-
Notifications
You must be signed in to change notification settings - Fork 9
Expand file tree
/
Copy pathgit.js
More file actions
228 lines (196 loc) · 6.69 KB
/
Copy pathgit.js
File metadata and controls
228 lines (196 loc) · 6.69 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
import { spawn, execSync } from 'child_process';
import { existsSync, statSync, mkdirSync, writeFileSync } from 'fs';
import { join, resolve, dirname } from 'path';
/**
* Check if a URL path is a Git protocol request
* @param {string} urlPath - The URL path
* @returns {boolean}
*/
export function isGitRequest(urlPath) {
return urlPath.includes('/info/refs') ||
urlPath.includes('/git-upload-pack') ||
urlPath.includes('/git-receive-pack');
}
/**
* Determine if this is a write operation (push)
* @param {string} urlPath - The URL path
* @returns {boolean}
*/
export function isGitWriteOperation(urlPath) {
return urlPath.includes('/git-receive-pack') || urlPath.includes('service=git-receive-pack');
}
/**
* Extract the repository path from the URL
* @param {string} urlPath - The URL path
* @returns {string|null} The repository relative path or null
*/
function extractRepoPath(urlPath) {
// Remove git service suffixes to get the repo path
const cleanPath = urlPath
.replace(/\/info\/refs.*$/, '')
.replace(/\/git-upload-pack$/, '')
.replace(/\/git-receive-pack$/, '');
// Remove leading slash
return cleanPath.replace(/^\//, '') || null;
}
/**
* Find the git directory for a path
* @param {string} repoPath - Absolute path to check
* @returns {{gitDir: string, isRegular: boolean}|null}
*/
function findGitDir(repoPath) {
if (!existsSync(repoPath) || !statSync(repoPath).isDirectory()) {
return null;
}
// Check for regular repo with .git subdirectory
const dotGitPath = join(repoPath, '.git');
if (existsSync(dotGitPath) && statSync(dotGitPath).isDirectory()) {
return { gitDir: dotGitPath, isRegular: true };
}
// Check for bare repository
const objectsPath = join(repoPath, 'objects');
const refsPath = join(repoPath, 'refs');
if (existsSync(objectsPath) && existsSync(refsPath)) {
return { gitDir: repoPath, isRegular: false };
}
return null;
}
/**
* Handle Git HTTP requests using git http-backend
* @param {FastifyRequest} request
* @param {FastifyReply} reply
*/
export async function handleGit(request, reply) {
const urlPath = decodeURIComponent(request.url.split('?')[0]);
const queryString = request.url.split('?')[1] || '';
// Extract repository path
const repoRelative = extractRepoPath(urlPath);
if (!repoRelative) {
return reply.code(400).send({ error: 'Invalid git request' });
}
// Handle subdomain mode
let dataRoot = process.env.DATA_ROOT || './data';
if (request.podName) {
dataRoot = join(dataRoot, request.podName);
}
const repoAbs = resolve(dataRoot, repoRelative);
// Find git directory
const gitInfo = findGitDir(repoAbs);
if (!gitInfo) {
return reply.code(404).send({ error: 'Not a git repository' });
}
// Auto-configure repos to accept pushes (check full URL for query string)
if (isGitWriteOperation(request.url)) {
try {
// Enable receive-pack for HTTP push
execSync('git config http.receivepack true', {
cwd: repoAbs,
env: { ...process.env, GIT_DIR: gitInfo.gitDir }
});
// For non-bare repos, auto-update working directory after push
if (gitInfo.isRegular) {
execSync('git config receive.denyCurrentBranch updateInstead', {
cwd: repoAbs,
env: { ...process.env, GIT_DIR: gitInfo.gitDir }
});
}
} catch (e) {
// Ignore config errors - repo may still work
}
}
// Build CGI environment
const env = {
...process.env,
GIT_PROJECT_ROOT: dataRoot,
GIT_HTTP_EXPORT_ALL: '', // Allow read access
GIT_HTTP_RECEIVE_PACK: 'true', // Enable push
GIT_CONFIG_PARAMETERS: "'uploadpack.allowTipSHA1InWant=true'",
PATH_INFO: urlPath,
REQUEST_METHOD: request.method,
CONTENT_TYPE: request.headers['content-type'] || '',
QUERY_STRING: queryString,
REMOTE_USER: request.webId || '', // Pass authenticated user
CONTENT_LENGTH: request.headers['content-length'] || '0',
};
// For regular repositories, set GIT_DIR
if (gitInfo.isRegular) {
env.GIT_DIR = gitInfo.gitDir;
}
// Spawn git http-backend
return new Promise((resolve, reject) => {
const child = spawn('git', ['http-backend'], { env });
let buffer = Buffer.alloc(0);
let headersSent = false;
child.stdout.on('data', (data) => {
buffer = Buffer.concat([buffer, data]);
if (!headersSent) {
// Look for end of CGI headers (try both \r\n\r\n and \n\n)
let headerEnd = buffer.indexOf('\r\n\r\n');
let headerSep = '\r\n';
let headerEndLen = 4;
if (headerEnd === -1) {
headerEnd = buffer.indexOf('\n\n');
headerSep = '\n';
headerEndLen = 2;
}
if (headerEnd !== -1) {
const headerSection = buffer.subarray(0, headerEnd).toString();
const bodySection = buffer.subarray(headerEnd + headerEndLen);
// Parse CGI headers and set on raw response
const lines = headerSection.split(headerSep);
let statusCode = 200;
for (const line of lines) {
const colonIndex = line.indexOf(':');
if (colonIndex > 0) {
const key = line.substring(0, colonIndex).trim();
const value = line.substring(colonIndex + 1).trim();
// Handle Status header specially
if (key.toLowerCase() === 'status') {
statusCode = parseInt(value.split(' ')[0], 10);
} else {
reply.raw.setHeader(key, value);
}
}
}
reply.raw.writeHead(statusCode);
headersSent = true;
reply.raw.write(bodySection);
buffer = Buffer.alloc(0);
}
} else {
reply.raw.write(buffer);
buffer = Buffer.alloc(0);
}
});
child.stdout.on('end', () => {
reply.raw.end();
resolve();
});
// Send request body to git
// For POST requests, Fastify has already parsed the body into request.body
if (request.body && request.body.length > 0) {
child.stdin.write(request.body);
child.stdin.end();
} else {
// For GET requests or empty bodies, just close stdin
child.stdin.end();
}
// Log errors
child.stderr.on('data', (data) => {
console.error('git http-backend stderr:', data.toString());
});
child.on('error', (err) => {
console.error('Failed to spawn git http-backend:', err);
if (!headersSent) {
reply.code(500).send({ error: 'Git backend error' });
}
resolve();
});
child.on('close', (code) => {
if (code !== 0 && !headersSent) {
reply.code(500).send({ error: 'Git operation failed' });
}
resolve();
});
});
}