provisioning.go 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815
  1. // mautrix-whatsapp - A Matrix-WhatsApp puppeting bridge.
  2. // Copyright (C) 2022 Tulir Asokan
  3. //
  4. // This program is free software: you can redistribute it and/or modify
  5. // it under the terms of the GNU Affero General Public License as published by
  6. // the Free Software Foundation, either version 3 of the License, or
  7. // (at your option) any later version.
  8. //
  9. // This program is distributed in the hope that it will be useful,
  10. // but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. // GNU Affero General Public License for more details.
  13. //
  14. // You should have received a copy of the GNU Affero General Public License
  15. // along with this program. If not, see <https://www.gnu.org/licenses/>.
  16. package main
  17. import (
  18. "bufio"
  19. "context"
  20. "encoding/json"
  21. "errors"
  22. "fmt"
  23. "net"
  24. "net/http"
  25. "strconv"
  26. "strings"
  27. "time"
  28. "github.com/gorilla/mux"
  29. "github.com/gorilla/websocket"
  30. "go.mau.fi/whatsmeow/appstate"
  31. waBinary "go.mau.fi/whatsmeow/binary"
  32. "go.mau.fi/whatsmeow/types"
  33. "go.mau.fi/whatsmeow"
  34. log "maunium.net/go/maulogger/v2"
  35. "maunium.net/go/mautrix/bridge/status"
  36. "maunium.net/go/mautrix/id"
  37. )
  38. type ProvisioningAPI struct {
  39. bridge *WABridge
  40. log log.Logger
  41. }
  42. func (prov *ProvisioningAPI) Init() {
  43. prov.log = prov.bridge.Log.Sub("Provisioning")
  44. prov.log.Debugln("Enabling provisioning API at", prov.bridge.Config.Bridge.Provisioning.Prefix)
  45. r := prov.bridge.AS.Router.PathPrefix(prov.bridge.Config.Bridge.Provisioning.Prefix).Subrouter()
  46. r.Use(prov.AuthMiddleware)
  47. r.HandleFunc("/v1/ping", prov.Ping).Methods(http.MethodGet)
  48. r.HandleFunc("/v1/login", prov.Login).Methods(http.MethodGet)
  49. r.HandleFunc("/v1/logout", prov.Logout).Methods(http.MethodPost)
  50. r.HandleFunc("/v1/delete_session", prov.DeleteSession).Methods(http.MethodPost)
  51. r.HandleFunc("/v1/disconnect", prov.Disconnect).Methods(http.MethodPost)
  52. r.HandleFunc("/v1/reconnect", prov.Reconnect).Methods(http.MethodPost)
  53. r.HandleFunc("/v1/debug/appstate/{name}", prov.SyncAppState).Methods(http.MethodPost)
  54. r.HandleFunc("/v1/debug/retry", prov.SendRetryReceipt).Methods(http.MethodPost)
  55. r.HandleFunc("/v1/contacts", prov.ListContacts).Methods(http.MethodGet)
  56. r.HandleFunc("/v1/groups", prov.ListGroups).Methods(http.MethodGet, http.MethodPost)
  57. r.HandleFunc("/v1/resolve_identifier/{number}", prov.ResolveIdentifier).Methods(http.MethodGet)
  58. r.HandleFunc("/v1/bulk_resolve_identifier", prov.BulkResolveIdentifier).Methods(http.MethodPost)
  59. r.HandleFunc("/v1/pm/{number}", prov.StartPM).Methods(http.MethodPost)
  60. r.HandleFunc("/v1/open/{groupID}", prov.OpenGroup).Methods(http.MethodPost)
  61. r.HandleFunc("/v1/group/open/{groupID}", prov.OpenGroup).Methods(http.MethodPost)
  62. r.HandleFunc("/v1/group/resolve/{inviteCode}", prov.ResolveGroupInvite).Methods(http.MethodPost)
  63. r.HandleFunc("/v1/group/join/{inviteCode}", prov.JoinGroup).Methods(http.MethodPost)
  64. prov.bridge.AS.Router.HandleFunc("/_matrix/app/com.beeper.asmux/ping", prov.BridgeStatePing).Methods(http.MethodPost)
  65. prov.bridge.AS.Router.HandleFunc("/_matrix/app/com.beeper.bridge_state", prov.BridgeStatePing).Methods(http.MethodPost)
  66. // Deprecated, just use /disconnect
  67. r.HandleFunc("/v1/delete_connection", prov.Disconnect).Methods(http.MethodPost)
  68. }
  69. type responseWrap struct {
  70. http.ResponseWriter
  71. statusCode int
  72. }
  73. var _ http.Hijacker = (*responseWrap)(nil)
