pgsql.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348
  1. // +build !nopgsql
  2. package dataprovider
  3. import (
  4. "context"
  5. "crypto/x509"
  6. "database/sql"
  7. "errors"
  8. "fmt"
  9. "strings"
  10. "time"
  11. // we import lib/pq here to be able to disable PostgreSQL support using a build tag
  12. _ "github.com/lib/pq"
  13. "github.com/drakkan/sftpgo/v2/logger"
  14. "github.com/drakkan/sftpgo/v2/version"
  15. "github.com/drakkan/sftpgo/v2/vfs"
  16. )
  17. const (
  18. pgsqlInitial = `CREATE TABLE "{{schema_version}}" ("id" serial NOT NULL PRIMARY KEY, "version" integer NOT NULL);
  19. CREATE TABLE "{{admins}}" ("id" serial NOT NULL PRIMARY KEY, "username" varchar(255) NOT NULL UNIQUE,
  20. "description" varchar(512) NULL, "password" varchar(255) NOT NULL, "email" varchar(255) NULL, "status" integer NOT NULL,
  21. "permissions" text NOT NULL, "filters" text NULL, "additional_info" text NULL);
  22. CREATE TABLE "{{folders}}" ("id" serial NOT NULL PRIMARY KEY, "name" varchar(255) NOT NULL UNIQUE, "description" varchar(512) NULL,
  23. "path" varchar(512) NULL, "used_quota_size" bigint NOT NULL, "used_quota_files" integer NOT NULL, "last_quota_update" bigint NOT NULL,
  24. "filesystem" text NULL);
  25. CREATE TABLE "{{users}}" ("id" serial NOT NULL PRIMARY KEY, "username" varchar(255) NOT NULL UNIQUE, "status" integer NOT NULL,
  26. "expiration_date" bigint NOT NULL, "description" varchar(512) NULL, "password" text NULL, "public_keys" text NULL,
  27. "home_dir" varchar(512) NOT NULL, "uid" integer NOT NULL, "gid" integer NOT NULL, "max_sessions" integer NOT NULL,
  28. "quota_size" bigint NOT NULL, "quota_files" integer NOT NULL, "permissions" text NOT NULL, "used_quota_size" bigint NOT NULL,
  29. "used_quota_files" integer NOT NULL, "last_quota_update" bigint NOT NULL, "upload_bandwidth" integer NOT NULL,
  30. "download_bandwidth" integer NOT NULL, "last_login" bigint NOT NULL, "filters" text NULL, "filesystem" text NULL,
  31. "additional_info" text NULL);
  32. CREATE TABLE "{{folders_mapping}}" ("id" serial NOT NULL PRIMARY KEY, "virtual_path" varchar(512) NOT NULL,
  33. "quota_size" bigint NOT NULL, "quota_files" integer NOT NULL, "folder_id" integer NOT NULL, "user_id" integer NOT NULL);
  34. ALTER TABLE "{{folders_mapping}}" ADD CONSTRAINT "{{prefix}}unique_mapping" UNIQUE ("user_id", "folder_id");
  35. ALTER TABLE "{{folders_mapping}}" ADD CONSTRAINT "{{prefix}}folders_mapping_folder_id_fk_folders_id"
  36. FOREIGN KEY ("folder_id") REFERENCES "{{folders}}" ("id") MATCH SIMPLE ON UPDATE NO ACTION ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED;
  37. ALTER TABLE "{{folders_mapping}}" ADD CONSTRAINT "{{prefix}}folders_mapping_user_id_fk_users_id"
  38. FOREIGN KEY ("user_id") REFERENCES "{{users}}" ("id") MATCH SIMPLE ON UPDATE NO ACTION ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED;
  39. CREATE INDEX "{{prefix}}folders_mapping_folder_id_idx" ON "{{folders_mapping}}" ("folder_id");
  40. CREATE INDEX "{{prefix}}folders_mapping_user_id_idx" ON "{{folders_mapping}}" ("user_id");
