config.go 63 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916
  1. // Package config manages the configuration
  2. package config
  3. import (
  4. "errors"
  5. "fmt"
  6. "os"
  7. "path/filepath"
  8. "strconv"
  9. "strings"
  10. "github.com/spf13/viper"
  11. "github.com/drakkan/sftpgo/v2/acme"
  12. "github.com/drakkan/sftpgo/v2/command"
  13. "github.com/drakkan/sftpgo/v2/common"
  14. "github.com/drakkan/sftpgo/v2/dataprovider"
  15. "github.com/drakkan/sftpgo/v2/ftpd"
  16. "github.com/drakkan/sftpgo/v2/httpclient"
  17. "github.com/drakkan/sftpgo/v2/httpd"
  18. "github.com/drakkan/sftpgo/v2/kms"
  19. "github.com/drakkan/sftpgo/v2/logger"
  20. "github.com/drakkan/sftpgo/v2/mfa"
  21. "github.com/drakkan/sftpgo/v2/plugin"
  22. "github.com/drakkan/sftpgo/v2/sftpd"
  23. "github.com/drakkan/sftpgo/v2/smtp"
  24. "github.com/drakkan/sftpgo/v2/telemetry"
  25. "github.com/drakkan/sftpgo/v2/util"
  26. "github.com/drakkan/sftpgo/v2/version"
  27. "github.com/drakkan/sftpgo/v2/webdavd"
  28. )
  29. const (
  30. logSender = "config"
  31. // configName defines the name for config file.
  32. // This name does not include the extension, viper will search for files
  33. // with supported extensions such as "sftpgo.json", "sftpgo.yaml" and so on
  34. configName = "sftpgo"
  35. // ConfigEnvPrefix defines a prefix that environment variables will use
  36. configEnvPrefix = "sftpgo"
  37. )
  38. var (
  39. globalConf globalConfig
  40. defaultSFTPDBanner = fmt.Sprintf("SFTPGo_%v", version.Get().Version)
  41. defaultFTPDBanner = fmt.Sprintf("SFTPGo %v ready", version.Get().Version)
  42. defaultInstallCodeHint = "Installation code"
  43. defaultSFTPDBinding = sftpd.Binding{
  44. Address: "",
  45. Port: 2022,
  46. ApplyProxyConfig: true,
  47. }
  48. defaultFTPDBinding = ftpd.Binding{
  49. Address: "",
  50. Port: 0,
  51. ApplyProxyConfig: true,
  52. TLSMode: 0,
  53. CertificateFile: "",
  54. CertificateKeyFile: "",
  55. MinTLSVersion: 12,
  56. ForcePassiveIP: "",
  57. PassiveIPOverrides: nil,
  58. ClientAuthType: 0,
  59. TLSCipherSuites: nil,
  60. PassiveConnectionsSecurity: 0,
  61. ActiveConnectionsSecurity: 0,
  62. Debug: false,
  63. }
  64. defaultWebDAVDBinding = webdavd.Binding{
  65. Address: "",
  66. Port: 0,
  67. EnableHTTPS: false,
  68. CertificateFile: "",
  69. CertificateKeyFile: "",
  70. MinTLSVersion: 12,
  71. ClientAuthType: 0,
  72. TLSCipherSuites: nil,
  73. Prefix: "",
  74. ProxyAllowed: nil,
  75. }
  76. defaultHTTPDBinding = httpd.Binding{
  77. Address: "",
  78. Port: 8080,
  79. EnableWebAdmin: true,
  80. EnableWebClient: true,
  81. EnableHTTPS: false,
  82. CertificateFile: "",
  83. CertificateKeyFile: "",
  84. MinTLSVersion: 12,
  85. ClientAuthType: 0,
  86. TLSCipherSuites: nil,
  87. ProxyAllowed: nil,
  88. HideLoginURL: 0,
  89. RenderOpenAPI: true,
  90. WebClientIntegrations: nil,
  91. OIDC: httpd.OIDC{
  92. ClientID: "",
  93. ClientSecret: "",
  94. ConfigURL: "",
  95. RedirectBaseURL: "",
  96. UsernameField: "",
  97. RoleField: "",
  98. ImplicitRoles: false,
  99. CustomFields: []string{},
  100. },
  101. Security: httpd.SecurityConf{
  102. Enabled: false,
  103. AllowedHosts: nil,
  104. AllowedHostsAreRegex: false,
  105. HostsProxyHeaders: nil,
  106. HTTPSRedirect: false,
  107. HTTPSHost: "",
  108. HTTPSProxyHeaders: nil,
  109. STSSeconds: 0,
  110. STSIncludeSubdomains: false,
  111. STSPreload: false,
  112. ContentTypeNosniff: false,
  113. ContentSecurityPolicy: "",
  114. PermissionsPolicy: "",
  115. CrossOriginOpenerPolicy: "",
  116. ExpectCTHeader: "",
  117. },
  118. Branding: httpd.Branding{},
  119. }
  120. defaultRateLimiter = common.RateLimiterConfig{
  121. Average: 0,
  122. Period: 1000,
  123. Burst: 1,
  124. Type: 2,
  125. Protocols: []string{common.ProtocolSSH, common.ProtocolFTP, common.ProtocolWebDAV, common.ProtocolHTTP},
  126. AllowList: []string{},
  127. GenerateDefenderEvents: false,
  128. EntriesSoftLimit: 100,
  129. EntriesHardLimit: 150,
  130. }
  131. defaultTOTP = mfa.TOTPConfig{
  132. Name: "Default",
  133. Issuer: "SFTPGo",
  134. Algo: mfa.TOTPAlgoSHA1,
  135. }
  136. )
  137. type globalConfig struct {
  138. Common common.Configuration `json:"common" mapstructure:"common"`
  139. ACME acme.Configuration `json:"acme" mapstructure:"acme"`
  140. SFTPD sftpd.Configuration `json:"sftpd" mapstructure:"sftpd"`
  141. FTPD ftpd.Configuration `json:"ftpd" mapstructure:"ftpd"`
  142. WebDAVD webdavd.Configuration `json:"webdavd" mapstructure:"webdavd"`
  143. ProviderConf dataprovider.Config `json:"data_provider" mapstructure:"data_provider"`
  144. HTTPDConfig httpd.Conf `json:"httpd" mapstructure:"httpd"`
  145. HTTPConfig httpclient.Config `json:"http" mapstructure:"http"`
  146. CommandConfig command.Config `json:"command" mapstructure:"command"`
  147. KMSConfig kms.Configuration `json:"kms" mapstructure:"kms"`
  148. MFAConfig mfa.Config `json:"mfa" mapstructure:"mfa"`
  149. TelemetryConfig telemetry.Conf `json:"telemetry" mapstructure:"telemetry"`
  150. PluginsConfig []plugin.Config `json:"plugins" mapstructure:"plugins"`
  151. SMTPConfig smtp.Config `json:"smtp" mapstructure:"smtp"`
  152. }
  153. func init() {
  154. Init()
  155. }
  156. // Init initializes the global configuration.
  157. // It is not supposed to be called outside of this package.
  158. // It is exported to minimize refactoring efforts. Will eventually disappear.
  159. func Init() {
  160. // create a default configuration to use if no config file is provided
  161. globalConf = globalConfig{
  162. Common: common.Configuration{
  163. IdleTimeout: 15,
  164. UploadMode: 0,
  165. Actions: common.ProtocolActions{
  166. ExecuteOn: []string{},
  167. ExecuteSync: []string{},
  168. Hook: "",
  169. },
  170. SetstatMode: 0,
  171. TempPath: "",
  172. ProxyProtocol: 0,
  173. ProxyAllowed: []string{},
  174. PostConnectHook: "",
  175. PostDisconnectHook: "",
  176. DataRetentionHook: "",
  177. MaxTotalConnections: 0,
  178. MaxPerHostConnections: 20,
  179. WhiteListFile: "",
  180. DefenderConfig: common.DefenderConfig{
  181. Enabled: false,
  182. Driver: common.DefenderDriverMemory,
  183. BanTime: 30,
  184. BanTimeIncrement: 50,
  185. Threshold: 15,
  186. ScoreInvalid: 2,
  187. ScoreValid: 1,
  188. ScoreLimitExceeded: 3,
  189. ObservationTime: 30,
  190. EntriesSoftLimit: 100,
  191. EntriesHardLimit: 150,
  192. SafeListFile: "",
  193. BlockListFile: "",
  194. SafeList: []string{},
  195. BlockList: []string{},
  196. },
  197. RateLimitersConfig: []common.RateLimiterConfig{defaultRateLimiter},
  198. },
  199. ACME: acme.Configuration{
  200. Email: "",
  201. KeyType: "4096",
  202. CertsPath: "certs",
  203. CAEndpoint: "https://acme-v02.api.letsencrypt.org/directory",
  204. Domains: []string{},
  205. RenewDays: 30,
  206. HTTP01Challenge: acme.HTTP01Challenge{
  207. Port: 80,
  208. WebRoot: "",
  209. ProxyHeader: "",
  210. },
  211. TLSALPN01Challenge: acme.TLSALPN01Challenge{
  212. Port: 0,
  213. },
  214. },
  215. SFTPD: sftpd.Configuration{
  216. Bindings: []sftpd.Binding{defaultSFTPDBinding},
  217. MaxAuthTries: 0,
  218. Banner: defaultSFTPDBanner,
  219. HostKeys: []string{},
  220. HostCertificates: []string{},
  221. HostKeyAlgorithms: []string{},
  222. KexAlgorithms: []string{},
  223. Ciphers: []string{},
  224. MACs: []string{},
  225. TrustedUserCAKeys: []string{},
  226. RevokedUserCertsFile: "",
  227. LoginBannerFile: "",
  228. EnabledSSHCommands: []string{},
  229. KeyboardInteractiveAuthentication: false,
  230. KeyboardInteractiveHook: "",
  231. PasswordAuthentication: true,
  232. FolderPrefix: "",
  233. },
  234. FTPD: ftpd.Configuration{
  235. Bindings: []ftpd.Binding{defaultFTPDBinding},
  236. Banner: defaultFTPDBanner,
  237. BannerFile: "",
  238. ActiveTransfersPortNon20: true,
  239. PassivePortRange: ftpd.PortRange{
  240. Start: 50000,
  241. End: 50100,
  242. },
  243. DisableActiveMode: false,
  244. EnableSite: false,
  245. HASHSupport: 0,
  246. CombineSupport: 0,
  247. CertificateFile: "",
  248. CertificateKeyFile: "",
  249. CACertificates: []string{},
  250. CARevocationLists: []string{},
  251. },
  252. WebDAVD: webdavd.Configuration{