  74. func (rw *responseWrap) WriteHeader(statusCode int) {
  75. rw.ResponseWriter.WriteHeader(statusCode)
  76. rw.statusCode = statusCode
  77. }
  78. func (rw *responseWrap) Hijack() (net.Conn, *bufio.ReadWriter, error) {
  79. hijacker, ok := rw.ResponseWriter.(http.Hijacker)
  80. if !ok {
  81. return nil, nil, errors.New("response does not implement http.Hijacker")
  82. }
  83. return hijacker.Hijack()
  84. }
  85. func (prov *ProvisioningAPI) AuthMiddleware(h http.Handler) http.Handler {
  86. return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
  87. auth := r.Header.Get("Authorization")
  88. if len(auth) == 0 && strings.HasSuffix(r.URL.Path, "/login") {
  89. authParts := strings.Split(r.Header.Get("Sec-WebSocket-Protocol"), ",")
  90. for _, part := range authParts {
  91. part = strings.TrimSpace(part)
  92. if strings.HasPrefix(part, "net.maunium.whatsapp.auth-") {
  93. auth = part[len("net.maunium.whatsapp.auth-"):]
  94. break
  95. }
  96. }
  97. } else if strings.HasPrefix(auth, "Bearer ") {
  98. auth = auth[len("Bearer "):]
  99. }
  100. if auth != prov.bridge.Config.Bridge.Provisioning.SharedSecret {
  101. prov.log.Infof("Authentication token does not match shared secret")
  102. jsonResponse(w, http.StatusForbidden, map[string]interface{}{
  103. "error": "Authentication token does not match shared secret",
  104. "errcode": "M_FORBIDDEN",
  105. })
  106. return
  107. }
  108. userID := r.URL.Query().Get("user_id")
  109. user := prov.bridge.GetUserByMXID(id.UserID(userID))
  110. start := time.Now()
  111. wWrap := &responseWrap{w, 200}
  112. h.ServeHTTP(wWrap, r.WithContext(context.WithValue(r.Context(), "user", user)))
  113. duration := time.Now().Sub(start).Seconds()
  114. prov.log.Infofln("%s %s from %s took %.2f seconds and returned status %d", r.Method, r.URL.Path, user.MXID, duration, wWrap.statusCode)
  115. })
  116. }
  117. type Error struct {
  118. Success bool `json:"success"`
  119. Error string `json:"error"`
  120. ErrCode string `json:"errcode"`
  121. }
  122. type Response struct {
  123. Success bool `json:"success"`
  124. Status string `json:"status"`
  125. }
  126. func (prov *ProvisioningAPI) DeleteSession(w http.ResponseWriter, r *http.Request) {
  127. user := r.Context().Value("user").(*User)
  128. if user.Session == nil && user.Client == nil {
  129. jsonResponse(w, http.StatusNotFound, Error{
  130. Error: "Nothing to purge: no session information stored and no active connection.",
  131. ErrCode: "no session",
  132. })
  133. return
  134. }
  135. user.DeleteConnection()
  136. user.DeleteSession()
  137. jsonResponse(w, http.StatusOK, Response{true, "Session information purged"})
  138. user.removeFromJIDMap(status.BridgeState{StateEvent: status.StateLoggedOut})
  139. }
  140. func (prov *ProvisioningAPI) Disconnect(w http.ResponseWriter, r *http.Request) {
  141. user := r.Context().Value("user").(*User)
  142. if user.Client == nil {
  143. jsonResponse(w, http.StatusNotFound, Error{
  144. Error: "You don't have a WhatsApp connection.",
  145. ErrCode: "no connection",
  146. })
  147. return
  148. }
  149. user.DeleteConnection()
  150. jsonResponse(w, http.StatusOK, Response{true, "Disconnected from WhatsApp"})
  151. user.BridgeState.Send(status.BridgeState{StateEvent: status.StateBadCredentials, Error: WANotConnected})
  152. }
  153. func (prov *ProvisioningAPI) Reconnect(w http.ResponseWriter, r *http.Request) {
  154. user := r.Context().Value("user").(*User)
  155. if user.Client == nil {
  156. if user.Session == nil {
  157. jsonResponse(w, http.StatusForbidden, Error{
  158. Error: "No existing connection and no session. Please log in first.",
  159. ErrCode: "no session",
  160. })
  161. } else {
  162. user.Connect()