  41. INSERT INTO {{schema_version}} (version) VALUES (10);
  42. `
  43. pgsqlV11SQL = `CREATE TABLE "{{api_keys}}" ("id" serial NOT NULL PRIMARY KEY, "name" varchar(255) NOT NULL,
  44. "key_id" varchar(50) NOT NULL UNIQUE, "api_key" varchar(255) NOT NULL UNIQUE, "scope" integer NOT NULL,
  45. "created_at" bigint NOT NULL, "updated_at" bigint NOT NULL, "last_use_at" bigint NOT NULL,"expires_at" bigint NOT NULL,
  46. "description" text NULL, "admin_id" integer NULL, "user_id" integer NULL);
  47. ALTER TABLE "{{api_keys}}" ADD CONSTRAINT "{{prefix}}api_keys_admin_id_fk_admins_id" FOREIGN KEY ("admin_id")
  48. REFERENCES "{{admins}}" ("id") MATCH SIMPLE ON UPDATE NO ACTION ON DELETE CASCADE;
  49. ALTER TABLE "{{api_keys}}" ADD CONSTRAINT "{{prefix}}api_keys_user_id_fk_users_id" FOREIGN KEY ("user_id")
  50. REFERENCES "{{users}}" ("id") MATCH SIMPLE ON UPDATE NO ACTION ON DELETE CASCADE;
  51. CREATE INDEX "{{prefix}}api_keys_admin_id_idx" ON "{{api_keys}}" ("admin_id");
  52. CREATE INDEX "{{prefix}}api_keys_user_id_idx" ON "{{api_keys}}" ("user_id");
  53. `
  54. pgsqlV11DownSQL = `DROP TABLE "{{api_keys}}" CASCADE;`
  55. )
  56. // PGSQLProvider auth provider for PostgreSQL database
  57. type PGSQLProvider struct {
  58. dbHandle *sql.DB
  59. }
  60. func init() {
  61. version.AddFeature("+pgsql")
  62. }
  63. func initializePGSQLProvider() error {
  64. var err error
  65. dbHandle, err := sql.Open("postgres", getPGSQLConnectionString(false))
  66. if err == nil {
  67. providerLog(logger.LevelDebug, "postgres database handle created, connection string: %#v, pool size: %v",
  68. getPGSQLConnectionString(true), config.PoolSize)
  69. dbHandle.SetMaxOpenConns(config.PoolSize)
  70. if config.PoolSize > 0 {
  71. dbHandle.SetMaxIdleConns(config.PoolSize)
  72. } else {
  73. dbHandle.SetMaxIdleConns(2)
  74. }
  75. dbHandle.SetConnMaxLifetime(240 * time.Second)
  76. provider = &PGSQLProvider{dbHandle: dbHandle}
  77. } else {
  78. providerLog(logger.LevelWarn, "error creating postgres database handler, connection string: %#v, error: %v",
  79. getPGSQLConnectionString(true), err)
  80. }
  81. return err
  82. }
  83. func getPGSQLConnectionString(redactedPwd bool) string {
  84. var connectionString string
  85. if config.ConnectionString == "" {
  86. password := config.Password
  87. if redactedPwd {
  88. password = "[redacted]"
  89. }
  90. connectionString = fmt.Sprintf("host='%v' port=%v dbname='%v' user='%v' password='%v' sslmode=%v connect_timeout=10",
  91. config.Host, config.Port, config.Name, config.Username, password, getSSLMode())
  92. } else {
  93. connectionString = config.ConnectionString
  94. }
  95. return connectionString
  96. }
  97. func (p *PGSQLProvider) checkAvailability() error {
  98. return sqlCommonCheckAvailability(p.dbHandle)
  99. }
  100. func (p *PGSQLProvider) validateUserAndPass(username, password, ip, protocol string) (User, error) {
  101. return sqlCommonValidateUserAndPass(username, password, ip, protocol, p.dbHandle)
  102. }
  103. func (p *PGSQLProvider) validateUserAndTLSCert(username, protocol string, tlsCert *x509.Certificate) (User, error) {