  253. Bindings: []webdavd.Binding{defaultWebDAVDBinding},
  254. CertificateFile: "",
  255. CertificateKeyFile: "",
  256. CACertificates: []string{},
  257. CARevocationLists: []string{},
  258. Cors: webdavd.CorsConfig{
  259. Enabled: false,
  260. AllowedOrigins: []string{},
  261. AllowedMethods: []string{},
  262. AllowedHeaders: []string{},
  263. ExposedHeaders: []string{},
  264. AllowCredentials: false,
  265. MaxAge: 0,
  266. },
  267. Cache: webdavd.Cache{
  268. Users: webdavd.UsersCacheConfig{
  269. ExpirationTime: 0,
  270. MaxSize: 50,
  271. },
  272. MimeTypes: webdavd.MimeCacheConfig{
  273. Enabled: true,
  274. MaxSize: 1000,
  275. },
  276. },
  277. },
  278. ProviderConf: dataprovider.Config{
  279. Driver: "sqlite",
  280. Name: "sftpgo.db",
  281. Host: "",
  282. Port: 0,
  283. Username: "",
  284. Password: "",
  285. ConnectionString: "",
  286. SQLTablesPrefix: "",
  287. SSLMode: 0,
  288. RootCert: "",
  289. ClientCert: "",
  290. ClientKey: "",
  291. TrackQuota: 2,
  292. PoolSize: 0,
  293. UsersBaseDir: "",
  294. Actions: dataprovider.ObjectsActions{
  295. ExecuteOn: []string{},
  296. ExecuteFor: []string{},
  297. Hook: "",
  298. },
  299. ExternalAuthHook: "",
  300. ExternalAuthScope: 0,
  301. CredentialsPath: "credentials",
  302. PreLoginHook: "",
  303. PostLoginHook: "",
  304. PostLoginScope: 0,
  305. CheckPasswordHook: "",
  306. CheckPasswordScope: 0,
  307. PasswordHashing: dataprovider.PasswordHashing{
  308. Argon2Options: dataprovider.Argon2Options{
  309. Memory: 65536,
  310. Iterations: 1,
  311. Parallelism: 2,
  312. },
  313. BcryptOptions: dataprovider.BcryptOptions{
  314. Cost: 10,
  315. },
  316. Algo: dataprovider.HashingAlgoBcrypt,
  317. },
  318. PasswordValidation: dataprovider.PasswordValidation{
  319. Admins: dataprovider.PasswordValidationRules{
  320. MinEntropy: 0,
  321. },
  322. Users: dataprovider.PasswordValidationRules{
  323. MinEntropy: 0,
  324. },
  325. },
  326. PasswordCaching: true,
  327. UpdateMode: 0,
  328. DelayedQuotaUpdate: 0,
  329. CreateDefaultAdmin: false,
  330. NamingRules: 0,
  331. IsShared: 0,
  332. BackupsPath: "backups",
  333. AutoBackup: dataprovider.AutoBackup{
  334. Enabled: true,
  335. Hour: "0",
  336. DayOfWeek: "*",
  337. },
  338. },
  339. HTTPDConfig: httpd.Conf{
  340. Bindings: []httpd.Binding{defaultHTTPDBinding},
  341. TemplatesPath: "templates",
  342. StaticFilesPath: "static",
  343. OpenAPIPath: "openapi",
  344. WebRoot: "",
  345. CertificateFile: "",
  346. CertificateKeyFile: "",
  347. CACertificates: nil,
  348. CARevocationLists: nil,
  349. SigningPassphrase: "",
  350. MaxUploadFileSize: 1048576000,
  351. Cors: httpd.CorsConfig{
  352. Enabled: false,
  353. AllowedOrigins: []string{},
  354. AllowedMethods: []string{},
  355. AllowedHeaders: []string{},
  356. ExposedHeaders: []string{},
  357. AllowCredentials: false,
  358. MaxAge: 0,
  359. },
  360. Setup: httpd.SetupConfig{
  361. InstallationCode: "",
  362. InstallationCodeHint: defaultInstallCodeHint,
  363. },
  364. },
  365. HTTPConfig: httpclient.Config{
  366. Timeout: 20,
  367. RetryWaitMin: 2,
  368. RetryWaitMax: 30,
  369. RetryMax: 3,
  370. CACertificates: nil,
  371. Certificates: nil,
  372. SkipTLSVerify: false,
  373. Headers: nil,
  374. },
  375. CommandConfig: command.Config{
  376. Timeout: 30,
  377. Env: nil,
  378. Commands: nil,
  379. },
  380. KMSConfig: kms.Configuration{
  381. Secrets: kms.Secrets{
  382. URL: "",
  383. MasterKeyString: "",
  384. MasterKeyPath: "",
  385. },
  386. },
  387. MFAConfig: mfa.Config{
  388. TOTP: nil,
  389. },
  390. TelemetryConfig: telemetry.Conf{
  391. BindPort: 0,
  392. BindAddress: "127.0.0.1",
  393. EnableProfiler: false,
  394. AuthUserFile: "",
  395. CertificateFile: "",
  396. CertificateKeyFile: "",
  397. MinTLSVersion: 12,
  398. TLSCipherSuites: nil,
  399. },
  400. SMTPConfig: smtp.Config{
  401. Host: "",
  402. Port: 25,
  403. From: "",
  404. User: "",
  405. Password: "",
  406. AuthType: 0,
  407. Encryption: 0,
  408. Domain: "",
  409. TemplatesPath: "templates",
  410. },
  411. PluginsConfig: nil,
  412. }
  413. viper.SetEnvPrefix(configEnvPrefix)
  414. replacer := strings.NewReplacer(".", "__")
  415. viper.SetEnvKeyReplacer(replacer)
  416. viper.SetConfigName(configName)
  417. setViperDefaults()
  418. viper.AutomaticEnv()
  419. viper.AllowEmptyEnv(true)
  420. }
  421. // GetCommonConfig returns the common protocols configuration
  422. func GetCommonConfig() common.Configuration {
  423. return globalConf.Common
  424. }
  425. // SetCommonConfig sets the common protocols configuration
  426. func SetCommonConfig(config common.Configuration) {
  427. globalConf.Common = config
  428. }
  429. // GetSFTPDConfig returns the configuration for the SFTP server
  430. func GetSFTPDConfig() sftpd.Configuration {
  431. return globalConf.SFTPD
  432. }
  433. // SetSFTPDConfig sets the configuration for the SFTP server
  434. func SetSFTPDConfig(config sftpd.Configuration) {
  435. globalConf.SFTPD = config
  436. }
  437. // GetFTPDConfig returns the configuration for the FTP server
  438. func GetFTPDConfig() ftpd.Configuration {
  439. return globalConf.FTPD
  440. }
  441. // SetFTPDConfig sets the configuration for the FTP server
  442. func SetFTPDConfig(config ftpd.Configuration) {
  443. globalConf.FTPD = config
  444. }
  445. // GetWebDAVDConfig returns the configuration for the WebDAV server
  446. func GetWebDAVDConfig() webdavd.Configuration {
  447. return globalConf.WebDAVD
  448. }
  449. // SetWebDAVDConfig sets the configuration for the WebDAV server
  450. func SetWebDAVDConfig(config webdavd.Configuration) {
  451. globalConf.WebDAVD = config
  452. }
  453. // GetHTTPDConfig returns the configuration for the HTTP server
  454. func GetHTTPDConfig() httpd.Conf {
  455. return globalConf.HTTPDConfig
  456. }
  457. // SetHTTPDConfig sets the configuration for the HTTP server
  458. func SetHTTPDConfig(config httpd.Conf) {
  459. globalConf.HTTPDConfig = config
  460. }
  461. // GetProviderConf returns the configuration for the data provider
  462. func GetProviderConf() dataprovider.Config {
  463. return globalConf.ProviderConf
  464. }
  465. // SetProviderConf sets the configuration for the data provider
  466. func SetProviderConf(config dataprovider.Config) {
  467. globalConf.ProviderConf = config
  468. }
  469. // GetHTTPConfig returns the configuration for HTTP clients
  470. func GetHTTPConfig() httpclient.Config {
  471. return globalConf.HTTPConfig
  472. }
  473. // GetCommandConfig returns the configuration for external commands
  474. func GetCommandConfig() command.Config {
  475. return globalConf.CommandConfig
  476. }
  477. // GetKMSConfig returns the KMS configuration
  478. func GetKMSConfig() kms.Configuration {
  479. return globalConf.KMSConfig
  480. }
  481. // SetKMSConfig sets the kms configuration
  482. func SetKMSConfig(config kms.Configuration) {
  483. globalConf.KMSConfig = config
  484. }
  485. // GetTelemetryConfig returns the telemetry configuration
  486. func GetTelemetryConfig() telemetry.Conf {
  487. return globalConf.TelemetryConfig
  488. }
  489. // SetTelemetryConfig sets the telemetry configuration
  490. func SetTelemetryConfig(config telemetry.Conf) {
  491. globalConf.TelemetryConfig = config
  492. }
  493. // GetPluginsConfig returns the plugins configuration
  494. func GetPluginsConfig() []plugin.Config {
  495. return globalConf.PluginsConfig
  496. }
  497. // SetPluginsConfig sets the plugin configuration
  498. func SetPluginsConfig(config []plugin.Config) {
  499. globalConf.PluginsConfig = config
  500. }
  501. // GetMFAConfig returns multi-factor authentication config
  502. func GetMFAConfig() mfa.Config {
  503. return globalConf.MFAConfig
  504. }
  505. // GetSMTPConfig returns the SMTP configuration
  506. func GetSMTPConfig() smtp.Config {
  507. return globalConf.SMTPConfig
  508. }
  509. // GetACMEConfig returns the ACME configuration
  510. func GetACMEConfig() acme.Configuration {
  511. return globalConf.ACME
  512. }
  513. // HasServicesToStart returns true if the config defines at least a service to start.