  163. jsonResponse(w, http.StatusAccepted, Response{true, "Created connection to WhatsApp."})
  164. }
  165. } else {
  166. user.DeleteConnection()
  167. user.BridgeState.Send(status.BridgeState{StateEvent: status.StateTransientDisconnect, Error: WANotConnected})
  168. user.Connect()
  169. jsonResponse(w, http.StatusAccepted, Response{true, "Restarted connection to WhatsApp"})
  170. }
  171. }
  172. type debugRetryReceiptContent struct {
  173. ID types.MessageID `json:"id"`
  174. From types.JID `json:"from"`
  175. Recipient types.JID `json:"recipient"`
  176. Participant types.JID `json:"participant"`
  177. Timestamp int64 `json:"timestamp"`
  178. Count int `json:"count"`
  179. ForceIncludeIdentity bool `json:"force_include_identity"`
  180. }
  181. func (prov *ProvisioningAPI) SendRetryReceipt(w http.ResponseWriter, r *http.Request) {
  182. var req debugRetryReceiptContent
  183. user := r.Context().Value("user").(*User)
  184. if user == nil || user.Client == nil {
  185. jsonResponse(w, http.StatusNotFound, Error{
  186. Error: "User is not connected to WhatsApp",
  187. ErrCode: "no session",
  188. })
  189. return
  190. } else if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
  191. jsonResponse(w, http.StatusBadRequest, Error{
  192. Error: "Failed to parse request JSON",
  193. ErrCode: "bad json",
  194. })
  195. } else {
  196. node := &waBinary.Node{
  197. Attrs: waBinary.Attrs{
  198. "id": string(req.ID),
  199. "from": req.From,
  200. "t": strconv.FormatInt(req.Timestamp, 10),
  201. },
  202. }
  203. if !req.Recipient.IsEmpty() {
  204. node.Attrs["recipient"] = req.Recipient
  205. }
  206. if !req.Participant.IsEmpty() {
  207. node.Attrs["participant"] = req.Participant
  208. }
  209. if req.Count > 0 {
  210. node.Content = []waBinary.Node{{
  211. Tag: "enc",
  212. Attrs: waBinary.Attrs{"count": strconv.Itoa(req.Count)},
  213. }}
  214. }
  215. user.Client.DangerousInternals().SendRetryReceipt(node, req.ForceIncludeIdentity)
  216. }
  217. }
  218. func (prov *ProvisioningAPI) SyncAppState(w http.ResponseWriter, r *http.Request) {
  219. user := r.Context().Value("user").(*User)
  220. if user == nil || user.Client == nil {
  221. jsonResponse(w, http.StatusNotFound, Error{
  222. Error: "User is not connected to WhatsApp",
  223. ErrCode: "no session",
  224. })
  225. return
  226. }
  227. vars := mux.Vars(r)
  228. nameStr := vars["name"]
  229. if len(nameStr) == 0 {
  230. jsonResponse(w, http.StatusBadRequest, Error{
  231. Error: "The `name` parameter is required",
  232. ErrCode: "missing-name-param",
  233. })
  234. return
  235. }
  236. var name appstate.WAPatchName
  237. for _, existingName := range appstate.AllPatchNames {
  238. if nameStr == string(existingName) {
  239. name = existingName
  240. }
  241. }
  242. if len(name) == 0 {
  243. jsonResponse(w, http.StatusBadRequest, Error{
  244. Error: fmt.Sprintf("'%s' is not a valid app state patch name", nameStr),
  245. ErrCode: "invalid-name-param",
  246. })
  247. return
  248. }
  249. fullStr := r.URL.Query().Get("full")
  250. fullSync := len(fullStr) > 0 && (fullStr == "1" || strings.ToLower(fullStr)[0] == 't')
  251. err := user.Client.FetchAppState(name, fullSync, false)
  252. if err != nil {
  253. jsonResponse(w, http.StatusInternalServerError, Error{false, err.Error(), "sync-fail"})
  254. } else {
  255. jsonResponse(w, http.StatusOK, Response{true, fmt.Sprintf("Synced app state %s", name)})
  256. }
  257. }
  258. func (prov *ProvisioningAPI) ListContacts(w http.ResponseWriter, r *http.Request) {
  259. if user := r.Context().Value("user").(*User); user.Session == nil {
  260. jsonResponse(w, http.StatusBadRequest, Error{
  261. Error: "User is not logged into WhatsApp",
