2020-03-20 05:46:22 +08:00
|
|
|
// Copyright 2015 Matthew Holt and The Caddy Authors
|
|
|
|
//
|
|
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
// you may not use this file except in compliance with the License.
|
|
|
|
// You may obtain a copy of the License at
|
|
|
|
//
|
|
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
//
|
|
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
// See the License for the specific language governing permissions and
|
|
|
|
// limitations under the License.
|
|
|
|
|
|
|
|
package caddyhttp
|
|
|
|
|
|
|
|
import (
|
2020-08-01 05:06:30 +08:00
|
|
|
"crypto/x509/pkix"
|
2020-03-20 05:46:22 +08:00
|
|
|
"encoding/json"
|
2022-06-23 06:53:46 +08:00
|
|
|
"errors"
|
2020-03-20 05:46:22 +08:00
|
|
|
"fmt"
|
|
|
|
"net/http"
|
|
|
|
"reflect"
|
|
|
|
"regexp"
|
|
|
|
"strings"
|
2020-05-22 08:19:01 +08:00
|
|
|
"time"
|
2020-03-20 05:46:22 +08:00
|
|
|
|
|
|
|
"github.com/caddyserver/caddy/v2"
|
|
|
|
"github.com/caddyserver/caddy/v2/caddyconfig/caddyfile"
|
|
|
|
"github.com/google/cel-go/cel"
|
2022-06-23 06:53:46 +08:00
|
|
|
"github.com/google/cel-go/common"
|
|
|
|
"github.com/google/cel-go/common/operators"
|
2020-03-20 05:46:22 +08:00
|
|
|
"github.com/google/cel-go/common/types"
|
|
|
|
"github.com/google/cel-go/common/types/ref"
|
|
|
|
"github.com/google/cel-go/common/types/traits"
|
2020-03-20 22:53:40 +08:00
|
|
|
"github.com/google/cel-go/ext"
|
2022-06-23 06:53:46 +08:00
|
|
|
"github.com/google/cel-go/interpreter"
|
2020-03-20 05:46:22 +08:00
|
|
|
"github.com/google/cel-go/interpreter/functions"
|
2022-06-23 06:53:46 +08:00
|
|
|
"github.com/google/cel-go/parser"
|
2022-06-09 06:42:24 +08:00
|
|
|
"go.uber.org/zap"
|
2020-03-20 05:46:22 +08:00
|
|
|
exprpb "google.golang.org/genproto/googleapis/api/expr/v1alpha1"
|
|
|
|
)
|
|
|
|
|
|
|
|
func init() {
|
|
|
|
caddy.RegisterModule(MatchExpression{})
|
|
|
|
}
|
|
|
|
|
|
|
|
// MatchExpression matches requests by evaluating a
|
|
|
|
// [CEL](https://github.com/google/cel-spec) expression.
|
|
|
|
// This enables complex logic to be expressed using a comfortable,
|
2020-05-14 01:11:31 +08:00
|
|
|
// familiar syntax. Please refer to
|
|
|
|
// [the standard definitions of CEL functions and operators](https://github.com/google/cel-spec/blob/master/doc/langdef.md#standard-definitions).
|
2020-03-20 05:46:22 +08:00
|
|
|
//
|
2020-04-11 23:01:40 +08:00
|
|
|
// This matcher's JSON interface is actually a string, not a struct.
|
|
|
|
// The generated docs are not correct because this type has custom
|
|
|
|
// marshaling logic.
|
|
|
|
//
|
2020-03-20 05:46:22 +08:00
|
|
|
// COMPATIBILITY NOTE: This module is still experimental and is not
|
|
|
|
// subject to Caddy's compatibility guarantee.
|
|
|
|
type MatchExpression struct {
|
|
|
|
// The CEL expression to evaluate. Any Caddy placeholders
|
|
|
|
// will be expanded and situated into proper CEL function
|
|
|
|
// calls before evaluating.
|
|
|
|
Expr string
|
|
|
|
|
|
|
|
expandedExpr string
|
|
|
|
prg cel.Program
|
2020-04-09 00:44:36 +08:00
|
|
|
ta ref.TypeAdapter
|
2022-06-09 06:42:24 +08:00
|
|
|
|
|
|
|
log *zap.Logger
|
2020-03-20 05:46:22 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
// CaddyModule returns the Caddy module information.
|
|
|
|
func (MatchExpression) CaddyModule() caddy.ModuleInfo {
|
|
|
|
return caddy.ModuleInfo{
|
|
|
|
ID: "http.matchers.expression",
|
|
|
|
New: func() caddy.Module { return new(MatchExpression) },
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// MarshalJSON marshals m's expression.
|
|
|
|
func (m MatchExpression) MarshalJSON() ([]byte, error) {
|
|
|
|
return json.Marshal(m.Expr)
|
|
|
|
}
|
|
|
|
|
|
|
|
// UnmarshalJSON unmarshals m's expression.