  514. // Supported services are SFTP, FTP and WebDAV
  515. func HasServicesToStart() bool {
  516. if globalConf.SFTPD.ShouldBind() {
  517. return true
  518. }
  519. if globalConf.FTPD.ShouldBind() {
  520. return true
  521. }
  522. if globalConf.WebDAVD.ShouldBind() {
  523. return true
  524. }
  525. return false
  526. }
  527. func getRedactedPassword(value string) string {
  528. if value == "" {
  529. return value
  530. }
  531. return "[redacted]"
  532. }
  533. func getRedactedGlobalConf() globalConfig {
  534. conf := globalConf
  535. conf.Common.Actions.Hook = util.GetRedactedURL(conf.Common.Actions.Hook)
  536. conf.Common.StartupHook = util.GetRedactedURL(conf.Common.StartupHook)
  537. conf.Common.PostConnectHook = util.GetRedactedURL(conf.Common.PostConnectHook)
  538. conf.Common.PostDisconnectHook = util.GetRedactedURL(conf.Common.PostDisconnectHook)
  539. conf.Common.DataRetentionHook = util.GetRedactedURL(conf.Common.DataRetentionHook)
  540. conf.SFTPD.KeyboardInteractiveHook = util.GetRedactedURL(conf.SFTPD.KeyboardInteractiveHook)
  541. conf.HTTPDConfig.SigningPassphrase = getRedactedPassword(conf.HTTPDConfig.SigningPassphrase)
  542. conf.HTTPDConfig.Setup.InstallationCode = getRedactedPassword(conf.HTTPDConfig.Setup.InstallationCode)
  543. conf.ProviderConf.Password = getRedactedPassword(conf.ProviderConf.Password)
  544. conf.ProviderConf.Actions.Hook = util.GetRedactedURL(conf.ProviderConf.Actions.Hook)
  545. conf.ProviderConf.ExternalAuthHook = util.GetRedactedURL(conf.ProviderConf.ExternalAuthHook)
  546. conf.ProviderConf.PreLoginHook = util.GetRedactedURL(conf.ProviderConf.PreLoginHook)
  547. conf.ProviderConf.PostLoginHook = util.GetRedactedURL(conf.ProviderConf.PostLoginHook)
  548. conf.ProviderConf.CheckPasswordHook = util.GetRedactedURL(conf.ProviderConf.CheckPasswordHook)
  549. conf.SMTPConfig.Password = getRedactedPassword(conf.SMTPConfig.Password)
  550. conf.HTTPDConfig.Bindings = nil
  551. for _, binding := range globalConf.HTTPDConfig.Bindings {
  552. binding.OIDC.ClientID = getRedactedPassword(binding.OIDC.ClientID)
  553. binding.OIDC.ClientSecret = getRedactedPassword(binding.OIDC.ClientSecret)
  554. conf.HTTPDConfig.Bindings = append(conf.HTTPDConfig.Bindings, binding)
  555. }
  556. return conf
  557. }
  558. func setConfigFile(configDir, configFile string) {
  559. if configFile == "" {
  560. return
  561. }
  562. if !filepath.IsAbs(configFile) && util.IsFileInputValid(configFile) {
  563. configFile = filepath.Join(configDir, configFile)
  564. }
  565. viper.SetConfigFile(configFile)
  566. }
  567. // LoadConfig loads the configuration
  568. // configDir will be added to the configuration search paths.
  569. // The search path contains by default the current directory and on linux it contains
  570. // $HOME/.config/sftpgo and /etc/sftpgo too.
  571. // configFile is an absolute or relative path (to the config dir) to the configuration file.
  572. func LoadConfig(configDir, configFile string) error {
  573. var err error
  574. viper.AddConfigPath(configDir)
  575. setViperAdditionalConfigPaths()
  576. viper.AddConfigPath(".")
  577. setConfigFile(configDir, configFile)
  578. if err = viper.ReadInConfig(); err != nil {
  579. // if the user specify a configuration file we get os.ErrNotExist.
  580. // viper.ConfigFileNotFoundError is returned if viper is unable
  581. // to find sftpgo.{json,yaml, etc..} in any of the search paths
  582. if errors.As(err, &viper.ConfigFileNotFoundError{}) {
  583. logger.Debug(logSender, "", "no configuration file found")
  584. } else {
  585. // should we return the error and not start here?
  586. logger.Warn(logSender, "", "error loading configuration file: %v", err)
  587. logger.WarnToConsole("error loading configuration file: %v", err)
  588. }
  589. globalConf.MFAConfig.TOTP = []mfa.TOTPConfig{defaultTOTP}
  590. }
  591. err = viper.Unmarshal(&globalConf)
  592. if err != nil {
  593. logger.Warn(logSender, "", "error parsing configuration file: %v", err)
  594. logger.WarnToConsole("error parsing configuration file: %v", err)
  595. return err
  596. }
  597. // viper only supports slice of strings from env vars, so we use our custom method
  598. loadBindingsFromEnv()
  599. resetInvalidConfigs()
  600. logger.Debug(logSender, "", "config file used: '%#v', config loaded: %+v", viper.ConfigFileUsed(), getRedactedGlobalConf())
  601. return nil
  602. }
  603. func isUploadModeValid() bool {
  604. return globalConf.Common.UploadMode >= 0 && globalConf.Common.UploadMode <= 2
  605. }
  606. func isProxyProtocolValid() bool {
  607. return globalConf.Common.ProxyProtocol >= 0 && globalConf.Common.ProxyProtocol <= 2
  608. }
  609. func isExternalAuthScopeValid() bool {
  610. return globalConf.ProviderConf.ExternalAuthScope >= 0 && globalConf.ProviderConf.ExternalAuthScope <= 15
  611. }
  612. func resetInvalidConfigs() {
  613. if strings.TrimSpace(globalConf.SFTPD.Banner) == "" {
  614. globalConf.SFTPD.Banner = defaultSFTPDBanner
  615. }
  616. if strings.TrimSpace(globalConf.FTPD.Banner) == "" {
  617. globalConf.FTPD.Banner = defaultFTPDBanner
  618. }
  619. if strings.TrimSpace(globalConf.HTTPDConfig.Setup.InstallationCodeHint) == "" {
  620. globalConf.HTTPDConfig.Setup.InstallationCodeHint = defaultInstallCodeHint
  621. }
  622. if globalConf.ProviderConf.UsersBaseDir != "" && !util.IsFileInputValid(globalConf.ProviderConf.UsersBaseDir) {
  623. warn := fmt.Sprintf("invalid users base dir %#v will be ignored", globalConf.ProviderConf.UsersBaseDir)
  624. globalConf.ProviderConf.UsersBaseDir = ""
  625. logger.Warn(logSender, "", "Non-fatal configuration error: %v", warn)
  626. logger.WarnToConsole("Non-fatal configuration error: %v", warn)
  627. }
  628. if !isUploadModeValid() {
  629. warn := fmt.Sprintf("invalid upload_mode 0, 1 and 2 are supported, configured: %v reset upload_mode to 0",
  630. globalConf.Common.UploadMode)
  631. globalConf.Common.UploadMode = 0
  632. logger.Warn(logSender, "", "Non-fatal configuration error: %v", warn)
  633. logger.WarnToConsole("Non-fatal configuration error: %v", warn)
  634. }
  635. if !isProxyProtocolValid() {
  636. warn := fmt.Sprintf("invalid proxy_protocol 0, 1 and 2 are supported, configured: %v reset proxy_protocol to 0",
  637. globalConf.Common.ProxyProtocol)
  638. globalConf.Common.ProxyProtocol = 0
  639. logger.Warn(logSender, "", "Non-fatal configuration error: %v", warn)
  640. logger.WarnToConsole("Non-fatal configuration error: %v", warn)
  641. }
  642. if !isExternalAuthScopeValid() {
  643. warn := fmt.Sprintf("invalid external_auth_scope: %v reset to 0", globalConf.ProviderConf.ExternalAuthScope)
  644. globalConf.ProviderConf.ExternalAuthScope = 0
  645. logger.Warn(logSender, "", "Non-fatal configuration error: %v", warn)
  646. logger.WarnToConsole("Non-fatal configuration error: %v", warn)
  647. }
  648. if globalConf.ProviderConf.CredentialsPath == "" {
  649. warn := "invalid credentials path, reset to \"credentials\""
  650. globalConf.ProviderConf.CredentialsPath = "credentials"
  651. logger.Warn(logSender, "", "Non-fatal configuration error: %v", warn)
  652. logger.WarnToConsole("Non-fatal configuration error: %v", warn)
  653. }
  654. if globalConf.Common.DefenderConfig.Enabled && globalConf.Common.DefenderConfig.Driver == common.DefenderDriverProvider {
  655. if !globalConf.ProviderConf.IsDefenderSupported() {
  656. warn := fmt.Sprintf("provider based defender is not supported with data provider %#v, "+
  657. "the memory defender implementation will be used. If you want to use the provider defender "+
  658. "implementation please switch to a shared/distributed data provider",
  659. globalConf.ProviderConf.Driver)
  660. globalConf.Common.DefenderConfig.Driver = common.DefenderDriverMemory
  661. logger.Warn(logSender, "", "Non-fatal configuration error: %v", warn)
  662. logger.WarnToConsole("Non-fatal configuration error: %v", warn)
  663. }
  664. }
  665. }
  666. func loadBindingsFromEnv() {
  667. for idx := 0; idx < 10; idx++ {
  668. getTOTPFromEnv(idx)
  669. getRateLimitersFromEnv(idx)
  670. getPluginsFromEnv(idx)
  671. getSFTPDBindindFromEnv(idx)
  672. getFTPDBindingFromEnv(idx)
  673. getWebDAVDBindingFromEnv(idx)
  674. getHTTPDBindingFromEnv(idx)
  675. getHTTPClientCertificatesFromEnv(idx)
  676. getHTTPClientHeadersFromEnv(idx)
  677. getCommandConfigsFromEnv(idx)
  678. }
  679. }
  680. func getTOTPFromEnv(idx int) {
  681. totpConfig := defaultTOTP
  682. if len(globalConf.MFAConfig.TOTP) > idx {
  683. totpConfig = globalConf.MFAConfig.TOTP[idx]
  684. }
  685. isSet := false
  686. name, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_MFA__TOTP__%v__NAME", idx))
  687. if ok {
  688. totpConfig.Name = name
  689. isSet = true
  690. }
  691. issuer, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_MFA__TOTP__%v__ISSUER", idx))
  692. if ok {
  693. totpConfig.Issuer = issuer
  694. isSet = true
  695. }
  696. algo, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_MFA__TOTP__%v__ALGO", idx))
  697. if ok {
  698. totpConfig.Algo = algo
  699. isSet = true
  700. }
  701. if isSet {
  702. if len(globalConf.MFAConfig.TOTP) > idx {
  703. globalConf.MFAConfig.TOTP[idx] = totpConfig
  704. } else {