  104. return sqlCommonValidateUserAndTLSCertificate(username, protocol, tlsCert, p.dbHandle)
  105. }
  106. func (p *PGSQLProvider) validateUserAndPubKey(username string, publicKey []byte) (User, string, error) {
  107. return sqlCommonValidateUserAndPubKey(username, publicKey, p.dbHandle)
  108. }
  109. func (p *PGSQLProvider) updateQuota(username string, filesAdd int, sizeAdd int64, reset bool) error {
  110. return sqlCommonUpdateQuota(username, filesAdd, sizeAdd, reset, p.dbHandle)
  111. }
  112. func (p *PGSQLProvider) getUsedQuota(username string) (int, int64, error) {
  113. return sqlCommonGetUsedQuota(username, p.dbHandle)
  114. }
  115. func (p *PGSQLProvider) updateLastLogin(username string) error {
  116. return sqlCommonUpdateLastLogin(username, p.dbHandle)
  117. }
  118. func (p *PGSQLProvider) userExists(username string) (User, error) {
  119. return sqlCommonGetUserByUsername(username, p.dbHandle)
  120. }
  121. func (p *PGSQLProvider) addUser(user *User) error {
  122. return sqlCommonAddUser(user, p.dbHandle)
  123. }
  124. func (p *PGSQLProvider) updateUser(user *User) error {
  125. return sqlCommonUpdateUser(user, p.dbHandle)
  126. }
  127. func (p *PGSQLProvider) deleteUser(user *User) error {
  128. return sqlCommonDeleteUser(user, p.dbHandle)
  129. }
  130. func (p *PGSQLProvider) dumpUsers() ([]User, error) {
  131. return sqlCommonDumpUsers(p.dbHandle)
  132. }
  133. func (p *PGSQLProvider) getUsers(limit int, offset int, order string) ([]User, error) {
  134. return sqlCommonGetUsers(limit, offset, order, p.dbHandle)
  135. }
  136. func (p *PGSQLProvider) dumpFolders() ([]vfs.BaseVirtualFolder, error) {
  137. return sqlCommonDumpFolders(p.dbHandle)
  138. }
  139. func (p *PGSQLProvider) getFolders(limit, offset int, order string) ([]vfs.BaseVirtualFolder, error) {
  140. return sqlCommonGetFolders(limit, offset, order, p.dbHandle)
  141. }
  142. func (p *PGSQLProvider) getFolderByName(name string) (vfs.BaseVirtualFolder, error) {
  143. ctx, cancel := context.WithTimeout(context.Background(), defaultSQLQueryTimeout)
  144. defer cancel()
  145. return sqlCommonGetFolderByName(ctx, name, p.dbHandle)
  146. }
  147. func (p *PGSQLProvider) addFolder(folder *vfs.BaseVirtualFolder) error {
  148. return sqlCommonAddFolder(folder, p.dbHandle)
  149. }
  150. func (p *PGSQLProvider) updateFolder(folder *vfs.BaseVirtualFolder) error {
  151. return sqlCommonUpdateFolder(folder, p.dbHandle)
  152. }
  153. func (p *PGSQLProvider) deleteFolder(folder *vfs.BaseVirtualFolder) error {
  154. return sqlCommonDeleteFolder(folder, p.dbHandle)
  155. }
  156. func (p *PGSQLProvider) updateFolderQuota(name string, filesAdd int, sizeAdd int64, reset bool) error {
  157. return sqlCommonUpdateFolderQuota(name, filesAdd, sizeAdd, reset, p.dbHandle)
  158. }
  159. func (p *PGSQLProvider) getUsedFolderQuota(name string) (int, int64, error) {
  160. return sqlCommonGetFolderUsedQuota(name, p.dbHandle)
  161. }
  162. func (p *PGSQLProvider) adminExists(username string) (Admin, error) {
  163. return sqlCommonGetAdminByUsername(username, p.dbHandle)