|
|
|
|
func (m *MatchExpression) UnmarshalJSON(data []byte) error {
|
|
|
|
return json.Unmarshal(data, &m.Expr)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Provision sets ups m.
|
2022-06-09 06:42:24 +08:00
|
|
|
func (m *MatchExpression) Provision(ctx caddy.Context) error {
|
2022-09-17 06:55:30 +08:00
|
|
|
m.log = ctx.Logger()
|
2022-06-09 06:42:24 +08:00
|
|
|
|
2020-03-20 05:46:22 +08:00
|
|
|
// replace placeholders with a function call - this is just some
|
|
|
|
// light (and possibly naïve) syntactic sugar
|
|
|
|
m.expandedExpr = placeholderRegexp.ReplaceAllString(m.Expr, placeholderExpansion)
|
|
|
|
|
2020-04-09 00:44:36 +08:00
|
|
|
// our type adapter expands CEL's standard type support
|
|
|
|
m.ta = celTypeAdapter{}
|
|
|
|
|
2022-06-23 06:53:46 +08:00
|
|
|
// initialize the CEL libraries from the Matcher implementations which
|
|
|
|
// have been configured to support CEL.
|
|
|
|
matcherLibProducers := []CELLibraryProducer{}
|
|
|
|
for _, info := range caddy.GetModules("http.matchers") {
|
|
|
|
p, ok := info.New().(CELLibraryProducer)
|
|
|
|
if ok {
|
|
|
|
matcherLibProducers = append(matcherLibProducers, p)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
// Assemble the compilation and program options from the different library
|
|
|
|
// producers into a single cel.Library implementation.
|
|
|
|
matcherEnvOpts := []cel.EnvOption{}
|
|
|
|
matcherProgramOpts := []cel.ProgramOption{}
|
|
|
|
for _, producer := range matcherLibProducers {
|
|
|
|
l, err := producer.CELLibrary(ctx)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("error initializing CEL library for %T: %v", producer, err)
|
|
|
|
}
|
|
|
|
matcherEnvOpts = append(matcherEnvOpts, l.CompileOptions()...)
|
|
|
|
matcherProgramOpts = append(matcherProgramOpts, l.ProgramOptions()...)
|
|
|
|
}
|
|
|
|
matcherLib := cel.Lib(NewMatcherCELLibrary(matcherEnvOpts, matcherProgramOpts))
|
|
|
|
|
2020-03-20 05:46:22 +08:00
|
|
|
// create the CEL environment
|
|
|
|
env, err := cel.NewEnv(
|
2023-02-09 01:49:17 +08:00
|
|
|
cel.Function(placeholderFuncName, cel.SingletonBinaryBinding(m.caddyPlaceholderFunc), cel.Overload(
|
2022-07-29 04:50:28 +08:00
|
|
|
placeholderFuncName+"_httpRequest_string",
|
|
|
|
[]*cel.Type{httpRequestObjectType, cel.StringType},
|
|
|
|
cel.AnyType,
|
|
|
|
)),
|
|
|
|
cel.Variable("request", httpRequestObjectType),
|
2020-04-09 00:44:36 +08:00
|
|
|
cel.CustomTypeAdapter(m.ta),
|
2020-03-20 22:53:40 +08:00
|
|
|
ext.Strings(),
|
2022-06-23 06:53:46 +08:00
|
|
|
matcherLib,
|
2020-03-20 05:46:22 +08:00
|
|
|
)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("setting up CEL environment: %v", err)
|
|
|
|
}
|
|
|
|
|
2020-04-09 05:39:23 +08:00
|
|
|
// parse and type-check the expression
|
|
|
|
checked, issues := env.Compile(m.expandedExpr)
|
2022-06-23 06:53:46 +08:00
|
|
|
if issues.Err() != nil {
|
2020-04-09 05:39:23 +08:00
|
|
|
return fmt.Errorf("compiling CEL program: %s", issues.Err())
|
2020-03-20 05:46:22 +08:00
|
|
|
}
|
|
|
|
|
2020-04-09 05:39:23 +08:00
|
|
|
// request matching is a boolean operation, so we don't really know
|
|
|
|
// what to do if the expression returns a non-boolean type
|
2022-07-29 04:50:28 +08:00
|
|
|
if checked.OutputType() != cel.BoolType {
|
|
|
|
return fmt.Errorf("CEL request matcher expects return type of bool, not %s", checked.OutputType())
|
2020-03-20 05:46:22 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
// compile the "program"
|
2022-07-29 04:50:28 +08:00
|
|
|
m.prg, err = env.Program(checked, cel.EvalOptions(cel.OptOptimize))
|
2020-03-20 05:46:22 +08:00
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("compiling CEL program: %s", err)
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// Match returns true if r matches m.