  262. ErrCode: "no session",
  263. })
  264. } else if contacts, err := user.Session.Contacts.GetAllContacts(); err != nil {
  265. prov.log.Errorfln("Failed to fetch %s's contacts: %v", user.MXID, err)
  266. jsonResponse(w, http.StatusInternalServerError, Error{
  267. Error: "Internal server error while fetching contact list",
  268. ErrCode: "failed to get contacts",
  269. })
  270. } else {
  271. augmentedContacts := map[types.JID]interface{}{}
  272. for jid, contact := range contacts {
  273. var avatarUrl id.ContentURI
  274. if puppet := prov.bridge.GetPuppetByJID(jid); puppet != nil {
  275. avatarUrl = puppet.AvatarURL
  276. }
  277. augmentedContacts[jid] = map[string]interface{}{
  278. "Found": contact.Found,
  279. "FirstName": contact.FirstName,
  280. "FullName": contact.FullName,
  281. "PushName": contact.PushName,
  282. "BusinessName": contact.BusinessName,
  283. "AvatarURL": avatarUrl,
  284. }
  285. }
  286. jsonResponse(w, http.StatusOK, augmentedContacts)
  287. }
  288. }
  289. func (prov *ProvisioningAPI) ListGroups(w http.ResponseWriter, r *http.Request) {
  290. user := r.Context().Value("user").(*User)
  291. if user.Session == nil {
  292. jsonResponse(w, http.StatusBadRequest, Error{
  293. Error: "User is not logged into WhatsApp",
  294. ErrCode: "no session",
  295. })
  296. return
  297. }
  298. if r.Method == http.MethodPost {
  299. err := user.ResyncGroups(r.URL.Query().Get("create_portals") == "true")
  300. if err != nil {
  301. prov.log.Errorfln("Failed to resync %s's groups: %v", user.MXID, err)
  302. jsonResponse(w, http.StatusInternalServerError, Error{
  303. Error: "Internal server error while resyncing groups",
  304. ErrCode: "failed to sync groups",
  305. })
  306. return
  307. }
  308. }
  309. if groups, err := user.getCachedGroupList(); err != nil {
  310. prov.log.Errorfln("Failed to fetch %s's groups: %v", user.MXID, err)
  311. jsonResponse(w, http.StatusInternalServerError, Error{
  312. Error: "Internal server error while fetching group list",
  313. ErrCode: "failed to get groups",
  314. })
  315. } else {
  316. jsonResponse(w, http.StatusOK, groups)
  317. }
  318. }
  319. type OtherUserInfo struct {
  320. MXID id.UserID `json:"mxid"`
  321. JID types.JID `json:"jid"`
  322. Name string `json:"displayname"`
  323. Avatar id.ContentURI `json:"avatar_url"`
  324. }
  325. type PortalInfo struct {
  326. RoomID id.RoomID `json:"room_id"`
  327. OtherUser *OtherUserInfo `json:"other_user,omitempty"`
  328. GroupInfo *types.GroupInfo `json:"group_info,omitempty"`
  329. JustCreated bool `json:"just_created"`
  330. }
  331. func looksEmaily(str string) bool {
  332. for _, char := range str {
  333. // Characters that are usually in emails, but shouldn't be in phone numbers
  334. if (char >= 'a' && char <= 'z') || (char >= 'A' && char <= 'Z') || char == '@' {
  335. return true
  336. }
  337. }
  338. return false
  339. }
  340. func (prov *ProvisioningAPI) resolveIdentifier(w http.ResponseWriter, r *http.Request) (types.JID, *User) {
  341. number, _ := mux.Vars(r)["number"]
  342. if strings.HasSuffix(number, "@"+types.DefaultUserServer) {
  343. jid, _ := types.ParseJID(number)
  344. number = "+" + jid.User
  345. }
  346. if looksEmaily(number) {
  347. jsonResponse(w, http.StatusBadRequest, Error{
  348. Error: "WhatsApp only supports phone numbers as user identifiers",
  349. ErrCode: "number looks like email",
  350. })
  351. } else if user := r.Context().Value("user").(*User); !user.IsLoggedIn() {
  352. jsonResponse(w, http.StatusBadRequest, Error{
  353. Error: "User is not logged into WhatsApp",
  354. ErrCode: "no session",
  355. })
  356. } else if resp, err := user.Client.IsOnWhatsApp([]string{number}); err != nil {