  705. globalConf.MFAConfig.TOTP = append(globalConf.MFAConfig.TOTP, totpConfig)
  706. }
  707. }
  708. }
  709. func getRateLimitersFromEnv(idx int) {
  710. rtlConfig := defaultRateLimiter
  711. if len(globalConf.Common.RateLimitersConfig) > idx {
  712. rtlConfig = globalConf.Common.RateLimitersConfig[idx]
  713. }
  714. isSet := false
  715. average, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_COMMON__RATE_LIMITERS__%v__AVERAGE", idx))
  716. if ok {
  717. rtlConfig.Average = average
  718. isSet = true
  719. }
  720. period, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_COMMON__RATE_LIMITERS__%v__PERIOD", idx))
  721. if ok {
  722. rtlConfig.Period = period
  723. isSet = true
  724. }
  725. burst, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_COMMON__RATE_LIMITERS__%v__BURST", idx))
  726. if ok {
  727. rtlConfig.Burst = int(burst)
  728. isSet = true
  729. }
  730. rtlType, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_COMMON__RATE_LIMITERS__%v__TYPE", idx))
  731. if ok {
  732. rtlConfig.Type = int(rtlType)
  733. isSet = true
  734. }
  735. protocols, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_COMMON__RATE_LIMITERS__%v__PROTOCOLS", idx))
  736. if ok {
  737. rtlConfig.Protocols = protocols
  738. isSet = true
  739. }
  740. allowList, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_COMMON__RATE_LIMITERS__%v__ALLOW_LIST", idx))
  741. if ok {
  742. rtlConfig.AllowList = allowList
  743. isSet = true
  744. }
  745. generateEvents, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_COMMON__RATE_LIMITERS__%v__GENERATE_DEFENDER_EVENTS", idx))
  746. if ok {
  747. rtlConfig.GenerateDefenderEvents = generateEvents
  748. isSet = true
  749. }
  750. softLimit, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_COMMON__RATE_LIMITERS__%v__ENTRIES_SOFT_LIMIT", idx))
  751. if ok {
  752. rtlConfig.EntriesSoftLimit = int(softLimit)
  753. isSet = true
  754. }
  755. hardLimit, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_COMMON__RATE_LIMITERS__%v__ENTRIES_HARD_LIMIT", idx))
  756. if ok {
  757. rtlConfig.EntriesHardLimit = int(hardLimit)
  758. isSet = true
  759. }
  760. if isSet {
  761. if len(globalConf.Common.RateLimitersConfig) > idx {
  762. globalConf.Common.RateLimitersConfig[idx] = rtlConfig
  763. } else {
  764. globalConf.Common.RateLimitersConfig = append(globalConf.Common.RateLimitersConfig, rtlConfig)
  765. }
  766. }
  767. }
  768. func getKMSPluginFromEnv(idx int, pluginConfig *plugin.Config) bool {
  769. isSet := false
  770. kmsScheme, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__KMS_OPTIONS__SCHEME", idx))
  771. if ok {
  772. pluginConfig.KMSOptions.Scheme = kmsScheme
  773. isSet = true
  774. }
  775. kmsEncStatus, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__KMS_OPTIONS__ENCRYPTED_STATUS", idx))
  776. if ok {
  777. pluginConfig.KMSOptions.EncryptedStatus = kmsEncStatus
  778. isSet = true
  779. }
  780. return isSet
  781. }
  782. func getAuthPluginFromEnv(idx int, pluginConfig *plugin.Config) bool {
  783. isSet := false
  784. authScope, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__AUTH_OPTIONS__SCOPE", idx))
  785. if ok {
  786. pluginConfig.AuthOptions.Scope = int(authScope)
  787. isSet = true
  788. }
  789. return isSet
  790. }
  791. func getNotifierPluginFromEnv(idx int, pluginConfig *plugin.Config) bool {
  792. isSet := false
  793. notifierFsEvents, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__NOTIFIER_OPTIONS__FS_EVENTS", idx))
  794. if ok {
  795. pluginConfig.NotifierOptions.FsEvents = notifierFsEvents
  796. isSet = true
  797. }
  798. notifierProviderEvents, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__NOTIFIER_OPTIONS__PROVIDER_EVENTS", idx))
  799. if ok {
  800. pluginConfig.NotifierOptions.ProviderEvents = notifierProviderEvents
  801. isSet = true
  802. }
  803. notifierProviderObjects, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__NOTIFIER_OPTIONS__PROVIDER_OBJECTS", idx))
  804. if ok {
  805. pluginConfig.NotifierOptions.ProviderObjects = notifierProviderObjects
  806. isSet = true
  807. }
  808. notifierRetryMaxTime, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__NOTIFIER_OPTIONS__RETRY_MAX_TIME", idx))
  809. if ok {
  810. pluginConfig.NotifierOptions.RetryMaxTime = int(notifierRetryMaxTime)
  811. isSet = true
  812. }
  813. notifierRetryQueueMaxSize, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__NOTIFIER_OPTIONS__RETRY_QUEUE_MAX_SIZE", idx))
  814. if ok {
  815. pluginConfig.NotifierOptions.RetryQueueMaxSize = int(notifierRetryQueueMaxSize)
  816. isSet = true
  817. }
  818. return isSet
  819. }
  820. func getPluginsFromEnv(idx int) {
  821. pluginConfig := plugin.Config{}
  822. if len(globalConf.PluginsConfig) > idx {
  823. pluginConfig = globalConf.PluginsConfig[idx]
  824. }
  825. isSet := false
  826. pluginType, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__TYPE", idx))
  827. if ok {
  828. pluginConfig.Type = pluginType
  829. isSet = true
  830. }
  831. if getNotifierPluginFromEnv(idx, &pluginConfig) {
  832. isSet = true
  833. }
  834. if getKMSPluginFromEnv(idx, &pluginConfig) {
  835. isSet = true
  836. }
  837. if getAuthPluginFromEnv(idx, &pluginConfig) {
  838. isSet = true
  839. }
  840. cmd, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__CMD", idx))
  841. if ok {
  842. pluginConfig.Cmd = cmd
  843. isSet = true
  844. }
  845. cmdArgs, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__ARGS", idx))
  846. if ok {
  847. pluginConfig.Args = cmdArgs
  848. isSet = true
  849. }
  850. pluginHash, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__SHA256SUM", idx))
  851. if ok {
  852. pluginConfig.SHA256Sum = pluginHash
  853. isSet = true
  854. }
  855. autoMTLS, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_PLUGINS__%v__AUTO_MTLS", idx))
  856. if ok {
  857. pluginConfig.AutoMTLS = autoMTLS
  858. isSet = true
  859. }
  860. if isSet {
  861. if len(globalConf.PluginsConfig) > idx {
  862. globalConf.PluginsConfig[idx] = pluginConfig
  863. } else {
  864. globalConf.PluginsConfig = append(globalConf.PluginsConfig, pluginConfig)
  865. }
  866. }
  867. }
  868. func getSFTPDBindindFromEnv(idx int) {
  869. binding := sftpd.Binding{
  870. ApplyProxyConfig: true,
  871. }
  872. if len(globalConf.SFTPD.Bindings) > idx {
  873. binding = globalConf.SFTPD.Bindings[idx]
  874. }
  875. isSet := false
  876. port, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_SFTPD__BINDINGS__%v__PORT", idx))
  877. if ok {
  878. binding.Port = int(port)
  879. isSet = true
  880. }
  881. address, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_SFTPD__BINDINGS__%v__ADDRESS", idx))
  882. if ok {
  883. binding.Address = address
  884. isSet = true
  885. }
  886. applyProxyConfig, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_SFTPD__BINDINGS__%v__APPLY_PROXY_CONFIG", idx))
  887. if ok {
  888. binding.ApplyProxyConfig = applyProxyConfig
  889. isSet = true
  890. }
  891. if isSet {
  892. if len(globalConf.SFTPD.Bindings) > idx {
  893. globalConf.SFTPD.Bindings[idx] = binding
  894. } else {
  895. globalConf.SFTPD.Bindings = append(globalConf.SFTPD.Bindings, binding)
  896. }
  897. }
  898. }
  899. func getFTPDPassiveIPOverridesFromEnv(idx int) []ftpd.PassiveIPOverride {
  900. var overrides []ftpd.PassiveIPOverride
  901. for subIdx := 0; subIdx < 10; subIdx++ {
  902. var override ftpd.PassiveIPOverride
  903. ip, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__PASSIVE_IP_OVERRIDES__%v__IP", idx, subIdx))
  904. if ok {
  905. override.IP = ip
  906. }
  907. networks, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__PASSIVE_IP_OVERRIDES__%v__NETWORKS",
  908. idx, subIdx))
  909. if ok {
  910. override.Networks = networks
  911. }
  912. if len(override.Networks) > 0 {
  913. overrides = append(overrides, override)
  914. }
  915. }
  916. return overrides
  917. }
  918. func getDefaultFTPDBinding(idx int) ftpd.Binding {
  919. binding := ftpd.Binding{
  920. ApplyProxyConfig: true,
  921. MinTLSVersion: 12,
  922. }
  923. if len(globalConf.FTPD.Bindings) > idx {
  924. binding = globalConf.FTPD.Bindings[idx]
  925. }
  926. return binding
  927. }
  928. func getFTPDBindingFromEnv(idx int) {
  929. binding := getDefaultFTPDBinding(idx)
  930. isSet := false
  931. port, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__PORT", idx))
  932. if ok {
  933. binding.Port = int(port)
  934. isSet = true
  935. }
  936. address, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__ADDRESS", idx))
  937. if ok {
  938. binding.Address = address
  939. isSet = true
  940. }
  941. applyProxyConfig, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__APPLY_PROXY_CONFIG", idx))
  942. if ok {
  943. binding.ApplyProxyConfig = applyProxyConfig
  944. isSet = true
  945. }
  946. certificateFile, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__CERTIFICATE_FILE", idx))
  947. if ok {
  948. binding.CertificateFile = certificateFile
  949. isSet = true
  950. }
  951. certificateKeyFile, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__CERTIFICATE_KEY_FILE", idx))
  952. if ok {
  953. binding.CertificateKeyFile = certificateKeyFile
  954. isSet = true