|
|
|
|
func (m MatchExpression) Match(r *http.Request) bool {
|
2022-06-23 06:53:46 +08:00
|
|
|
celReq := celHTTPRequest{r}
|
|
|
|
out, _, err := m.prg.Eval(celReq)
|
2022-06-09 06:42:24 +08:00
|
|
|
if err != nil {
|
|
|
|
m.log.Error("evaluating expression", zap.Error(err))
|
2022-06-23 06:53:46 +08:00
|
|
|
SetVar(r.Context(), MatcherErrorVarKey, err)
|
2022-06-09 06:42:24 +08:00
|
|
|
return false
|
|
|
|
}
|
2020-03-20 05:46:22 +08:00
|
|
|
if outBool, ok := out.Value().(bool); ok {
|
|
|
|
return outBool
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
|
|
|
// UnmarshalCaddyfile implements caddyfile.Unmarshaler.
|
|
|
|
func (m *MatchExpression) UnmarshalCaddyfile(d *caddyfile.Dispenser) error {
|
|
|
|
for d.Next() {
|
2022-03-19 05:08:23 +08:00
|
|
|
if d.CountRemainingArgs() > 1 {
|
|
|
|
m.Expr = strings.Join(d.RemainingArgsRaw(), " ")
|
|
|
|
} else {
|
|
|
|
m.Expr = d.Val()
|
|
|
|
}
|
2020-03-20 05:46:22 +08:00
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2020-04-09 00:44:36 +08:00
|
|
|
// caddyPlaceholderFunc implements the custom CEL function that accesses the
|
|
|
|
// Replacer on a request and gets values from it.
|
|
|
|
func (m MatchExpression) caddyPlaceholderFunc(lhs, rhs ref.Val) ref.Val {
|
|
|
|
celReq, ok := lhs.(celHTTPRequest)
|
|
|
|
if !ok {
|
|
|
|
return types.NewErr(
|
2023-02-26 08:34:27 +08:00
|
|
|
"invalid request of type '%v' to %s(request, placeholderVarName)",
|
2022-06-23 06:53:46 +08:00
|
|
|
lhs.Type(),
|
2023-02-26 08:34:27 +08:00
|
|
|
placeholderFuncName,
|
2022-06-23 06:53:46 +08:00
|
|
|
)
|
2020-04-09 00:44:36 +08:00
|
|
|
}
|
|
|
|
phStr, ok := rhs.(types.String)
|
|
|
|
if !ok {
|
|
|
|
return types.NewErr(
|
2023-02-26 08:34:27 +08:00
|
|
|
"invalid placeholder variable name of type '%v' to %s(request, placeholderVarName)",
|
2022-06-23 06:53:46 +08:00
|
|
|
rhs.Type(),
|
2023-02-26 08:34:27 +08:00
|
|
|
placeholderFuncName,
|
2022-06-23 06:53:46 +08:00
|
|
|
)
|
2020-04-09 00:44:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
repl := celReq.Context().Value(caddy.ReplacerCtxKey).(*caddy.Replacer)
|
|
|
|
val, _ := repl.Get(string(phStr))
|
|
|
|
|
|
|
|
return m.ta.NativeToValue(val)
|
|
|
|
}
|
|
|
|
|
2020-03-20 05:46:22 +08:00
|
|
|
// httpRequestCELType is the type representation of a native HTTP request.
|
|
|
|
var httpRequestCELType = types.NewTypeValue("http.Request", traits.ReceiverType)
|
|
|
|
|
2022-06-23 06:53:46 +08:00
|
|
|
// celHTTPRequest wraps an http.Request with ref.Val interface methods.
|
|
|
|
//
|
|
|
|
// This type also implements the interpreter.Activation interface which
|
|
|
|
// drops allocation costs for CEL expression evaluations by roughly half.
|
2020-04-09 00:44:36 +08:00
|
|
|
type celHTTPRequest struct{ *http.Request }
|
2020-03-20 05:46:22 +08:00
|
|
|
|
2022-08-03 04:39:09 +08:00
|
|
|
func (cr celHTTPRequest) ResolveName(name string) (any, bool) {
|
2022-06-23 06:53:46 +08:00
|
|
|
if name == "request" {
|
|
|
|
return cr, true
|
|
|
|
}
|
|
|
|
return nil, false
|
|
|
|
}
|
|
|
|
|
|
|
|
func (cr celHTTPRequest) Parent() interpreter.Activation {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2022-08-03 04:39:09 +08:00
|
|
|
func (cr celHTTPRequest) ConvertToNative(typeDesc reflect.Type) (any, error) {
|
2020-03-20 05:46:22 +08:00
|
|
|
return cr.Request, nil
|
|
|
|
}
|
|
|
|
func (celHTTPRequest) ConvertToType(typeVal ref.Type) ref.Val {
|
|
|
|
panic("not implemented")
|
|
|
|
}
|
|
|
|
func (cr celHTTPRequest) Equal(other ref.Val) ref.Val {
|
|
|
|
if o, ok := other.Value().(celHTTPRequest); ok {
|
|
|
|
return types.Bool(o.Request == cr.Request)
|
|
|
|
}
|
|
|
|
return types.ValOrErr(other, "%v is not comparable type", other)
|
|
|
|
}
|
2022-08-03 04:39:09 +08:00
|
|
|
func (celHTTPRequest) Type() ref.Type { return httpRequestCELType }
|
|
|
|
func (cr celHTTPRequest) Value() any { return cr }
|
2020-03-20 05:46:22 +08:00
|
|
|
|
2020-08-01 05:06:30 +08:00
|
|
|
var pkixNameCELType = types.NewTypeValue("pkix.Name", traits.ReceiverType)
|
|
|
|
|
|
|
|
// celPkixName wraps an pkix.Name with
|
|
|
|
// methods to satisfy the ref.Val interface.