  357. jsonResponse(w, http.StatusInternalServerError, Error{
  358. Error: fmt.Sprintf("Failed to check if number is on WhatsApp: %v", err),
  359. ErrCode: "error checking number",
  360. })
  361. } else if len(resp) == 0 {
  362. jsonResponse(w, http.StatusInternalServerError, Error{
  363. Error: "Didn't get a response to checking if the number is on WhatsApp",
  364. ErrCode: "error checking number",
  365. })
  366. } else if !resp[0].IsIn {
  367. jsonResponse(w, http.StatusNotFound, Error{
  368. Error: fmt.Sprintf("The server said +%s is not on WhatsApp", resp[0].JID.User),
  369. ErrCode: "not on whatsapp",
  370. })
  371. } else {
  372. return resp[0].JID, user
  373. }
  374. return types.EmptyJID, nil
  375. }
  376. func (prov *ProvisioningAPI) StartPM(w http.ResponseWriter, r *http.Request) {
  377. jid, user := prov.resolveIdentifier(w, r)
  378. if jid.IsEmpty() || user == nil {
  379. // resolveIdentifier already responded with an error
  380. return
  381. }
  382. portal, puppet, justCreated, err := user.StartPM(jid, "provisioning API PM")
  383. if err != nil {
  384. jsonResponse(w, http.StatusInternalServerError, Error{
  385. Error: fmt.Sprintf("Failed to create portal: %v", err),
  386. })
  387. }
  388. status := http.StatusOK
  389. if justCreated {
  390. status = http.StatusCreated
  391. }
  392. jsonResponse(w, status, PortalInfo{
  393. RoomID: portal.MXID,
  394. OtherUser: &OtherUserInfo{
  395. JID: puppet.JID,
  396. MXID: puppet.MXID,
  397. Name: puppet.Displayname,
  398. Avatar: puppet.AvatarURL,
  399. },
  400. JustCreated: justCreated,
  401. })
  402. }
  403. func (prov *ProvisioningAPI) ResolveIdentifier(w http.ResponseWriter, r *http.Request) {
  404. jid, user := prov.resolveIdentifier(w, r)
  405. if jid.IsEmpty() || user == nil {
  406. // resolveIdentifier already responded with an error
  407. return
  408. }
  409. portal := user.GetPortalByJID(jid)
  410. puppet := user.bridge.GetPuppetByJID(jid)
  411. jsonResponse(w, http.StatusOK, PortalInfo{
  412. RoomID: portal.MXID,
  413. OtherUser: &OtherUserInfo{
  414. JID: puppet.JID,
  415. MXID: puppet.MXID,
  416. Name: puppet.Displayname,
  417. Avatar: puppet.AvatarURL,
  418. },
  419. })
  420. }
  421. type ReqBulkResolveIdentifier struct {
  422. Numbers []string `json:"numbers"`
  423. }
  424. func (prov *ProvisioningAPI) BulkResolveIdentifier(w http.ResponseWriter, r *http.Request) {
  425. var req ReqBulkResolveIdentifier
  426. var resp []types.IsOnWhatsAppResponse
  427. if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
  428. jsonResponse(w, http.StatusBadRequest, Error{
  429. Error: "Failed to parse request JSON",
  430. ErrCode: "bad json",
  431. })
  432. } else if user := r.Context().Value("user").(*User); !user.IsLoggedIn() {
  433. jsonResponse(w, http.StatusBadRequest, Error{
  434. Error: "User is not logged into WhatsApp",
  435. ErrCode: "no session",
  436. })
  437. } else if resp, err = user.Client.IsOnWhatsApp(req.Numbers); err != nil {
  438. jsonResponse(w, http.StatusInternalServerError, Error{
  439. Error: fmt.Sprintf("Failed to check if number is on WhatsApp: %v", err),
  440. ErrCode: "error checking number",
  441. })
  442. } else {
  443. jsonResponse(w, http.StatusOK, resp)
  444. }
  445. }
  446. func (prov *ProvisioningAPI) OpenGroup(w http.ResponseWriter, r *http.Request) {
  447. groupID, _ := mux.Vars(r)["groupID"]
  448. if user := r.Context().Value("user").(*User); !user.IsLoggedIn() {
  449. jsonResponse(w, http.StatusBadRequest, Error{
  450. Error: "User is not logged into WhatsApp",
  451. ErrCode: "no session",
  452. })
  453. } else if jid, err := types.ParseJID(groupID); err != nil || jid.Server != types.GroupServer || (!strings.ContainsRune(jid.User, '-') && len(jid.User) < 15) {