  164. }
  165. func (p *PGSQLProvider) addAdmin(admin *Admin) error {
  166. return sqlCommonAddAdmin(admin, p.dbHandle)
  167. }
  168. func (p *PGSQLProvider) updateAdmin(admin *Admin) error {
  169. return sqlCommonUpdateAdmin(admin, p.dbHandle)
  170. }
  171. func (p *PGSQLProvider) deleteAdmin(admin *Admin) error {
  172. return sqlCommonDeleteAdmin(admin, p.dbHandle)
  173. }
  174. func (p *PGSQLProvider) getAdmins(limit int, offset int, order string) ([]Admin, error) {
  175. return sqlCommonGetAdmins(limit, offset, order, p.dbHandle)
  176. }
  177. func (p *PGSQLProvider) dumpAdmins() ([]Admin, error) {
  178. return sqlCommonDumpAdmins(p.dbHandle)
  179. }
  180. func (p *PGSQLProvider) validateAdminAndPass(username, password, ip string) (Admin, error) {
  181. return sqlCommonValidateAdminAndPass(username, password, ip, p.dbHandle)
  182. }
  183. func (p *PGSQLProvider) apiKeyExists(keyID string) (APIKey, error) {
  184. return sqlCommonGetAPIKeyByID(keyID, p.dbHandle)
  185. }
  186. func (p *PGSQLProvider) addAPIKey(apiKey *APIKey) error {
  187. return sqlCommonAddAPIKey(apiKey, p.dbHandle)
  188. }
  189. func (p *PGSQLProvider) updateAPIKey(apiKey *APIKey) error {
  190. return sqlCommonUpdateAPIKey(apiKey, p.dbHandle)
  191. }
  192. func (p *PGSQLProvider) deleteAPIKeys(apiKey *APIKey) error {
  193. return sqlCommonDeleteAPIKey(apiKey, p.dbHandle)
  194. }
  195. func (p *PGSQLProvider) getAPIKeys(limit int, offset int, order string) ([]APIKey, error) {
  196. return sqlCommonGetAPIKeys(limit, offset, order, p.dbHandle)
  197. }
  198. func (p *PGSQLProvider) dumpAPIKeys() ([]APIKey, error) {
  199. return sqlCommonDumpAPIKeys(p.dbHandle)
  200. }
  201. func (p *PGSQLProvider) updateAPIKeyLastUse(keyID string) error {
  202. return sqlCommonUpdateAPIKeyLastUse(keyID, p.dbHandle)
  203. }
  204. func (p *PGSQLProvider) close() error {
  205. return p.dbHandle.Close()
  206. }
  207. func (p *PGSQLProvider) reloadConfig() error {
  208. return nil
  209. }
  210. // initializeDatabase creates the initial database structure
  211. func (p *PGSQLProvider) initializeDatabase() error {
  212. dbVersion, err := sqlCommonGetDatabaseVersion(p.dbHandle, false)
  213. if err == nil && dbVersion.Version > 0 {
  214. return ErrNoInitRequired
  215. }
  216. initialSQL := strings.ReplaceAll(pgsqlInitial, "{{schema_version}}", sqlTableSchemaVersion)
  217. initialSQL = strings.ReplaceAll(initialSQL, "{{admins}}", sqlTableAdmins)
  218. initialSQL = strings.ReplaceAll(initialSQL, "{{folders}}", sqlTableFolders)
  219. initialSQL = strings.ReplaceAll(initialSQL, "{{users}}", sqlTableUsers)
  220. initialSQL = strings.ReplaceAll(initialSQL, "{{folders_mapping}}", sqlTableFoldersMapping)
  221. initialSQL = strings.ReplaceAll(initialSQL, "{{prefix}}", config.SQLTablesPrefix)
  222. if config.Driver == CockroachDataProviderName {
  223. // Cockroach does not support deferrable constraint validation, we don't need them,
  224. // we keep these definitions for the PostgreSQL driver to avoid changes for users
  225. // upgrading from old SFTPGo versions