|
|
|
|
type celPkixName struct{ *pkix.Name }
|
|
|
|
|
2022-08-03 04:39:09 +08:00
|
|
|
func (pn celPkixName) ConvertToNative(typeDesc reflect.Type) (any, error) {
|
2020-08-01 05:06:30 +08:00
|
|
|
return pn.Name, nil
|
|
|
|
}
|
|
|
|
func (celPkixName) ConvertToType(typeVal ref.Type) ref.Val {
|
|
|
|
panic("not implemented")
|
|
|
|
}
|
|
|
|
func (pn celPkixName) Equal(other ref.Val) ref.Val {
|
|
|
|
if o, ok := other.Value().(string); ok {
|
|
|
|
return types.Bool(pn.Name.String() == o)
|
|
|
|
}
|
|
|
|
return types.ValOrErr(other, "%v is not comparable type", other)
|
|
|
|
}
|
2022-08-03 04:39:09 +08:00
|
|
|
func (celPkixName) Type() ref.Type { return pkixNameCELType }
|
|
|
|
func (pn celPkixName) Value() any { return pn }
|
2020-08-01 05:06:30 +08:00
|
|
|
|
2020-04-09 00:44:36 +08:00
|
|
|
// celTypeAdapter can adapt our custom types to a CEL value.
|
|
|
|
type celTypeAdapter struct{}
|
2020-03-20 05:46:22 +08:00
|
|
|
|
2022-08-03 04:39:09 +08:00
|
|
|
func (celTypeAdapter) NativeToValue(value any) ref.Val {
|
2020-04-09 00:44:36 +08:00
|
|
|
switch v := value.(type) {
|
|
|
|
case celHTTPRequest:
|
|
|
|
return v
|
2020-08-01 05:06:30 +08:00
|
|
|
case pkix.Name:
|
|
|
|
return celPkixName{&v}
|
2020-05-22 08:19:01 +08:00
|
|
|
case time.Time:
|
2021-06-04 02:18:25 +08:00
|
|
|
return types.Timestamp{Time: v}
|
2020-04-09 00:44:36 +08:00
|
|
|
case error:
|
|
|
|
types.NewErr(v.Error())
|
2020-03-20 05:46:22 +08:00
|
|
|
}
|
|
|
|
return types.DefaultTypeAdapter.NativeToValue(value)
|
|
|
|
}
|
|
|
|
|
2022-06-23 06:53:46 +08:00
|
|
|
// CELLibraryProducer provide CEL libraries that expose a Matcher
|
|
|
|
// implementation as a first class function within the CEL expression
|
|
|
|
// matcher.
|
|
|
|
type CELLibraryProducer interface {
|
|
|
|
// CELLibrary creates a cel.Library which makes it possible to use the
|
|
|
|
// target object within CEL expression matchers.
|
|
|
|
CELLibrary(caddy.Context) (cel.Library, error)
|
|
|
|
}
|
|
|
|
|
|
|
|
// CELMatcherImpl creates a new cel.Library based on the following pieces of
|
|
|
|
// data:
|
|
|
|
//
|
2022-09-17 06:55:30 +08:00
|
|
|
// - macroName: the function name to be used within CEL. This will be a macro
|
|
|
|
// and not a function proper.
|
|
|
|
// - funcName: the function overload name generated by the CEL macro used to
|
|
|
|
// represent the matcher.
|
|
|
|
// - matcherDataTypes: the argument types to the macro.
|
|
|
|
// - fac: a matcherFactory implementation which converts from CEL constant
|
|
|
|
// values to a Matcher instance.
|
2022-06-23 06:53:46 +08:00
|
|
|
//
|
|
|
|
// Note, macro names and function names must not collide with other macros or
|
|
|
|
// functions exposed within CEL expressions, or an error will be produced
|
|
|
|
// during the expression matcher plan time.
|
|
|
|
//
|
|
|
|
// The existing CELMatcherImpl support methods are configured to support a
|
|
|
|
// limited set of function signatures. For strong type validation you may need
|
|
|
|
// to provide a custom macro which does a more detailed analysis of the CEL
|
|
|
|
// literal provided to the macro as an argument.