  454. jsonResponse(w, http.StatusBadRequest, Error{
  455. Error: "Invalid group ID",
  456. ErrCode: "invalid group id",
  457. })
  458. } else if info, err := user.Client.GetGroupInfo(jid); err != nil {
  459. // TODO return better responses for different errors (like ErrGroupNotFound and ErrNotInGroup)
  460. jsonResponse(w, http.StatusInternalServerError, Error{
  461. Error: fmt.Sprintf("Failed to get group info: %v", err),
  462. ErrCode: "error getting group info",
  463. })
  464. } else {
  465. prov.log.Debugln("Importing", jid, "for", user.MXID)
  466. portal := user.GetPortalByJID(info.JID)
  467. status := http.StatusOK
  468. if len(portal.MXID) == 0 {
  469. err = portal.CreateMatrixRoom(user, info, true, true)
  470. if err != nil {
  471. jsonResponse(w, http.StatusInternalServerError, Error{
  472. Error: fmt.Sprintf("Failed to create portal: %v", err),
  473. })
  474. return
  475. }
  476. status = http.StatusCreated
  477. }
  478. jsonResponse(w, status, PortalInfo{
  479. RoomID: portal.MXID,
  480. GroupInfo: info,
  481. JustCreated: status == http.StatusCreated,
  482. })
  483. }
  484. }
  485. func (prov *ProvisioningAPI) resolveGroupInvite(w http.ResponseWriter, r *http.Request) (*types.GroupInfo, *User) {
  486. inviteCode, _ := mux.Vars(r)["inviteCode"]
  487. if user := r.Context().Value("user").(*User); !user.IsLoggedIn() {
  488. jsonResponse(w, http.StatusBadRequest, Error{
  489. Error: "User is not logged into WhatsApp",
  490. ErrCode: "no session",
  491. })
  492. } else if info, err := user.Client.GetGroupInfoFromLink(inviteCode); err != nil {
  493. if errors.Is(err, whatsmeow.ErrInviteLinkRevoked) {
  494. jsonResponse(w, http.StatusBadRequest, Error{
  495. Error: whatsmeow.ErrInviteLinkRevoked.Error(),
  496. ErrCode: "invite link revoked",
  497. })
  498. } else if errors.Is(err, whatsmeow.ErrInviteLinkInvalid) {
  499. jsonResponse(w, http.StatusBadRequest, Error{
  500. Error: whatsmeow.ErrInviteLinkInvalid.Error(),
  501. ErrCode: "invalid invite link",
  502. })
  503. } else {
  504. jsonResponse(w, http.StatusInternalServerError, Error{
  505. Error: fmt.Sprintf("Failed to fetch group info with link: %v", err),
  506. ErrCode: "error getting group info",
  507. })
  508. }
  509. } else {
  510. return info, user
  511. }
  512. return nil, nil
  513. }
  514. func (prov *ProvisioningAPI) ResolveGroupInvite(w http.ResponseWriter, r *http.Request) {
  515. info, user := prov.resolveGroupInvite(w, r)
  516. if info == nil {
  517. return
  518. }
  519. jsonResponse(w, http.StatusOK, PortalInfo{
  520. RoomID: user.GetPortalByJID(info.JID).MXID,
  521. GroupInfo: info,
  522. })
  523. }
  524. func (prov *ProvisioningAPI) JoinGroup(w http.ResponseWriter, r *http.Request) {
  525. info, user := prov.resolveGroupInvite(w, r)
  526. if info == nil {
  527. return
  528. }
  529. user.groupJoinLock.Lock()
  530. user.skipGroupCreateDelay = info.JID
  531. defer func() {
  532. user.skipGroupCreateDelay = types.EmptyJID
  533. user.groupJoinLock.Unlock()
  534. }()
  535. inviteCode, _ := mux.Vars(r)["inviteCode"]
  536. if jid, err := user.Client.JoinGroupWithLink(inviteCode); err != nil {
  537. jsonResponse(w, http.StatusInternalServerError, Error{
  538. Error: fmt.Sprintf("Failed to join group: %v", err),
  539. ErrCode: "error joining group",
  540. })
  541. } else {
  542. prov.log.Debugln(user.MXID, "successfully joined group", jid)
  543. portal := user.GetPortalByJID(jid)
  544. status := http.StatusOK
  545. if len(portal.MXID) == 0 {
  546. time.Sleep(500 * time.Millisecond) // Wait for incoming group info to create the portal automatically
  547. err = portal.CreateMatrixRoom(user, info, true, true)