  226. initialSQL = strings.ReplaceAll(initialSQL, "DEFERRABLE INITIALLY DEFERRED", "")
  227. }
  228. return sqlCommonExecSQLAndUpdateDBVersion(p.dbHandle, []string{initialSQL}, 10)
  229. }
  230. func (p *PGSQLProvider) migrateDatabase() error {
  231. dbVersion, err := sqlCommonGetDatabaseVersion(p.dbHandle, true)
  232. if err != nil {
  233. return err
  234. }
  235. switch version := dbVersion.Version; {
  236. case version == sqlDatabaseVersion:
  237. providerLog(logger.LevelDebug, "sql database is up to date, current version: %v", version)
  238. return ErrNoInitRequired
  239. case version < 10:
  240. err = fmt.Errorf("database version %v is too old, please see the upgrading docs", version)
  241. providerLog(logger.LevelError, "%v", err)
  242. logger.ErrorToConsole("%v", err)
  243. return err
  244. case version == 10:
  245. return updatePGSQLDatabaseFromV10(p.dbHandle)
  246. default:
  247. if version > sqlDatabaseVersion {
  248. providerLog(logger.LevelWarn, "database version %v is newer than the supported one: %v", version,
  249. sqlDatabaseVersion)
  250. logger.WarnToConsole("database version %v is newer than the supported one: %v", version,
  251. sqlDatabaseVersion)
  252. return nil
  253. }
  254. return fmt.Errorf("database version not handled: %v", version)
  255. }
  256. }
  257. func (p *PGSQLProvider) revertDatabase(targetVersion int) error {
  258. dbVersion, err := sqlCommonGetDatabaseVersion(p.dbHandle, true)
  259. if err != nil {
  260. return err
  261. }
  262. if dbVersion.Version == targetVersion {
  263. return errors.New("current version match target version, nothing to do")
  264. }
  265. switch dbVersion.Version {
  266. case 11:
  267. return downgradePGSQLDatabaseFromV11(p.dbHandle)
  268. default:
  269. return fmt.Errorf("database version not handled: %v", dbVersion.Version)
  270. }
  271. }
  272. func updatePGSQLDatabaseFromV10(dbHandle *sql.DB) error {
  273. return updatePGSQLDatabaseFrom10To11(dbHandle)
  274. }
  275. func downgradePGSQLDatabaseFromV11(dbHandle *sql.DB) error {
  276. return downgradePGSQLDatabaseFrom11To10(dbHandle)
  277. }
  278. func updatePGSQLDatabaseFrom10To11(dbHandle *sql.DB) error {
  279. logger.InfoToConsole("updating database version: 10 -> 11")
  280. providerLog(logger.LevelInfo, "updating database version: 10 -> 11")
  281. sql := strings.ReplaceAll(pgsqlV11SQL, "{{users}}", sqlTableUsers)
  282. sql = strings.ReplaceAll(sql, "{{admins}}", sqlTableAdmins)
  283. sql = strings.ReplaceAll(sql, "{{api_keys}}", sqlTableAPIKeys)
  284. sql = strings.ReplaceAll(sql, "{{prefix}}", config.SQLTablesPrefix)
  285. return sqlCommonExecSQLAndUpdateDBVersion(dbHandle, []string{sql}, 11)
  286. }
  287. func downgradePGSQLDatabaseFrom11To10(dbHandle *sql.DB) error {
  288. logger.InfoToConsole("downgrading database version: 11 -> 10")
  289. providerLog(logger.LevelInfo, "downgrading database version: 11 -> 10")
  290. sql := strings.ReplaceAll(pgsqlV11DownSQL, "{{api_keys}}", sqlTableAPIKeys)
  291. return sqlCommonExecSQLAndUpdateDBVersion(dbHandle, []string{sql}, 10)
  292. }