|
2022-07-29 04:50:28 +08:00
|
|
|
func CELMatcherImpl(macroName, funcName string, matcherDataTypes []*cel.Type, fac CELMatcherFactory) (cel.Library, error) {
|
|
|
|
requestType := cel.ObjectType("http.Request")
|
2022-06-23 06:53:46 +08:00
|
|
|
var macro parser.Macro
|
|
|
|
switch len(matcherDataTypes) {
|
|
|
|
case 1:
|
|
|
|
matcherDataType := matcherDataTypes[0]
|
2022-07-29 04:50:28 +08:00
|
|
|
switch matcherDataType.String() {
|
|
|
|
case "list(string)":
|
2022-06-23 06:53:46 +08:00
|
|
|
macro = parser.NewGlobalVarArgMacro(macroName, celMatcherStringListMacroExpander(funcName))
|
2022-07-29 04:50:28 +08:00
|
|
|
case cel.StringType.String():
|
2022-06-23 06:53:46 +08:00
|
|
|
macro = parser.NewGlobalMacro(macroName, 1, celMatcherStringMacroExpander(funcName))
|
2022-07-29 04:50:28 +08:00
|
|
|
case CELTypeJSON.String():
|
2022-06-23 06:53:46 +08:00
|
|
|
macro = parser.NewGlobalMacro(macroName, 1, celMatcherJSONMacroExpander(funcName))
|
2022-07-29 04:50:28 +08:00
|
|
|
default:
|
|
|
|
return nil, fmt.Errorf("unsupported matcher data type: %s", matcherDataType)
|
2022-06-23 06:53:46 +08:00
|
|
|
}
|
|
|
|
case 2:
|
2022-07-29 04:50:28 +08:00
|
|
|
if matcherDataTypes[0] == cel.StringType && matcherDataTypes[1] == cel.StringType {
|
2022-06-23 06:53:46 +08:00
|
|
|
macro = parser.NewGlobalMacro(macroName, 2, celMatcherStringListMacroExpander(funcName))
|
2022-07-29 04:50:28 +08:00
|
|
|
matcherDataTypes = []*cel.Type{cel.ListType(cel.StringType)}
|
2022-06-23 06:53:46 +08:00
|
|
|
} else {
|
2022-07-29 04:50:28 +08:00
|
|
|
return nil, fmt.Errorf("unsupported matcher data type: %s, %s", matcherDataTypes[0], matcherDataTypes[1])
|
2022-06-23 06:53:46 +08:00
|
|
|
}
|
|
|
|
case 3:
|
2022-07-29 04:50:28 +08:00
|
|
|
if matcherDataTypes[0] == cel.StringType && matcherDataTypes[1] == cel.StringType && matcherDataTypes[2] == cel.StringType {
|
2022-06-23 06:53:46 +08:00
|
|
|
macro = parser.NewGlobalMacro(macroName, 3, celMatcherStringListMacroExpander(funcName))
|
2022-07-29 04:50:28 +08:00
|
|
|
matcherDataTypes = []*cel.Type{cel.ListType(cel.StringType)}
|
2022-06-23 06:53:46 +08:00
|
|
|
} else {
|
2022-07-29 04:50:28 +08:00
|
|
|
return nil, fmt.Errorf("unsupported matcher data type: %s, %s, %s", matcherDataTypes[0], matcherDataTypes[1], matcherDataTypes[2])
|
2022-06-23 06:53:46 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
envOptions := []cel.EnvOption{
|
|
|
|
cel.Macros(macro),
|
2022-07-29 04:50:28 +08:00
|
|
|
cel.Function(funcName,
|
|
|
|
cel.Overload(funcName, append([]*cel.Type{requestType}, matcherDataTypes...), cel.BoolType),
|
2023-02-09 01:49:17 +08:00
|
|
|
cel.SingletonBinaryBinding(CELMatcherRuntimeFunction(funcName, fac))),
|
2022-06-23 06:53:46 +08:00
|
|
|
}
|
|
|
|
programOptions := []cel.ProgramOption{
|
|
|
|
cel.CustomDecorator(CELMatcherDecorator(funcName, fac)),
|
|
|
|
}
|
|
|
|
return NewMatcherCELLibrary(envOptions, programOptions), nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// CELMatcherFactory converts a constant CEL value into a RequestMatcher.
|
|
|
|
type CELMatcherFactory func(data ref.Val) (RequestMatcher, error)
|
|
|
|
|
|
|
|
// matcherCELLibrary is a simplistic configurable cel.Library implementation.
|
|
|
|
type matcherCELLibary struct {
|
|
|
|
envOptions []cel.EnvOption
|
|
|
|
programOptions []cel.ProgramOption
|
|
|
|
}
|
|
|
|
|
|
|
|
// NewMatcherCELLibrary creates a matcherLibrary from option setes.
