfgProvider(setting.CustomConf)
  452. setting.LoadCommonSettings()
  453. setting.MustInstalled()
  454. setting.LoadDBSetting()
  455. if err := common.InitDBEngine(ctx); err != nil {
  456. log.Fatal("ORM engine initialization failed: %v", err)
  457. }
  458. // Create admin account
  459. if len(form.AdminName) > 0 {
  460. u := &user_model.User{
  461. Name: form.AdminName,
  462. Email: form.AdminEmail,
  463. Passwd: form.AdminPasswd,
  464. IsAdmin: true,
  465. }
  466. overwriteDefault := &user_model.CreateUserOverwriteOptions{
  467. IsRestricted: optional.Some(false),
  468. IsActive: optional.Some(true),
  469. }
  470. if err = user_model.CreateUser(ctx, u, &user_model.Meta{}, overwriteDefault); err != nil {
  471. if !user_model.IsErrUserAlreadyExist(err) {
  472. setting.InstallLock = false
  473. ctx.Data["Err_AdminName"] = true
  474. ctx.Data["Err_AdminEmail"] = true
  475. ctx.RenderWithErr(ctx.Tr("install.invalid_admin_setting", err), tplInstall, &form)
  476. return
  477. }
  478. log.Info("Admin account already exist")
  479. u, _ = user_model.GetUserByName(ctx, u.Name)
  480. }
  481. nt, token, err := auth_service.CreateAuthTokenForUserID(ctx, u.ID)
  482. if err != nil {
  483. ctx.ServerError("CreateAuthTokenForUserID", err)
  484. return
  485. }
  486. ctx.SetSiteCookie(setting.CookieRememberName, nt.ID+":"+token, setting.LogInRememberDays*timeutil.Day)
  487. // Auto-login for admin
  488. if err = ctx.Session.Set("uid", u.ID); err != nil {
  489. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  490. return
  491. }
  492. if err = ctx.Session.Set("uname", u.Name); err != nil {
  493. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  494. return
  495. }
  496. if err = ctx.Session.Release(); err != nil {
  497. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  498. return
  499. }
  500. }
  501. setting.ClearEnvConfigKeys()
  502. log.Info("First-time run install finished!")
  503. InstallDone(ctx)
  504. go func() {
  505. // Sleep for a while to make sure the user's browser has loaded the post-install page and its assets (images, css, js)
  506. // What if this duration is not long enough? That's impossible -- if the user can't load the simple page in time, how could they install or use Gitea in the future ....
  507. time.Sleep(3 * time.Second)
  508. // Now get the http.Server from this request and shut it down
  509. // NB: This is not our hammerable graceful shutdown this is http.Server.Shutdown
  510. srv := ctx.Value(http.ServerContextKey).(*http.Server)
  511. if err := srv.Shutdown(graceful.GetManager().HammerContext()); err != nil {
  512. log.Error("Unable to shutdown the install server! Error: %v", err)
  513. }
  514. // After the HTTP server for "install" shuts down, the `runWeb()` will continue to run the "normal" server
  515. }()
  516. }
  517. // InstallDone shows the "post-install" page, makes it easier to develop the page.
  518. // The name is not called as "PostInstall" to avoid misinterpretation as a handler for "POST /install"
  519. func InstallDone(ctx *context.Context) { //nolint:revive // export stutter
  520. hasUsers, _ := user_model.HasUsers(ctx)
  521. ctx.Data["IsAccountCreated"] = hasUsers.HasAnyUser
  522. ctx.HTML(http.StatusOK, tplPostInstall)
  523. }