  955. }
  956. tlsMode, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__TLS_MODE", idx))
  957. if ok {
  958. binding.TLSMode = int(tlsMode)
  959. isSet = true
  960. }
  961. tlsVer, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__MIN_TLS_VERSION", idx))
  962. if ok {
  963. binding.MinTLSVersion = int(tlsVer)
  964. isSet = true
  965. }
  966. passiveIP, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__FORCE_PASSIVE_IP", idx))
  967. if ok {
  968. binding.ForcePassiveIP = passiveIP
  969. isSet = true
  970. }
  971. passiveIPOverrides := getFTPDPassiveIPOverridesFromEnv(idx)
  972. if len(passiveIPOverrides) > 0 {
  973. binding.PassiveIPOverrides = passiveIPOverrides
  974. isSet = true
  975. }
  976. clientAuthType, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__CLIENT_AUTH_TYPE", idx))
  977. if ok {
  978. binding.ClientAuthType = int(clientAuthType)
  979. isSet = true
  980. }
  981. tlsCiphers, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__TLS_CIPHER_SUITES", idx))
  982. if ok {
  983. binding.TLSCipherSuites = tlsCiphers
  984. isSet = true
  985. }
  986. pasvSecurity, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__PASSIVE_CONNECTIONS_SECURITY", idx))
  987. if ok {
  988. binding.PassiveConnectionsSecurity = int(pasvSecurity)
  989. isSet = true
  990. }
  991. activeSecurity, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__ACTIVE_CONNECTIONS_SECURITY", idx))
  992. if ok {
  993. binding.ActiveConnectionsSecurity = int(activeSecurity)
  994. isSet = true
  995. }
  996. debug, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_FTPD__BINDINGS__%v__DEBUG", idx))
  997. if ok {
  998. binding.Debug = debug
  999. isSet = true
  1000. }
  1001. applyFTPDBindingFromEnv(idx, isSet, binding)
  1002. }
  1003. func applyFTPDBindingFromEnv(idx int, isSet bool, binding ftpd.Binding) {
  1004. if isSet {
  1005. if len(globalConf.FTPD.Bindings) > idx {
  1006. globalConf.FTPD.Bindings[idx] = binding
  1007. } else {
  1008. globalConf.FTPD.Bindings = append(globalConf.FTPD.Bindings, binding)
  1009. }
  1010. }
  1011. }
  1012. func getWebDAVDBindingFromEnv(idx int) {
  1013. binding := webdavd.Binding{
  1014. MinTLSVersion: 12,
  1015. }
  1016. if len(globalConf.WebDAVD.Bindings) > idx {
  1017. binding = globalConf.WebDAVD.Bindings[idx]
  1018. }
  1019. isSet := false
  1020. port, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_WEBDAVD__BINDINGS__%v__PORT", idx))
  1021. if ok {
  1022. binding.Port = int(port)
  1023. isSet = true
  1024. }
  1025. address, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_WEBDAVD__BINDINGS__%v__ADDRESS", idx))
  1026. if ok {
  1027. binding.Address = address
  1028. isSet = true
  1029. }
  1030. certificateFile, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_WEBDAVD__BINDINGS__%v__CERTIFICATE_FILE", idx))
  1031. if ok {
  1032. binding.CertificateFile = certificateFile
  1033. isSet = true
  1034. }
  1035. certificateKeyFile, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_WEBDAVD__BINDINGS__%v__CERTIFICATE_KEY_FILE", idx))
  1036. if ok {
  1037. binding.CertificateKeyFile = certificateKeyFile
  1038. isSet = true
  1039. }
  1040. enableHTTPS, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_WEBDAVD__BINDINGS__%v__ENABLE_HTTPS", idx))
  1041. if ok {
  1042. binding.EnableHTTPS = enableHTTPS
  1043. isSet = true
  1044. }
  1045. tlsVer, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_WEBDAVD__BINDINGS__%v__MIN_TLS_VERSION", idx))
  1046. if ok {
  1047. binding.MinTLSVersion = int(tlsVer)
  1048. isSet = true
  1049. }
  1050. clientAuthType, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_WEBDAVD__BINDINGS__%v__CLIENT_AUTH_TYPE", idx))
  1051. if ok {
  1052. binding.ClientAuthType = int(clientAuthType)
  1053. isSet = true
  1054. }
  1055. tlsCiphers, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_WEBDAVD__BINDINGS__%v__TLS_CIPHER_SUITES", idx))
  1056. if ok {
  1057. binding.TLSCipherSuites = tlsCiphers
  1058. isSet = true
  1059. }
  1060. proxyAllowed, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_WEBDAVD__BINDINGS__%v__PROXY_ALLOWED", idx))
  1061. if ok {
  1062. binding.ProxyAllowed = proxyAllowed
  1063. isSet = true
  1064. }
  1065. prefix, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_WEBDAVD__BINDINGS__%v__PREFIX", idx))
  1066. if ok {
  1067. binding.Prefix = prefix
  1068. isSet = true
  1069. }
  1070. if isSet {
  1071. if len(globalConf.WebDAVD.Bindings) > idx {
  1072. globalConf.WebDAVD.Bindings[idx] = binding
  1073. } else {
  1074. globalConf.WebDAVD.Bindings = append(globalConf.WebDAVD.Bindings, binding)
  1075. }
  1076. }
  1077. }
  1078. func getHTTPDSecurityProxyHeadersFromEnv(idx int) []httpd.HTTPSProxyHeader {
  1079. var httpsProxyHeaders []httpd.HTTPSProxyHeader
  1080. for subIdx := 0; subIdx < 10; subIdx++ {
  1081. proxyKey, _ := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__HTTPS_PROXY_HEADERS__%v__KEY", idx, subIdx))
  1082. proxyVal, _ := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__HTTPS_PROXY_HEADERS__%v__VALUE", idx, subIdx))
  1083. if proxyKey != "" && proxyVal != "" {
  1084. httpsProxyHeaders = append(httpsProxyHeaders, httpd.HTTPSProxyHeader{
  1085. Key: proxyKey,
  1086. Value: proxyVal,
  1087. })
  1088. }
  1089. }
  1090. return httpsProxyHeaders
  1091. }
  1092. func getHTTPDSecurityConfFromEnv(idx int) (httpd.SecurityConf, bool) { //nolint:gocyclo
  1093. var result httpd.SecurityConf
  1094. isSet := false
  1095. enabled, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__ENABLED", idx))
  1096. if ok {
  1097. result.Enabled = enabled
  1098. isSet = true
  1099. }
  1100. allowedHosts, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__ALLOWED_HOSTS", idx))
  1101. if ok {
  1102. result.AllowedHosts = allowedHosts
  1103. isSet = true
  1104. }
  1105. allowedHostsAreRegex, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__ALLOWED_HOSTS_ARE_REGEX", idx))
  1106. if ok {
  1107. result.AllowedHostsAreRegex = allowedHostsAreRegex
  1108. isSet = true
  1109. }
  1110. hostsProxyHeaders, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__HOSTS_PROXY_HEADERS", idx))
  1111. if ok {
  1112. result.HostsProxyHeaders = hostsProxyHeaders
  1113. isSet = true
  1114. }
  1115. httpsRedirect, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__HTTPS_REDIRECT", idx))
  1116. if ok {
  1117. result.HTTPSRedirect = httpsRedirect
  1118. isSet = true
  1119. }
  1120. httpsHost, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__HTTPS_HOST", idx))
  1121. if ok {
  1122. result.HTTPSHost = httpsHost
  1123. isSet = true
  1124. }
  1125. httpsProxyHeaders := getHTTPDSecurityProxyHeadersFromEnv(idx)
  1126. if len(httpsProxyHeaders) > 0 {
  1127. result.HTTPSProxyHeaders = httpsProxyHeaders
  1128. isSet = true
  1129. }
  1130. stsSeconds, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__STS_SECONDS", idx))
  1131. if ok {
  1132. result.STSSeconds = stsSeconds
  1133. }
  1134. stsIncludeSubDomains, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__STS_INCLUDE_SUBDOMAINS", idx))
  1135. if ok {
  1136. result.STSIncludeSubdomains = stsIncludeSubDomains
  1137. isSet = true
  1138. }
  1139. stsPreload, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__STS_PRELOAD", idx))
  1140. if ok {
  1141. result.STSPreload = stsPreload
  1142. isSet = true
  1143. }
  1144. contentTypeNosniff, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__CONTENT_TYPE_NOSNIFF", idx))
  1145. if ok {
  1146. result.ContentTypeNosniff = contentTypeNosniff
  1147. isSet = true
  1148. }
  1149. contentSecurityPolicy, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__CONTENT_SECURITY_POLICY", idx))
  1150. if ok {
  1151. result.ContentSecurityPolicy = contentSecurityPolicy
  1152. isSet = true
  1153. }
  1154. permissionsPolicy, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__PERMISSIONS_POLICY", idx))
  1155. if ok {
  1156. result.PermissionsPolicy = permissionsPolicy
  1157. isSet = true
  1158. }
  1159. crossOriginOpenedPolicy, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__CROSS_ORIGIN_OPENER_POLICY", idx))
  1160. if ok {
  1161. result.CrossOriginOpenerPolicy = crossOriginOpenedPolicy
  1162. isSet = true
  1163. }
  1164. expectCTHeader, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__SECURITY__EXPECT_CT_HEADER", idx))
  1165. if ok {
  1166. result.ExpectCTHeader = expectCTHeader
  1167. isSet = true
  1168. }
  1169. return result, isSet
  1170. }
  1171. func getHTTPDOIDCFromEnv(idx int) (httpd.OIDC, bool) {
  1172. var result httpd.OIDC
  1173. isSet := false
  1174. clientID, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__OIDC__CLIENT_ID", idx))
  1175. if ok {
  1176. result.ClientID = clientID
  1177. isSet = true
  1178. }
  1179. clientSecret, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__OIDC__CLIENT_SECRET", idx))
  1180. if ok {
  1181. result.ClientSecret = clientSecret
  1182. isSet = true
  1183. }
  1184. configURL, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__OIDC__CONFIG_URL", idx))
  1185. if ok {
  1186. result.ConfigURL = configURL
  1187. isSet = true
  1188. }
  1189. redirectBaseURL, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__OIDC__REDIRECT_BASE_URL", idx))