|
|
|
|
func NewMatcherCELLibrary(envOptions []cel.EnvOption, programOptions []cel.ProgramOption) cel.Library {
|
|
|
|
return &matcherCELLibary{
|
|
|
|
envOptions: envOptions,
|
|
|
|
programOptions: programOptions,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (lib *matcherCELLibary) CompileOptions() []cel.EnvOption {
|
|
|
|
return lib.envOptions
|
|
|
|
}
|
|
|
|
|
|
|
|
func (lib *matcherCELLibary) ProgramOptions() []cel.ProgramOption {
|
|
|
|
return lib.programOptions
|
|
|
|
}
|
|
|
|
|
|
|
|
// CELMatcherDecorator matches a call overload generated by a CEL macro
|
|
|
|
// that takes a single argument, and optimizes the implementation to precompile
|
|
|
|
// the matcher and return a function that references the precompiled and
|
|
|
|
// provisioned matcher.
|
|
|
|
func CELMatcherDecorator(funcName string, fac CELMatcherFactory) interpreter.InterpretableDecorator {
|
|
|
|
return func(i interpreter.Interpretable) (interpreter.Interpretable, error) {
|
|
|
|
call, ok := i.(interpreter.InterpretableCall)
|
|
|
|
if !ok {
|
|
|
|
return i, nil
|
|
|
|
}
|
|
|
|
if call.OverloadID() != funcName {
|
|
|
|
return i, nil
|
|
|
|
}
|
|
|
|
callArgs := call.Args()
|
|
|
|
reqAttr, ok := callArgs[0].(interpreter.InterpretableAttribute)
|
|
|
|
if !ok {
|
|
|
|
return nil, errors.New("missing 'request' argument")
|
|
|
|
}
|
|
|
|
nsAttr, ok := reqAttr.Attr().(interpreter.NamespacedAttribute)
|
|
|
|
if !ok {
|
|
|
|
return nil, errors.New("missing 'request' argument")
|
|
|
|
}
|
|
|
|
varNames := nsAttr.CandidateVariableNames()
|
|
|
|
if len(varNames) != 1 || len(varNames) == 1 && varNames[0] != "request" {
|
|
|
|
return nil, errors.New("missing 'request' argument")
|
|
|
|
}
|
|
|
|
matcherData, ok := callArgs[1].(interpreter.InterpretableConst)
|
|
|
|
if !ok {
|
|
|
|
// If the matcher arguments are not constant, then this means
|
|
|
|
// they contain a Caddy placeholder reference and the evaluation
|
|
|
|
// and matcher provisioning should be handled at dynamically.
|
|
|
|
return i, nil
|
|
|
|
}
|
|
|
|
matcher, err := fac(matcherData.Value())
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
return interpreter.NewCall(
|
|
|
|
i.ID(), funcName, funcName+"_opt",
|
|
|
|
[]interpreter.Interpretable{reqAttr},
|
|
|
|
func(args ...ref.Val) ref.Val {
|
|
|
|
// The request value, guaranteed to be of type celHTTPRequest
|
|
|
|
celReq := args[0]
|
|
|
|
// If needed this call could be changed to convert the value
|
|
|
|
// to a *http.Request using CEL's ConvertToNative method.
|
|
|
|
httpReq := celReq.Value().(celHTTPRequest)
|
|
|
|
return types.Bool(matcher.Match(httpReq.Request))
|
|
|
|
},
|
|
|
|
), nil
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// CELMatcherRuntimeFunction creates a function binding for when the input to the matcher
|
|
|
|
// is dynamically resolved rather than a set of static constant values.
|
|
|
|
func CELMatcherRuntimeFunction(funcName string, fac CELMatcherFactory) functions.BinaryOp {
|
|
|
|
return func(celReq, matcherData ref.Val) ref.Val {
|
|
|
|
matcher, err := fac(matcherData)
|
|
|
|
if err != nil {
|
|
|
|
return types.NewErr(err.Error())
|
|
|
|
}
|
|
|
|
httpReq := celReq.Value().(celHTTPRequest)
|
|
|
|
return types.Bool(matcher.Match(httpReq.Request))
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// celMatcherStringListMacroExpander validates that the macro is called
|
|
|
|
// with a variable number of string arguments (at least one).
|
|
|
|
//
|
|
|
|
// The arguments are collected into a single list argument the following
|
|
|
|
// function call returned: <funcName>(request, [args])
|
|
|
|
func celMatcherStringListMacroExpander(funcName string) parser.MacroExpander {
|
|
|
|
return func(eh parser.ExprHelper, target *exprpb.Expr, args []*exprpb.Expr) (*exprpb.Expr, *common.Error) {
|
|
|
|
matchArgs := []*exprpb.Expr{}
|
|
|
|
if len(args) == 0 {
|
|
|
|
return nil, &common.Error{
|
|
|
|
Message: "matcher requires at least one argument",
|
|
|
|
}
|
|
|
|
}
|
|
|
|
for _, arg := range args {
|
|
|
|
if isCELStringExpr(arg) {
|
|
|
|
matchArgs = append(matchArgs, arg)
|
|
|
|
} else {
|
|
|
|
return nil, &common.Error{
|
|
|
|
Location: eh.OffsetLocation(arg.GetId()),
|
|
|
|
Message: "matcher arguments must be string constants",
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return eh.GlobalCall(funcName, eh.Ident("request"), eh.NewList(matchArgs...)), nil
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// celMatcherStringMacroExpander validates that the macro is called a single
|
|
|
|
// string argument.