  548. if err != nil {
  549. jsonResponse(w, http.StatusInternalServerError, Error{
  550. Error: fmt.Sprintf("Failed to create portal: %v", err),
  551. })
  552. return
  553. }
  554. status = http.StatusCreated
  555. }
  556. jsonResponse(w, status, PortalInfo{
  557. RoomID: portal.MXID,
  558. GroupInfo: info,
  559. JustCreated: status == http.StatusCreated,
  560. })
  561. }
  562. }
  563. func (prov *ProvisioningAPI) Ping(w http.ResponseWriter, r *http.Request) {
  564. user := r.Context().Value("user").(*User)
  565. wa := map[string]interface{}{
  566. "has_session": user.Session != nil,
  567. "management_room": user.ManagementRoom,
  568. "conn": nil,
  569. }
  570. if !user.JID.IsEmpty() {
  571. wa["jid"] = user.JID.String()
  572. wa["phone"] = "+" + user.JID.User
  573. wa["device"] = user.JID.Device
  574. if user.Session != nil {
  575. wa["platform"] = user.Session.Platform
  576. }
  577. }
  578. if user.Client != nil {
  579. wa["conn"] = map[string]interface{}{
  580. "is_connected": user.Client.IsConnected(),
  581. "is_logged_in": user.Client.IsLoggedIn(),
  582. }
  583. }
  584. resp := map[string]interface{}{
  585. "mxid": user.MXID,
  586. "admin": user.Admin,
  587. "whitelisted": user.Whitelisted,
  588. "relay_whitelisted": user.RelayWhitelisted,
  589. "whatsapp": wa,
  590. }
  591. jsonResponse(w, http.StatusOK, resp)
  592. }
  593. func jsonResponse(w http.ResponseWriter, status int, response interface{}) {
  594. w.Header().Add("Content-Type", "application/json")
  595. w.WriteHeader(status)
  596. _ = json.NewEncoder(w).Encode(response)
  597. }
  598. func (prov *ProvisioningAPI) Logout(w http.ResponseWriter, r *http.Request) {
  599. user := r.Context().Value("user").(*User)
  600. if user.Session == nil {
  601. jsonResponse(w, http.StatusOK, Error{
  602. Error: "You're not logged in",
  603. ErrCode: "not logged in",
  604. })
  605. return
  606. }
  607. force := strings.ToLower(r.URL.Query().Get("force")) != "false"
  608. if user.Client == nil {
  609. if !force {
  610. jsonResponse(w, http.StatusNotFound, Error{
  611. Error: "You're not connected",
  612. ErrCode: "not connected",
  613. })
  614. }
  615. } else {
  616. err := user.Client.Logout()
  617. if err != nil {
  618. user.log.Warnln("Error while logging out:", err)
  619. if !force {
  620. jsonResponse(w, http.StatusInternalServerError, Error{
  621. Error: fmt.Sprintf("Unknown error while logging out: %v", err),
  622. ErrCode: err.Error(),
  623. })
  624. return
  625. }
  626. } else {
  627. user.Session = nil
  628. }
  629. user.DeleteConnection()
  630. }
  631. user.bridge.Metrics.TrackConnectionState(user.JID, false)
  632. user.removeFromJIDMap(status.BridgeState{StateEvent: status.StateLoggedOut})
  633. user.DeleteSession()
  634. jsonResponse(w, http.StatusOK, Response{true, "Logged out successfully."})
  635. }
  636. var upgrader = websocket.Upgrader{
  637. CheckOrigin: func(r *http.Request) bool {
  638. return true
  639. },
  640. Subprotocols: []string{"net.maunium.whatsapp.login"},
  641. }
  642. func (prov *ProvisioningAPI) Login(w http.ResponseWriter, r *http.Request) {
  643. userID := r.URL.Query().Get("user_id")
  644. user := prov.bridge.GetUserByMXID(id.UserID(userID))
  645. c, err := upgrader.Upgrade(w, r, nil)
  646. if err != nil {
  647. prov.log.Errorln("Failed to upgrade connection to websocket:", err)
  648. return
  649. }
  650. defer func() {
  651. err := c.Close()
  652. if err != nil {
  653. user.log.Debugln("Error closing websocket:", err)
  654. }
  655. }()
  656. go func() {
  657. // Read everything so SetCloseHandler() works
  658. for {
  659. _, _, err = c.ReadMessage()
  660. if err != nil {
  661. break
  662. }
  663. }
  664. }()
