aboutsummaryrefslogtreecommitdiffstats
path: root/main.go
blob: 798d234b3c6ccadec342dc03023c3d6f4c0db051 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
package main

import (
	"flag"
	"fmt"
	"math/rand"
	"net/http"
	"strings"
	"time"
)

var storage *Storage

var (
	uploadUrl   string
	uploadHost  string
	siteName    string
	contactMail string
	abuseMail   string
	csp         string
	hsts        bool
	allowHtml   bool
	cors        bool
)

func handle(w http.ResponseWriter, r *http.Request) {
	if hsts {
		w.Header().Set("Strict-Transport-Security", "max-age=15552000")
	}
	if uploadHost != "" && r.URL.Host == uploadHost {
		handleFile(w, r)
	} else {
		http.DefaultServeMux.ServeHTTP(w, r)
	}
}

func globalHandler(handler http.Handler) http.Handler {
	return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
		if cors {
			w.Header().Set("Access-Control-Allow-Origin", "*")
		}
		if r.Method == http.MethodGet || r.Method == http.MethodPost || r.Method == http.MethodHead {
			handler.ServeHTTP(w, r)
		} else {
			w.Header().Set("Allow", "POST, HEAD, OPTIONS, GET")
			if r.Method != http.MethodOptions {
				http.Error(w, "The method is not allowed for the requested URL.", http.StatusMethodNotAllowed)
			}
		}
	})
}

func main() {
	flag.StringVar(&uploadUrl, "upload-url", "", "URL to serve uploads from")
	flag.StringVar(&uploadHost, "upload-host", "", "host to serve uploads on")
	flag.StringVar(&siteName, "name", "Gomf", "website name")
	flag.StringVar(&contactMail, "contact", "contact@example.com", "contact email address")
	flag.StringVar(&abuseMail, "abuse", "abuse@example.com", "abuse email address")
	flag.StringVar(&csp, "csp", "default-src 'none'; media-src 'self'", "the Content-Security-Policy header for files; blank to disable")
	flag.BoolVar(&hsts, "hsts", false, "enable HSTS")
	flag.BoolVar(&allowHtml, "allow-html", false, "serve (X)HTML uploads with (X)HTML filetypes")
	flag.BoolVar(&cors, "cors", false, "enable CORS and allow all origins")
	listenHttp := flag.String("http", "localhost:8080", "address to listen on for HTTP")
	listenHttps := flag.String("https", "", "address to listen on for HTTPS")
	cert := flag.String("cert", "", "path to TLS certificate (for HTTPS)")
	key := flag.String("key", "", "path to TLS key (for HTTPS)")
	maxSize := flag.Int64("max-size", 50*1024*1024, "max filesize in bytes")
	forbidMime := flag.String("forbid-mime", "application/x-dosexec,application/x-msdos-program", "comma-separated list of forbidden MIME types")
	forbidExt := flag.String("forbid-ext", "exe,dll,msi,scr,com,pif", "comma-separated list of forbidden file extensions")
	grill := flag.Bool("grill", false, "enable grills")
	idLength := flag.Int("id-length", 6, "length of uploaded file IDs")
	idCharset := flag.String("id-charset", "", "charset for uploaded file IDs (default lowercase letters a-z)")

	flag.Parse()

	rand.Seed(time.Now().UnixNano())

	initWebsite()

	storage = NewStorage("upload", *maxSize)
	storage.ForbiddenExt = strings.Split(*forbidExt, ",")
	storage.ForbiddenMime = strings.Split(*forbidMime, ",")
	storage.IdLength = *idLength
	if *idCharset != "" {
		storage.IdCharset = *idCharset
	}

	http.HandleFunc("/upload.php", handleUpload)
	http.Handle("/u/", http.StripPrefix("/u/", http.HandlerFunc(handleFile)))
	if *grill {
		http.HandleFunc("/grill.php", handleGrill)
	}

	if uploadUrl == "" {
		if *listenHttps != "" {
			if uploadHost != "" {
				uploadUrl = "https://" + uploadHost + "/"
			} else {
				uploadUrl = "https://" + *listenHttps + "/u/"
			}
		} else if *listenHttp != "" {
			if uploadHost != "" {
				uploadUrl = "http://" + uploadHost + "/"
			} else {
				uploadUrl = "http://" + *listenHttp + "/u/"
			}
		}
	}

	exit := true
	if *listenHttp != "" {
		exit = false
		fmt.Printf("listening on http://%s/\n", *listenHttp)
		go panic(http.ListenAndServe(*listenHttp, globalHandler(http.HandlerFunc(handle))))
	}
	if *listenHttps != "" {
		exit = false
		fmt.Printf("listening on https://%s/\n", *listenHttps)
		go panic(http.ListenAndServeTLS(*listenHttps, *cert, *key, globalHandler(http.HandlerFunc(handle))))
	}

	if !exit {
		switch {
		}
	}
}