|
|
|
|
//
|
|
|
|
// The following function call is returned: <funcName>(request, arg)
|
|
|
|
func celMatcherStringMacroExpander(funcName string) parser.MacroExpander {
|
|
|
|
return func(eh parser.ExprHelper, target *exprpb.Expr, args []*exprpb.Expr) (*exprpb.Expr, *common.Error) {
|
|
|
|
if len(args) != 1 {
|
|
|
|
return nil, &common.Error{
|
|
|
|
Message: "matcher requires one argument",
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if isCELStringExpr(args[0]) {
|
|
|
|
return eh.GlobalCall(funcName, eh.Ident("request"), args[0]), nil
|
|
|
|
}
|
|
|
|
return nil, &common.Error{
|
|
|
|
Location: eh.OffsetLocation(args[0].GetId()),
|
|
|
|
Message: "matcher argument must be a string literal",
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// celMatcherStringMacroExpander validates that the macro is called a single
|
|
|
|
// map literal argument.
|
|
|
|
//
|
|
|
|
// The following function call is returned: <funcName>(request, arg)
|
|
|
|
func celMatcherJSONMacroExpander(funcName string) parser.MacroExpander {
|
|
|
|
return func(eh parser.ExprHelper, target *exprpb.Expr, args []*exprpb.Expr) (*exprpb.Expr, *common.Error) {
|
|
|
|
if len(args) != 1 {
|
|
|
|
return nil, &common.Error{
|
|
|
|
Message: "matcher requires a map literal argument",
|
|
|
|
}
|
|
|
|
}
|
|
|
|
arg := args[0]
|
|
|
|
switch arg.GetExprKind().(type) {
|
|
|
|
case *exprpb.Expr_StructExpr:
|
|
|
|
structExpr := arg.GetStructExpr()
|
|
|
|
if structExpr.GetMessageName() != "" {
|
|
|
|
return nil, &common.Error{
|
|
|
|
Location: eh.OffsetLocation(arg.GetId()),
|
|
|
|
Message: fmt.Sprintf(
|
|
|
|
"matcher input must be a map literal, not a %s",
|
|
|
|
structExpr.GetMessageName(),
|
|
|
|
),
|
|
|
|
}
|
|
|
|
}
|
|
|
|
for _, entry := range structExpr.GetEntries() {
|
|
|
|
isStringPlaceholder := isCELStringExpr(entry.GetMapKey())
|
|
|
|
if !isStringPlaceholder {
|
|
|
|
return nil, &common.Error{
|
|
|
|
Location: eh.OffsetLocation(entry.GetId()),
|
|
|
|
Message: "matcher map keys must be string literals",
|
|
|
|
}
|
|
|
|
}
|
|
|
|
isStringListPlaceholder := isCELStringExpr(entry.GetValue()) ||
|
|
|
|
isCELStringListLiteral(entry.GetValue())
|
|
|
|
if !isStringListPlaceholder {
|
|
|
|
return nil, &common.Error{
|
|
|
|
Location: eh.OffsetLocation(entry.GetValue().GetId()),
|
|
|
|
Message: "matcher map values must be string or list literals",
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return eh.GlobalCall(funcName, eh.Ident("request"), arg), nil
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil, &common.Error{
|
|
|
|
Location: eh.OffsetLocation(arg.GetId()),
|
|
|
|
Message: "matcher requires a map literal argument",
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// CELValueToMapStrList converts a CEL value to a map[string][]string
|
|
|
|
//
|
|
|
|
// Earlier validation stages should guarantee that the value has this type
|
2022-08-03 04:39:09 +08:00
|
|
|
// at compile time, and that the runtime value type is map[string]any.
|
2022-06-23 06:53:46 +08:00
|
|
|
// The reason for the slight difference in value type is that CEL allows for
|
|
|
|
// map literals containing heterogeneous values, in this case string and list
|
|
|
|
// of string.