  1190. if ok {
  1191. result.RedirectBaseURL = redirectBaseURL
  1192. isSet = true
  1193. }
  1194. usernameField, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__OIDC__USERNAME_FIELD", idx))
  1195. if ok {
  1196. result.UsernameField = usernameField
  1197. isSet = true
  1198. }
  1199. roleField, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__OIDC__ROLE_FIELD", idx))
  1200. if ok {
  1201. result.RoleField = roleField
  1202. isSet = true
  1203. }
  1204. implicitRoles, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__OIDC__IMPLICIT_ROLES", idx))
  1205. if ok {
  1206. result.ImplicitRoles = implicitRoles
  1207. isSet = true
  1208. }
  1209. customFields, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__OIDC__CUSTOM_FIELDS", idx))
  1210. if ok {
  1211. result.CustomFields = customFields
  1212. isSet = true
  1213. }
  1214. return result, isSet
  1215. }
  1216. func getHTTPDUIBrandingFromEnv(prefix string) (httpd.UIBranding, bool) {
  1217. var result httpd.UIBranding
  1218. isSet := false
  1219. name, ok := os.LookupEnv(fmt.Sprintf("%s__NAME", prefix))
  1220. if ok {
  1221. result.Name = name
  1222. isSet = true
  1223. }
  1224. shortName, ok := os.LookupEnv(fmt.Sprintf("%s__SHORT_NAME", prefix))
  1225. if ok {
  1226. result.ShortName = shortName
  1227. isSet = true
  1228. }
  1229. faviconPath, ok := os.LookupEnv(fmt.Sprintf("%s__FAVICON_PATH", prefix))
  1230. if ok {
  1231. result.FaviconPath = faviconPath
  1232. isSet = true
  1233. }
  1234. logoPath, ok := os.LookupEnv(fmt.Sprintf("%s__LOGO_PATH", prefix))
  1235. if ok {
  1236. result.LogoPath = logoPath
  1237. isSet = true
  1238. }
  1239. loginImagePath, ok := os.LookupEnv(fmt.Sprintf("%s__LOGIN_IMAGE_PATH", prefix))
  1240. if ok {
  1241. result.LoginImagePath = loginImagePath
  1242. isSet = true
  1243. }
  1244. disclaimerName, ok := os.LookupEnv(fmt.Sprintf("%s__DISCLAIMER_NAME", prefix))
  1245. if ok {
  1246. result.DisclaimerName = disclaimerName
  1247. isSet = true
  1248. }
  1249. disclaimerPath, ok := os.LookupEnv(fmt.Sprintf("%s__DISCLAIMER_PATH", prefix))
  1250. if ok {
  1251. result.DisclaimerPath = disclaimerPath
  1252. isSet = true
  1253. }
  1254. defaultCSSPath, ok := os.LookupEnv(fmt.Sprintf("%s__DEFAULT_CSS", prefix))
  1255. if ok {
  1256. result.DefaultCSS = defaultCSSPath
  1257. isSet = true
  1258. }
  1259. extraCSS, ok := lookupStringListFromEnv(fmt.Sprintf("%s__EXTRA_CSS", prefix))
  1260. if ok {
  1261. result.ExtraCSS = extraCSS
  1262. isSet = true
  1263. }
  1264. return result, isSet
  1265. }
  1266. func getHTTPDBrandingFromEnv(idx int) (httpd.Branding, bool) {
  1267. var result httpd.Branding
  1268. isSet := false
  1269. webAdmin, ok := getHTTPDUIBrandingFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__BRANDING__WEB_ADMIN", idx))
  1270. if ok {
  1271. result.WebAdmin = webAdmin
  1272. isSet = true
  1273. }
  1274. webClient, ok := getHTTPDUIBrandingFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__BRANDING__WEB_CLIENT", idx))
  1275. if ok {
  1276. result.WebClient = webClient
  1277. isSet = true
  1278. }
  1279. return result, isSet
  1280. }
  1281. func getHTTPDWebClientIntegrationsFromEnv(idx int) []httpd.WebClientIntegration {
  1282. var integrations []httpd.WebClientIntegration
  1283. for subIdx := 0; subIdx < 10; subIdx++ {
  1284. var integration httpd.WebClientIntegration
  1285. url, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__WEB_CLIENT_INTEGRATIONS__%v__URL", idx, subIdx))
  1286. if ok {
  1287. integration.URL = url
  1288. }
  1289. extensions, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__WEB_CLIENT_INTEGRATIONS__%v__FILE_EXTENSIONS",
  1290. idx, subIdx))
  1291. if ok {
  1292. integration.FileExtensions = extensions
  1293. }
  1294. if url != "" && len(extensions) > 0 {
  1295. integrations = append(integrations, integration)
  1296. }
  1297. }
  1298. return integrations
  1299. }
  1300. func getDefaultHTTPBinding(idx int) httpd.Binding {
  1301. binding := httpd.Binding{
  1302. EnableWebAdmin: true,
  1303. EnableWebClient: true,
  1304. RenderOpenAPI: true,
  1305. MinTLSVersion: 12,
  1306. }
  1307. if len(globalConf.HTTPDConfig.Bindings) > idx {
  1308. binding = globalConf.HTTPDConfig.Bindings[idx]
  1309. }
  1310. return binding
  1311. }
  1312. func getHTTPDNestedObjectsFromEnv(idx int, binding *httpd.Binding) bool {
  1313. isSet := false
  1314. webClientIntegrations := getHTTPDWebClientIntegrationsFromEnv(idx)
  1315. if len(webClientIntegrations) > 0 {
  1316. binding.WebClientIntegrations = webClientIntegrations
  1317. isSet = true
  1318. }
  1319. oidc, ok := getHTTPDOIDCFromEnv(idx)
  1320. if ok {
  1321. binding.OIDC = oidc
  1322. isSet = true
  1323. }
  1324. securityConf, ok := getHTTPDSecurityConfFromEnv(idx)
  1325. if ok {
  1326. binding.Security = securityConf
  1327. isSet = true
  1328. }
  1329. brandingConf, ok := getHTTPDBrandingFromEnv(idx)
  1330. if ok {
  1331. binding.Branding = brandingConf
  1332. }
  1333. return isSet
  1334. }
  1335. func getHTTPDBindingFromEnv(idx int) {
  1336. binding := getDefaultHTTPBinding(idx)
  1337. isSet := false
  1338. port, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__PORT", idx))
  1339. if ok {
  1340. binding.Port = int(port)
  1341. isSet = true
  1342. }
  1343. address, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__ADDRESS", idx))
  1344. if ok {
  1345. binding.Address = address
  1346. isSet = true
  1347. }
  1348. certificateFile, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__CERTIFICATE_FILE", idx))
  1349. if ok {
  1350. binding.CertificateFile = certificateFile
  1351. isSet = true
  1352. }
  1353. certificateKeyFile, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__CERTIFICATE_KEY_FILE", idx))
  1354. if ok {
  1355. binding.CertificateKeyFile = certificateKeyFile
  1356. isSet = true
  1357. }
  1358. enableWebAdmin, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__ENABLE_WEB_ADMIN", idx))
  1359. if ok {
  1360. binding.EnableWebAdmin = enableWebAdmin
  1361. isSet = true
  1362. }
  1363. enableWebClient, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__ENABLE_WEB_CLIENT", idx))
  1364. if ok {
  1365. binding.EnableWebClient = enableWebClient
  1366. isSet = true
  1367. }
  1368. renderOpenAPI, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__RENDER_OPENAPI", idx))
  1369. if ok {
  1370. binding.RenderOpenAPI = renderOpenAPI
  1371. isSet = true
  1372. }
  1373. enableHTTPS, ok := lookupBoolFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__ENABLE_HTTPS", idx))
  1374. if ok {
  1375. binding.EnableHTTPS = enableHTTPS
  1376. isSet = true
  1377. }
  1378. tlsVer, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__MIN_TLS_VERSION", idx))
  1379. if ok {
  1380. binding.MinTLSVersion = int(tlsVer)
  1381. isSet = true
  1382. }
  1383. clientAuthType, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__CLIENT_AUTH_TYPE", idx))
  1384. if ok {
  1385. binding.ClientAuthType = int(clientAuthType)
  1386. isSet = true
  1387. }
  1388. tlsCiphers, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__TLS_CIPHER_SUITES", idx))
  1389. if ok {
  1390. binding.TLSCipherSuites = tlsCiphers
  1391. isSet = true
  1392. }
  1393. proxyAllowed, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__PROXY_ALLOWED", idx))
  1394. if ok {
  1395. binding.ProxyAllowed = proxyAllowed
  1396. isSet = true
  1397. }
  1398. hideLoginURL, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_HTTPD__BINDINGS__%v__HIDE_LOGIN_URL", idx))
  1399. if ok {
  1400. binding.HideLoginURL = int(hideLoginURL)
  1401. isSet = true
  1402. }
  1403. if getHTTPDNestedObjectsFromEnv(idx, &binding) {
  1404. isSet = true
  1405. }
  1406. setHTTPDBinding(isSet, binding, idx)
  1407. }
  1408. func setHTTPDBinding(isSet bool, binding httpd.Binding, idx int) {
  1409. if isSet {
  1410. if len(globalConf.HTTPDConfig.Bindings) > idx {
  1411. globalConf.HTTPDConfig.Bindings[idx] = binding
  1412. } else {
  1413. globalConf.HTTPDConfig.Bindings = append(globalConf.HTTPDConfig.Bindings, binding)
  1414. }
  1415. }
  1416. }
  1417. func getHTTPClientCertificatesFromEnv(idx int) {
  1418. tlsCert := httpclient.TLSKeyPair{}
  1419. cert, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTP__CERTIFICATES__%v__CERT", idx))
  1420. if ok {
  1421. tlsCert.Cert = cert
  1422. }
  1423. key, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTP__CERTIFICATES__%v__KEY", idx))
  1424. if ok {
  1425. tlsCert.Key = key
  1426. }
  1427. if tlsCert.Cert != "" && tlsCert.Key != "" {
  1428. if len(globalConf.HTTPConfig.Certificates) > idx {
  1429. globalConf.HTTPConfig.Certificates[idx] = tlsCert
  1430. } else {
  1431. globalConf.HTTPConfig.Certificates = append(globalConf.HTTPConfig.Certificates, tlsCert)
  1432. }
  1433. }
  1434. }
  1435. func getHTTPClientHeadersFromEnv(idx int) {
  1436. header := httpclient.Header{}
  1437. if len(globalConf.HTTPConfig.Headers) > idx {
  1438. header = globalConf.HTTPConfig.Headers[idx]
  1439. }
  1440. key, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTP__HEADERS__%v__KEY", idx))
  1441. if ok {
  1442. header.Key = key
