jfjoch_broker: /start takes an optional `tokens` list (any number, all equivalent; writeOnly in the
API). While the current dataset has any, the endpoints that expose it - /statistics/data_collection,
/result/scan, /image_buffer/{start.cbor,image.cbor,image.jpeg,image.tiff}, /preview/plot{,.bin} -
answer 401 unless the request carries `Authorization: Bearer <token>`; /statistics keeps serving
the instrument view and only omits its `measurement` block. Enforcement is one pre-routing hook
over a named path set (the same set carries `bearerAuth` in jfjoch_api.yaml); tokens are compared
in constant time and never read back or logged. The tokens are replaced only by an accepted start,
and atomically with clearing the previous run's status, plots and image buffer, in this order:
clear, swap, import the new settings - so no moment serves the old run under the new tokens or the
new run's name under the old ones. Settings are validated on a copy first so a refused start
changes nothing.
jfjoch_viewer: a Token field (password echo) next to the http/https scheme in Open HTTP Connection,
JUNGFRAUJOCH_HTTP_TOKEN, and D-Bus LoadFile(..., token) / SetHttpToken; the dialog overrides the
others, nothing is persisted. A 401 clears the display, stops following and puts a line on the
status bar - no dialog, since a dataset changing hands is the normal cause.
Web frontend: key button in the top bar (token in sessionStorage, applied to the bearerAuth
operations by the generated client, and to the raw preview fetch), a tokens field in the start
form, and a "token required" hint on the plots. Python client: Configuration(access_token=...)
after regeneration.
Viewer: reference dataset accepts a structure-factor mmCIF (already read by content; the dialog
now offers it) and a model file can be chosen next to it (ProcessConfig::model_path, as
rugnux --model); the job also carries the reference's free-R flags, cell and setting, and the
copied command line states -z / --reference-column / --model. A grid scan keeps its own preferred
dataset-info plot and "Spots + background" means the spot count there. Dark theme: the navy hero
buttons, checked segments, warning texts and chart guide lines follow the theme instead of their
light-theme colours.
Docs: SECURITY.md section 3 is now the implemented scheme; a guided tour with four screenshots
in JFJOCH_VIEWER.md; broker, OpenAPI, Python client and frontend pages mention the token.
Tests: BearerTokens unit test and an HTTP round trip over the real broker HTTP layer (jfjoch_test
now compiles JFJochBrokerHttp.cpp and links httplib).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
101 lines
4.5 KiB
C++
101 lines
4.5 KiB
C++
// SPDX-FileCopyrightText: 2025 Filip Leonarski, Paul Scherrer Institute <filip.leonarski@psi.ch>
|
|
// SPDX-License-Identifier: GPL-3.0-only
|
|
|
|
#pragma once
|
|
|
|
#include "../reader/JFJochReader.h"
|
|
#include "../common/BrokerStatus.h"
|
|
#include "../common/ImageBuffer.h"
|
|
#include "../common/ROIDefinition.h"
|
|
|
|
#include <stdexcept>
|
|
|
|
// libcurl's easy handle, kept opaque here so this widely-included header does NOT pull in
|
|
// <curl/curl.h>. On Windows curl.h drags in <windows.h>, whose min/max/ERROR/LoadImage macros
|
|
// would then clobber every viewer translation unit that includes this header (breaking std::min /
|
|
// std::max in gemmi, the `ERROR` enum, the LoadImage() calls, ...). CURL is `typedef void` in
|
|
// libcurl; <curl/curl.h> is included only in JFJochHttpReader.cpp.
|
|
using CURL = void;
|
|
|
|
// The broker refused the request with 401/403: the current dataset is protected by tokens and the
|
|
// one we hold (or its absence) does not open it. Distinct from "broker unreachable" so the viewer
|
|
// can report it quietly instead of raising an error dialog.