|
|
|
|
func CELValueToMapStrList(data ref.Val) (map[string][]string, error) {
|
2022-08-03 04:39:09 +08:00
|
|
|
mapStrType := reflect.TypeOf(map[string]any{})
|
2022-06-23 06:53:46 +08:00
|
|
|
mapStrRaw, err := data.ConvertToNative(mapStrType)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2022-08-03 04:39:09 +08:00
|
|
|
mapStrIface := mapStrRaw.(map[string]any)
|
2022-06-23 06:53:46 +08:00
|
|
|
mapStrListStr := make(map[string][]string, len(mapStrIface))
|
|
|
|
for k, v := range mapStrIface {
|
|
|
|
switch val := v.(type) {
|
|
|
|
case string:
|
|
|
|
mapStrListStr[k] = []string{val}
|
|
|
|
case types.String:
|
|
|
|
mapStrListStr[k] = []string{string(val)}
|
|
|
|
case []string:
|
|
|
|
mapStrListStr[k] = val
|
|
|
|
case []ref.Val:
|
|
|
|
convVals := make([]string, len(val))
|
|
|
|
for i, elem := range val {
|
|
|
|
strVal, ok := elem.(types.String)
|
|
|
|
if !ok {
|
|
|
|
return nil, fmt.Errorf("unsupported value type in header match: %T", val)
|
|
|
|
}
|
|
|
|
convVals[i] = string(strVal)
|
|
|
|
}
|
|
|
|
mapStrListStr[k] = convVals
|
|
|
|
default:
|
|
|
|
return nil, fmt.Errorf("unsupported value type in header match: %T", val)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return mapStrListStr, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// isCELStringExpr indicates whether the expression is a supported string expression
|
|
|
|
func isCELStringExpr(e *exprpb.Expr) bool {
|
|
|
|
return isCELStringLiteral(e) || isCELCaddyPlaceholderCall(e) || isCELConcatCall(e)
|
|
|
|
}
|
|
|
|
|
|
|
|
// isCELStringLiteral returns whether the expression is a CEL string literal.
|
|
|
|
func isCELStringLiteral(e *exprpb.Expr) bool {
|
|
|
|
switch e.GetExprKind().(type) {
|
|
|
|
case *exprpb.Expr_ConstExpr:
|
|
|
|
constant := e.GetConstExpr()
|
|
|
|
switch constant.GetConstantKind().(type) {
|
|
|
|
case *exprpb.Constant_StringValue:
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
|
|
|
// isCELCaddyPlaceholderCall returns whether the expression is a caddy placeholder call.
|
|
|
|
func isCELCaddyPlaceholderCall(e *exprpb.Expr) bool {
|
|
|
|
switch e.GetExprKind().(type) {
|
|
|
|
case *exprpb.Expr_CallExpr:
|
|
|
|
call := e.GetCallExpr()
|
|
|
|
if call.GetFunction() == "caddyPlaceholder" {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
|
|
|
// isCELConcatCall tests whether the expression is a concat function (+) with string, placeholder, or
|
|
|
|
// other concat call arguments.
|
|
|
|
func isCELConcatCall(e *exprpb.Expr) bool {
|
|
|
|
switch e.GetExprKind().(type) {
|
|
|
|
case *exprpb.Expr_CallExpr:
|
|
|
|
call := e.GetCallExpr()
|
|
|
|
if call.GetTarget() != nil {
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
if call.GetFunction() != operators.Add {
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
for _, arg := range call.GetArgs() {
|
|
|
|
if !isCELStringExpr(arg) {
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
|
|
|
// isCELStringListLiteral returns whether the expression resolves to a list literal
|
|
|
|
// containing only string constants or a placeholder call.
|
|
|
|
func isCELStringListLiteral(e *exprpb.Expr) bool {
|
|
|
|
switch e.GetExprKind().(type) {
|
|
|
|
case *exprpb.Expr_ListExpr:
|
|
|
|
list := e.GetListExpr()
|
|
|
|
for _, elem := range list.GetElements() {
|
|
|
|
if !isCELStringExpr(elem) {
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
2020-03-20 05:46:22 +08:00
|
|
|
// Variables used for replacing Caddy placeholders in CEL
|
|
|
|
// expressions with a proper CEL function call; this is
|
|
|
|
// just for syntactic sugar.
|
|
|
|
var (
|
2022-06-23 06:53:46 +08:00
|
|
|
placeholderRegexp = regexp.MustCompile(`{([a-zA-Z][\w.-]+)}`)
|
2020-03-20 05:46:22 +08:00
|
|
|
placeholderExpansion = `caddyPlaceholder(request, "${1}")`
|
2022-06-23 06:53:46 +08:00
|
|
|
|
2022-07-29 04:50:28 +08:00
|
|
|
CELTypeJSON = cel.MapType(cel.StringType, cel.DynType)
|
2020-03-20 05:46:22 +08:00
|
|
|
)
|
|
|
|
|
2022-07-29 04:50:28 +08:00
|
|
|
var httpRequestObjectType = cel.ObjectType("http.Request")
|
2020-03-20 05:46:22 +08:00
|
|
|
|
|
|
|
// The name of the CEL function which accesses Replacer values.
|
|
|
|
const placeholderFuncName = "caddyPlaceholder"
|
|
|
|
|
|
|
|
// Interface guards
|
|
|
|
var (
|
|
|
|
_ caddy.Provisioner = (*MatchExpression)(nil)
|
|
|
|
_ RequestMatcher = (*MatchExpression)(nil)
|
|
|
|
_ caddyfile.Unmarshaler = (*MatchExpression)(nil)
|
|
|
|
_ json.Marshaler = (*MatchExpression)(nil)
|
|
|
|
_ json.Unmarshaler = (*MatchExpression)(nil)
|
|
|
|
)
|