  1443. }
  1444. value, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTP__HEADERS__%v__VALUE", idx))
  1445. if ok {
  1446. header.Value = value
  1447. }
  1448. url, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_HTTP__HEADERS__%v__URL", idx))
  1449. if ok {
  1450. header.URL = url
  1451. }
  1452. if header.Key != "" && header.Value != "" {
  1453. if len(globalConf.HTTPConfig.Headers) > idx {
  1454. globalConf.HTTPConfig.Headers[idx] = header
  1455. } else {
  1456. globalConf.HTTPConfig.Headers = append(globalConf.HTTPConfig.Headers, header)
  1457. }
  1458. }
  1459. }
  1460. func getCommandConfigsFromEnv(idx int) {
  1461. cfg := command.Command{}
  1462. if len(globalConf.CommandConfig.Commands) > idx {
  1463. cfg = globalConf.CommandConfig.Commands[idx]
  1464. }
  1465. path, ok := os.LookupEnv(fmt.Sprintf("SFTPGO_COMMAND__COMMANDS__%v__PATH", idx))
  1466. if ok {
  1467. cfg.Path = path
  1468. }
  1469. timeout, ok := lookupIntFromEnv(fmt.Sprintf("SFTPGO_COMMAND__COMMANDS__%v__TIMEOUT", idx))
  1470. if ok {
  1471. cfg.Timeout = int(timeout)
  1472. }
  1473. env, ok := lookupStringListFromEnv(fmt.Sprintf("SFTPGO_COMMAND__COMMANDS__%v__ENV", idx))
  1474. if ok {
  1475. cfg.Env = env
  1476. }
  1477. if cfg.Path != "" {
  1478. if len(globalConf.CommandConfig.Commands) > idx {
  1479. globalConf.CommandConfig.Commands[idx] = cfg
  1480. } else {
  1481. globalConf.CommandConfig.Commands = append(globalConf.CommandConfig.Commands, cfg)
  1482. }
  1483. }
  1484. }
  1485. func setViperDefaults() {
  1486. viper.SetDefault("common.idle_timeout", globalConf.Common.IdleTimeout)
  1487. viper.SetDefault("common.upload_mode", globalConf.Common.UploadMode)
  1488. viper.SetDefault("common.actions.execute_on", globalConf.Common.Actions.ExecuteOn)
  1489. viper.SetDefault("common.actions.execute_sync", globalConf.Common.Actions.ExecuteSync)
  1490. viper.SetDefault("common.actions.hook", globalConf.Common.Actions.Hook)
  1491. viper.SetDefault("common.setstat_mode", globalConf.Common.SetstatMode)
  1492. viper.SetDefault("common.temp_path", globalConf.Common.TempPath)
  1493. viper.SetDefault("common.proxy_protocol", globalConf.Common.ProxyProtocol)
  1494. viper.SetDefault("common.proxy_allowed", globalConf.Common.ProxyAllowed)
  1495. viper.SetDefault("common.post_connect_hook", globalConf.Common.PostConnectHook)
  1496. viper.SetDefault("common.post_disconnect_hook", globalConf.Common.PostDisconnectHook)
  1497. viper.SetDefault("common.data_retention_hook", globalConf.Common.DataRetentionHook)
  1498. viper.SetDefault("common.max_total_connections", globalConf.Common.MaxTotalConnections)
  1499. viper.SetDefault("common.max_per_host_connections", globalConf.Common.MaxPerHostConnections)
  1500. viper.SetDefault("common.whitelist_file", globalConf.Common.WhiteListFile)
  1501. viper.SetDefault("common.defender.enabled", globalConf.Common.DefenderConfig.Enabled)
  1502. viper.SetDefault("common.defender.driver", globalConf.Common.DefenderConfig.Driver)
  1503. viper.SetDefault("common.defender.ban_time", globalConf.Common.DefenderConfig.BanTime)
  1504. viper.SetDefault("common.defender.ban_time_increment", globalConf.Common.DefenderConfig.BanTimeIncrement)
  1505. viper.SetDefault("common.defender.threshold", globalConf.Common.DefenderConfig.Threshold)
  1506. viper.SetDefault("common.defender.score_invalid", globalConf.Common.DefenderConfig.ScoreInvalid)
  1507. viper.SetDefault("common.defender.score_valid", globalConf.Common.DefenderConfig.ScoreValid)
  1508. viper.SetDefault("common.defender.score_limit_exceeded", globalConf.Common.DefenderConfig.ScoreLimitExceeded)
  1509. viper.SetDefault("common.defender.observation_time", globalConf.Common.DefenderConfig.ObservationTime)
  1510. viper.SetDefault("common.defender.entries_soft_limit", globalConf.Common.DefenderConfig.EntriesSoftLimit)
  1511. viper.SetDefault("common.defender.entries_hard_limit", globalConf.Common.DefenderConfig.EntriesHardLimit)
  1512. viper.SetDefault("common.defender.safelist_file", globalConf.Common.DefenderConfig.SafeListFile)
  1513. viper.SetDefault("common.defender.blocklist_file", globalConf.Common.DefenderConfig.BlockListFile)
  1514. viper.SetDefault("common.defender.safelist", globalConf.Common.DefenderConfig.SafeList)
  1515. viper.SetDefault("common.defender.blocklist", globalConf.Common.DefenderConfig.BlockList)
  1516. viper.SetDefault("acme.email", globalConf.ACME.Email)
  1517. viper.SetDefault("acme.key_type", globalConf.ACME.KeyType)
  1518. viper.SetDefault("acme.certs_path", globalConf.ACME.CertsPath)
  1519. viper.SetDefault("acme.ca_endpoint", globalConf.ACME.CAEndpoint)
  1520. viper.SetDefault("acme.domains", globalConf.ACME.Domains)
  1521. viper.SetDefault("acme.renew_days", globalConf.ACME.RenewDays)
  1522. viper.SetDefault("acme.http01_challenge.port", globalConf.ACME.HTTP01Challenge.Port)
  1523. viper.SetDefault("acme.http01_challenge.webroot", globalConf.ACME.HTTP01Challenge.WebRoot)
  1524. viper.SetDefault("acme.http01_challenge.proxy_header", globalConf.ACME.HTTP01Challenge.ProxyHeader)
  1525. viper.SetDefault("acme.tls_alpn01_challenge.port", globalConf.ACME.TLSALPN01Challenge.Port)
  1526. viper.SetDefault("sftpd.max_auth_tries", globalConf.SFTPD.MaxAuthTries)
  1527. viper.SetDefault("sftpd.banner", globalConf.SFTPD.Banner)
  1528. viper.SetDefault("sftpd.host_keys", globalConf.SFTPD.HostKeys)
  1529. viper.SetDefault("sftpd.host_certificates", globalConf.SFTPD.HostCertificates)
  1530. viper.SetDefault("sftpd.host_key_algorithms", globalConf.SFTPD.HostKeyAlgorithms)
  1531. viper.SetDefault("sftpd.kex_algorithms", globalConf.SFTPD.KexAlgorithms)
  1532. viper.SetDefault("sftpd.ciphers", globalConf.SFTPD.Ciphers)
  1533. viper.SetDefault("sftpd.macs", globalConf.SFTPD.MACs)
  1534. viper.SetDefault("sftpd.trusted_user_ca_keys", globalConf.SFTPD.TrustedUserCAKeys)
  1535. viper.SetDefault("sftpd.revoked_user_certs_file", globalConf.SFTPD.RevokedUserCertsFile)
  1536. viper.SetDefault("sftpd.login_banner_file", globalConf.SFTPD.LoginBannerFile)
  1537. viper.SetDefault("sftpd.enabled_ssh_commands", sftpd.GetDefaultSSHCommands())
  1538. viper.SetDefault("sftpd.keyboard_interactive_authentication", globalConf.SFTPD.KeyboardInteractiveAuthentication)
  1539. viper.SetDefault("sftpd.keyboard_interactive_auth_hook", globalConf.SFTPD.KeyboardInteractiveHook)
  1540. viper.SetDefault("sftpd.password_authentication", globalConf.SFTPD.PasswordAuthentication)
  1541. viper.SetDefault("sftpd.folder_prefix", globalConf.SFTPD.FolderPrefix)
  1542. viper.SetDefault("ftpd.banner", globalConf.FTPD.Banner)
  1543. viper.SetDefault("ftpd.banner_file", globalConf.FTPD.BannerFile)
  1544. viper.SetDefault("ftpd.active_transfers_port_non_20", globalConf.FTPD.ActiveTransfersPortNon20)
  1545. viper.SetDefault("ftpd.passive_port_range.start", globalConf.FTPD.PassivePortRange.Start)
  1546. viper.SetDefault("ftpd.passive_port_range.end", globalConf.FTPD.PassivePortRange.End)
  1547. viper.SetDefault("ftpd.disable_active_mode", globalConf.FTPD.DisableActiveMode)
  1548. viper.SetDefault("ftpd.enable_site", globalConf.FTPD.EnableSite)
  1549. viper.SetDefault("ftpd.hash_support", globalConf.FTPD.HASHSupport)
  1550. viper.SetDefault("ftpd.combine_support", globalConf.FTPD.CombineSupport)
  1551. viper.SetDefault("ftpd.certificate_file", globalConf.FTPD.CertificateFile)
  1552. viper.SetDefault("ftpd.certificate_key_file", globalConf.FTPD.CertificateKeyFile)
  1553. viper.SetDefault("ftpd.ca_certificates", globalConf.FTPD.CACertificates)
  1554. viper.SetDefault("ftpd.ca_revocation_lists", globalConf.FTPD.CARevocationLists)
  1555. viper.SetDefault("webdavd.certificate_file", globalConf.WebDAVD.CertificateFile)
  1556. viper.SetDefault("webdavd.certificate_key_file", globalConf.WebDAVD.CertificateKeyFile)
  1557. viper.SetDefault("webdavd.ca_certificates", globalConf.WebDAVD.CACertificates)
  1558. viper.SetDefault("webdavd.ca_revocation_lists", globalConf.WebDAVD.CARevocationLists)
  1559. viper.SetDefault("webdavd.cors.enabled", globalConf.WebDAVD.Cors.Enabled)
  1560. viper.SetDefault("webdavd.cors.allowed_origins", globalConf.WebDAVD.Cors.AllowedOrigins)
  1561. viper.SetDefault("webdavd.cors.allowed_methods", globalConf.WebDAVD.Cors.AllowedMethods)
  1562. viper.SetDefault("webdavd.cors.allowed_headers", globalConf.WebDAVD.Cors.AllowedHeaders)
  1563. viper.SetDefault("webdavd.cors.exposed_headers", globalConf.WebDAVD.Cors.ExposedHeaders)
  1564. viper.SetDefault("webdavd.cors.allow_credentials", globalConf.WebDAVD.Cors.AllowCredentials)
  1565. viper.SetDefault("webdavd.cors.max_age", globalConf.WebDAVD.Cors.MaxAge)
  1566. viper.SetDefault("webdavd.cache.users.expiration_time", globalConf.WebDAVD.Cache.Users.ExpirationTime)
  1567. viper.SetDefault("webdavd.cache.users.max_size", globalConf.WebDAVD.Cache.Users.MaxSize)
  1568. viper.SetDefault("webdavd.cache.mime_types.enabled", globalConf.WebDAVD.Cache.MimeTypes.Enabled)
  1569. viper.SetDefault("webdavd.cache.mime_types.max_size", globalConf.WebDAVD.Cache.MimeTypes.MaxSize)
  1570. viper.SetDefault("data_provider.driver", globalConf.ProviderConf.Driver)
  1571. viper.SetDefault("data_provider.name", globalConf.ProviderConf.Name)
  1572. viper.SetDefault("data_provider.host", globalConf.ProviderConf.Host)