  665. ctx, cancel := context.WithCancel(context.Background())
  666. c.SetCloseHandler(func(code int, text string) error {
  667. user.log.Debugfln("Login websocket closed (%d), cancelling login", code)
  668. cancel()
  669. return nil
  670. })
  671. if userTimezone := r.URL.Query().Get("tz"); userTimezone != "" {
  672. user.log.Debug("Setting timezone to %s", userTimezone)
  673. user.Timezone = userTimezone
  674. user.Update()
  675. } else {
  676. user.log.Debug("No timezone provided in request")
  677. }
  678. qrChan, err := user.Login(ctx)
  679. if err != nil {
  680. user.log.Errorln("Failed to log in from provisioning API:", err)
  681. if errors.Is(err, ErrAlreadyLoggedIn) {
  682. go user.Connect()
  683. _ = c.WriteJSON(Error{
  684. Error: "You're already logged into WhatsApp",
  685. ErrCode: "already logged in",
  686. })
  687. } else {
  688. _ = c.WriteJSON(Error{
  689. Error: "Failed to connect to WhatsApp",
  690. ErrCode: "connection error",
  691. })
  692. }
  693. }
  694. user.log.Debugln("Started login via provisioning API")
  695. Segment.Track(user.MXID, "$login_start")
  696. for {
  697. select {
  698. case evt := <-qrChan:
  699. switch evt.Event {
  700. case whatsmeow.QRChannelSuccess.Event:
  701. jid := user.Client.Store.ID
  702. user.log.Debugln("Successful login as", jid, "via provisioning API")
  703. Segment.Track(user.MXID, "$login_success")
  704. _ = c.WriteJSON(map[string]interface{}{
  705. "success": true,
  706. "jid": jid,
  707. "phone": fmt.Sprintf("+%s", jid.User),
  708. "platform": user.Client.Store.Platform,
  709. })
  710. case whatsmeow.QRChannelTimeout.Event:
  711. user.log.Debugln("Login via provisioning API timed out")
  712. errCode := "login timed out"
  713. Segment.Track(user.MXID, "$login_failure", map[string]interface{}{"error": errCode})
  714. _ = c.WriteJSON(Error{
  715. Error: "QR code scan timed out. Please try again.",
  716. ErrCode: errCode,
  717. })
  718. case whatsmeow.QRChannelErrUnexpectedEvent.Event:
  719. user.log.Debugln("Login via provisioning API failed due to unexpected event")
  720. errCode := "unexpected event"
  721. Segment.Track(user.MXID, "$login_failure", map[string]interface{}{"error": errCode})
  722. _ = c.WriteJSON(Error{
  723. Error: "Got unexpected event while waiting for QRs, perhaps you're already logged in?",
  724. ErrCode: errCode,
  725. })
  726. case whatsmeow.QRChannelClientOutdated.Event:
  727. user.log.Debugln("Login via provisioning API failed due to outdated client")
  728. errCode := "bridge outdated"
  729. Segment.Track(user.MXID, "$login_failure", map[string]interface{}{"error": errCode})
  730. _ = c.WriteJSON(Error{
  731. Error: "Got client outdated error while waiting for QRs. The bridge must be updated to continue.",
  732. ErrCode: errCode,
  733. })
  734. case whatsmeow.QRChannelScannedWithoutMultidevice.Event:
  735. errCode := "multidevice not enabled"
  736. Segment.Track(user.MXID, "$login_failure", map[string]interface{}{"error": errCode})
  737. _ = c.WriteJSON(Error{
  738. Error: "Please enable the WhatsApp multidevice beta and scan the QR code again.",
  739. ErrCode: errCode,
  740. })
  741. continue
  742. case "error":
  743. errCode := "fatal error"
  744. Segment.Track(user.MXID, "$login_failure", map[string]interface{}{"error": errCode})
  745. _ = c.WriteJSON(Error{
  746. Error: "Fatal error while logging in",
  747. ErrCode: errCode,
  748. })
  749. case "code":
  750. Segment.Track(user.MXID, "$qrcode_retrieved")
  751. _ = c.WriteJSON(map[string]interface{}{
  752. "code": evt.Code,
  753. "timeout": int(evt.Timeout.Seconds()),
  754. })
  755. continue
  756. }
  757. return
  758. case <-ctx.Done():
  759. return
  760. }
  761. }
  762. }