|
|
struct HttpUnauthorized : public std::runtime_error {
|
|
using std::runtime_error::runtime_error;
|
|
};
|
|
|
|
class JFJochHttpReader : public JFJochReader {
|
|
mutable std::mutex http_mutex;
|
|
std::string addr;
|
|
// Sent as "Authorization: Bearer <token>" with every request while non-empty.
|
|
std::string bearer_token;
|
|
|
|
// Persistent libcurl handle: created lazily on the first request (i.e. as soon as an address
|
|
// is selected) and then reused for every subsequent request so the TCP/TLS connection is kept
|
|
// alive. libcurl transparently reopens the connection if it was dropped (idle timeout,
|
|
// server-side session limit, ...). curl_mutex serialises access because a single easy handle
|
|
// must never be used from two threads at once; it is a leaf lock (nothing else is taken while
|
|
// it is held), so it cannot deadlock with http_mutex.
|
|
mutable std::mutex curl_mutex;
|
|
mutable CURL *curl_handle = nullptr;
|
|
|
|
std::optional<int64_t> last_image_buffer_counter;
|
|
bool last_op_http_sync = false;
|
|
|
|
// Cache of the (constant-per-acquisition) pixel mask, keyed on arm date, so the per-refresh
|
|
// dataset rebuild reuses one shared mask instead of reconstructing it every tick.
|
|
std::shared_ptr<const PixelMask> cached_pixel_mask;
|
|
std::string cached_pixel_mask_arm_date;
|
|
|
|
// Minimal HTTP result: whether a response arrived (transport-level success), the HTTP status
|
|
// code, and the (possibly binary) response body.
|
|
struct HttpResult {
|
|
bool ok = false;
|
|
long status = 0;
|
|
std::string body;
|
|
};
|
|
// Single libcurl request helper behind every endpoint call. method is "GET" or "PUT"; for PUT
|
|
// the body is sent with the given content_type.
|
|
HttpResult Request(const std::string &method, const std::string &path,
|
|
const std::string &body = {}, const std::string &content_type = {}) const;
|
|
|
|
// Tear down the persistent connection (on disconnect, when a new address is selected, and in
|
|
// the destructor); the next Request transparently re-opens it.
|
|
void ResetConnection() const;
|
|
|
|
ImageBufferStatus GetImageBufferStatus() const;
|
|
|
|
bool LoadImage_i(std::shared_ptr<JFJochReaderDataset> &dataset,
|
|
DataMessage& message,
|
|
std::vector<uint8_t> &buffer,
|
|
int64_t image_number,
|
|
bool update_dataset) override;
|
|
std::shared_ptr<JFJochReaderDataset> UpdateDataset_i();
|
|
std::vector<float> GetPlot_i(const std::string &plot_type, float fill_value = 0.0) const;
|
|
public:
|
|
~JFJochHttpReader() override;
|
|
|
|
void ReadURL(const std::string& url);
|
|
// The dataset token; kept across Close() so a reconnect to the same broker reuses it.
|
|
void Token(const std::string &token);
|
|
uint64_t GetNumberOfImages() const override;
|
|
void Close() override;
|
|
|
|
// Refresh dataset/plots if the image buffer changed since the last poll (returns nullptr if
|
|
// unchanged). Always writes the current number of images to num_images_out. Does not load an image.
|
|
std::shared_ptr<const JFJochReaderDataset> RefreshDatasetIfChanged(int64_t &num_images_out);
|
|
|
|
void UploadUserMask(const std::vector<uint32_t>& mask);
|
|
|
|
[[nodiscard]] ROIDefinition GetROIDefinitions() const; // GET /config/roi
|
|
void UploadROIDefinitions(const ROIDefinition &rois) const; // PUT /config/roi
|
|
|
|
BrokerStatus GetBrokerStatus() const;
|
|
|
|
bool ReadRawImage(int64_t image_number, JFJochReaderRawImage &image) override;
|
|
std::vector<SpotToSave> ReadSpots(int64_t image) const override;
|
|
};
|
|
|
|
|
|
|