  1573. viper.SetDefault("data_provider.port", globalConf.ProviderConf.Port)
  1574. viper.SetDefault("data_provider.username", globalConf.ProviderConf.Username)
  1575. viper.SetDefault("data_provider.password", globalConf.ProviderConf.Password)
  1576. viper.SetDefault("data_provider.sslmode", globalConf.ProviderConf.SSLMode)
  1577. viper.SetDefault("data_provider.root_cert", globalConf.ProviderConf.RootCert)
  1578. viper.SetDefault("data_provider.client_cert", globalConf.ProviderConf.ClientCert)
  1579. viper.SetDefault("data_provider.client_key", globalConf.ProviderConf.ClientKey)
  1580. viper.SetDefault("data_provider.connection_string", globalConf.ProviderConf.ConnectionString)
  1581. viper.SetDefault("data_provider.sql_tables_prefix", globalConf.ProviderConf.SQLTablesPrefix)
  1582. viper.SetDefault("data_provider.track_quota", globalConf.ProviderConf.TrackQuota)
  1583. viper.SetDefault("data_provider.pool_size", globalConf.ProviderConf.PoolSize)
  1584. viper.SetDefault("data_provider.users_base_dir", globalConf.ProviderConf.UsersBaseDir)
  1585. viper.SetDefault("data_provider.actions.execute_on", globalConf.ProviderConf.Actions.ExecuteOn)
  1586. viper.SetDefault("data_provider.actions.execute_for", globalConf.ProviderConf.Actions.ExecuteFor)
  1587. viper.SetDefault("data_provider.actions.hook", globalConf.ProviderConf.Actions.Hook)
  1588. viper.SetDefault("data_provider.external_auth_hook", globalConf.ProviderConf.ExternalAuthHook)
  1589. viper.SetDefault("data_provider.external_auth_scope", globalConf.ProviderConf.ExternalAuthScope)
  1590. viper.SetDefault("data_provider.credentials_path", globalConf.ProviderConf.CredentialsPath)
  1591. viper.SetDefault("data_provider.pre_login_hook", globalConf.ProviderConf.PreLoginHook)
  1592. viper.SetDefault("data_provider.post_login_hook", globalConf.ProviderConf.PostLoginHook)
  1593. viper.SetDefault("data_provider.post_login_scope", globalConf.ProviderConf.PostLoginScope)
  1594. viper.SetDefault("data_provider.check_password_hook", globalConf.ProviderConf.CheckPasswordHook)
  1595. viper.SetDefault("data_provider.check_password_scope", globalConf.ProviderConf.CheckPasswordScope)
  1596. viper.SetDefault("data_provider.password_hashing.bcrypt_options.cost", globalConf.ProviderConf.PasswordHashing.BcryptOptions.Cost)
  1597. viper.SetDefault("data_provider.password_hashing.argon2_options.memory", globalConf.ProviderConf.PasswordHashing.Argon2Options.Memory)
  1598. viper.SetDefault("data_provider.password_hashing.argon2_options.iterations", globalConf.ProviderConf.PasswordHashing.Argon2Options.Iterations)
  1599. viper.SetDefault("data_provider.password_hashing.argon2_options.parallelism", globalConf.ProviderConf.PasswordHashing.Argon2Options.Parallelism)
  1600. viper.SetDefault("data_provider.password_hashing.algo", globalConf.ProviderConf.PasswordHashing.Algo)
  1601. viper.SetDefault("data_provider.password_validation.admins.min_entropy", globalConf.ProviderConf.PasswordValidation.Admins.MinEntropy)
  1602. viper.SetDefault("data_provider.password_validation.users.min_entropy", globalConf.ProviderConf.PasswordValidation.Users.MinEntropy)
  1603. viper.SetDefault("data_provider.password_caching", globalConf.ProviderConf.PasswordCaching)
  1604. viper.SetDefault("data_provider.update_mode", globalConf.ProviderConf.UpdateMode)
  1605. viper.SetDefault("data_provider.delayed_quota_update", globalConf.ProviderConf.DelayedQuotaUpdate)
  1606. viper.SetDefault("data_provider.create_default_admin", globalConf.ProviderConf.CreateDefaultAdmin)
  1607. viper.SetDefault("data_provider.naming_rules", globalConf.ProviderConf.NamingRules)
  1608. viper.SetDefault("data_provider.is_shared", globalConf.ProviderConf.IsShared)
  1609. viper.SetDefault("data_provider.backups_path", globalConf.ProviderConf.BackupsPath)
  1610. viper.SetDefault("data_provider.auto_backup.enabled", globalConf.ProviderConf.AutoBackup.Enabled)
  1611. viper.SetDefault("data_provider.auto_backup.hour", globalConf.ProviderConf.AutoBackup.Hour)
  1612. viper.SetDefault("data_provider.auto_backup.day_of_week", globalConf.ProviderConf.AutoBackup.DayOfWeek)
  1613. viper.SetDefault("httpd.templates_path", globalConf.HTTPDConfig.TemplatesPath)
  1614. viper.SetDefault("httpd.static_files_path", globalConf.HTTPDConfig.StaticFilesPath)
  1615. viper.SetDefault("httpd.openapi_path", globalConf.HTTPDConfig.OpenAPIPath)
  1616. viper.SetDefault("httpd.web_root", globalConf.HTTPDConfig.WebRoot)
  1617. viper.SetDefault("httpd.certificate_file", globalConf.HTTPDConfig.CertificateFile)
  1618. viper.SetDefault("httpd.certificate_key_file", globalConf.HTTPDConfig.CertificateKeyFile)
  1619. viper.SetDefault("httpd.ca_certificates", globalConf.HTTPDConfig.CACertificates)
  1620. viper.SetDefault("httpd.ca_revocation_lists", globalConf.HTTPDConfig.CARevocationLists)
  1621. viper.SetDefault("httpd.signing_passphrase", globalConf.HTTPDConfig.SigningPassphrase)
  1622. viper.SetDefault("httpd.max_upload_file_size", globalConf.HTTPDConfig.MaxUploadFileSize)
  1623. viper.SetDefault("httpd.cors.enabled", globalConf.HTTPDConfig.Cors.Enabled)
  1624. viper.SetDefault("httpd.cors.allowed_origins", globalConf.HTTPDConfig.Cors.AllowedOrigins)
  1625. viper.SetDefault("httpd.cors.allowed_methods", globalConf.HTTPDConfig.Cors.AllowedMethods)
  1626. viper.SetDefault("httpd.cors.allowed_headers", globalConf.HTTPDConfig.Cors.AllowedHeaders)
  1627. viper.SetDefault("httpd.cors.exposed_headers", globalConf.HTTPDConfig.Cors.ExposedHeaders)
  1628. viper.SetDefault("httpd.cors.allow_credentials", globalConf.HTTPDConfig.Cors.AllowCredentials)
  1629. viper.SetDefault("httpd.setup.installation_code", globalConf.HTTPDConfig.Setup.InstallationCode)
  1630. viper.SetDefault("httpd.setup.installation_code_hint", globalConf.HTTPDConfig.Setup.InstallationCodeHint)
  1631. viper.SetDefault("httpd.cors.max_age", globalConf.HTTPDConfig.Cors.MaxAge)
  1632. viper.SetDefault("http.timeout", globalConf.HTTPConfig.Timeout)
  1633. viper.SetDefault("http.retry_wait_min", globalConf.HTTPConfig.RetryWaitMin)
  1634. viper.SetDefault("http.retry_wait_max", globalConf.HTTPConfig.RetryWaitMax)
  1635. viper.SetDefault("http.retry_max", globalConf.HTTPConfig.RetryMax)
  1636. viper.SetDefault("http.ca_certificates", globalConf.HTTPConfig.CACertificates)
  1637. viper.SetDefault("http.skip_tls_verify", globalConf.HTTPConfig.SkipTLSVerify)
  1638. viper.SetDefault("command.timeout", globalConf.CommandConfig.Timeout)
  1639. viper.SetDefault("command.env", globalConf.CommandConfig.Env)
  1640. viper.SetDefault("kms.secrets.url", globalConf.KMSConfig.Secrets.URL)
  1641. viper.SetDefault("kms.secrets.master_key", globalConf.KMSConfig.Secrets.MasterKeyString)
  1642. viper.SetDefault("kms.secrets.master_key_path", globalConf.KMSConfig.Secrets.MasterKeyPath)
  1643. viper.SetDefault("telemetry.bind_port", globalConf.TelemetryConfig.BindPort)
  1644. viper.SetDefault("telemetry.bind_address", globalConf.TelemetryConfig.BindAddress)
  1645. viper.SetDefault("telemetry.enable_profiler", globalConf.TelemetryConfig.EnableProfiler)
  1646. viper.SetDefault("telemetry.auth_user_file", globalConf.TelemetryConfig.AuthUserFile)
  1647. viper.SetDefault("telemetry.certificate_file", globalConf.TelemetryConfig.CertificateFile)
  1648. viper.SetDefault("telemetry.certificate_key_file", globalConf.TelemetryConfig.CertificateKeyFile)
  1649. viper.SetDefault("telemetry.min_tls_version", globalConf.TelemetryConfig.MinTLSVersion)
  1650. viper.SetDefault("telemetry.tls_cipher_suites", globalConf.TelemetryConfig.TLSCipherSuites)
  1651. viper.SetDefault("smtp.host", globalConf.SMTPConfig.Host)
  1652. viper.SetDefault("smtp.port", globalConf.SMTPConfig.Port)
  1653. viper.SetDefault("smtp.from", globalConf.SMTPConfig.From)
  1654. viper.SetDefault("smtp.user", globalConf.SMTPConfig.User)
  1655. viper.SetDefault("smtp.password", globalConf.SMTPConfig.Password)
  1656. viper.SetDefault("smtp.auth_type", globalConf.SMTPConfig.AuthType)
  1657. viper.SetDefault("smtp.encryption", globalConf.SMTPConfig.Encryption)
  1658. viper.SetDefault("smtp.domain", globalConf.SMTPConfig.Domain)
  1659. viper.SetDefault("smtp.templates_path", globalConf.SMTPConfig.TemplatesPath)
  1660. }
  1661. func lookupBoolFromEnv(envName string) (bool, bool) {
  1662. value, ok := os.LookupEnv(envName)
  1663. if ok {
  1664. converted, err := strconv.ParseBool(strings.TrimSpace(value))
  1665. if err == nil {
  1666. return converted, ok
  1667. }
  1668. }
  1669. return false, false
  1670. }
  1671. func lookupIntFromEnv(envName string) (int64, bool) {
  1672. value, ok := os.LookupEnv(envName)
  1673. if ok {
  1674. converted, err := strconv.ParseInt(strings.TrimSpace(value), 10, 64)
  1675. if err == nil {
  1676. return converted, ok
  1677. }
  1678. }
  1679. return 0, false
  1680. }
  1681. func lookupStringListFromEnv(envName string) ([]string, bool) {
  1682. value, ok := os.LookupEnv(envName)
  1683. if ok {
  1684. var result []string
  1685. for _, v := range strings.Split(value, ",") {
  1686. val := strings.TrimSpace(v)
  1687. if val != "" {
  1688. result = append(result, val)
  1689. }
  1690. }
  1691. return result, true
  1692. }
  1693. return nil, false
  1694. }