James Moger
2011-05-26 2a7306a1d92522569a8bb6e5a7c0bcdd5cf4cfaa
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
/*
 * Copyright 2011 gitblit.com.
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */
package com.gitblit;
 
import java.util.Date;
 
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletResponse;
 
import org.eclipse.jgit.lib.Repository;
import org.eclipse.jgit.revwalk.RevCommit;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
 
import com.gitblit.Constants.AccessRestrictionType;
import com.gitblit.utils.JGitUtils;
import com.gitblit.utils.StringUtils;
import com.gitblit.wicket.models.RepositoryModel;
 
public class DownloadZipServlet extends HttpServlet {
 
    private static final long serialVersionUID = 1L;
 
    private transient Logger logger = LoggerFactory.getLogger(DownloadZipServlet.class);
 
    public DownloadZipServlet() {
        super();
    }
 
    public static String asLink(String baseURL, String repository, String objectId, String path) {
        return baseURL + (baseURL.endsWith("/") ? "" : "/") + "zip?r=" + repository
                + (path == null ? "" : ("&p=" + path))
                + (objectId == null ? "" : ("&h=" + objectId));
    }
 
    private void processRequest(javax.servlet.http.HttpServletRequest request,
            javax.servlet.http.HttpServletResponse response) throws javax.servlet.ServletException,
            java.io.IOException {
        if (!GitBlit.getBoolean(Keys.web.allowZipDownloads, true)) {
            logger.warn("Zip downloads are disabled");
            response.sendError(HttpServletResponse.SC_FORBIDDEN);
            return;
 
        }
        String repository = request.getParameter("r");
        String basePath = request.getParameter("p");
        String objectId = request.getParameter("h");
 
        try {
            String name = repository;
            if (name.indexOf('/') > -1) {
                name = name.substring(name.lastIndexOf('/') + 1);
            }
 
            // check roles first
            boolean authorized = request.isUserInRole(Constants.ADMIN_ROLE);
            authorized |= request.isUserInRole(repository);
 
            if (!authorized) {
                RepositoryModel model = GitBlit.self().getRepositoryModel(repository);
                if (model.accessRestriction.atLeast(AccessRestrictionType.VIEW)) {
                    logger.warn("Unauthorized access via zip servlet for " + model.name);
                    response.sendError(HttpServletResponse.SC_FORBIDDEN);
                    return;
                }
            }
            if (!StringUtils.isEmpty(basePath)) {
                name += "-" + basePath.replace('/', '_');
            }
            if (!StringUtils.isEmpty(objectId)) {
                name += "-" + objectId;
            }
 
            Repository r = GitBlit.self().getRepository(repository);
            RevCommit commit = JGitUtils.getCommit(r, objectId);
            Date date = JGitUtils.getCommitDate(commit);
            String contentType = "application/octet-stream";
            response.setContentType(contentType + "; charset=" + response.getCharacterEncoding());
            // response.setContentLength(attachment.getFileSize());
            response.setHeader("Content-Disposition", "attachment; filename=\"" + name + ".zip"
                    + "\"");
            response.setDateHeader("Last-Modified", date.getTime());
            response.setHeader("Cache-Control", "no-cache");
            response.setHeader("Pragma", "no-cache");
            response.setDateHeader("Expires", 0);
 
            try {
                JGitUtils.zip(r, basePath, objectId, response.getOutputStream());
                response.flushBuffer();
            } catch (Throwable t) {
                logger.error("Failed to write attachment to client", t);
            }
        } catch (Throwable t) {
            logger.error("Failed to write attachment to client", t);
        }
    }
 
    @Override
    protected void doPost(javax.servlet.http.HttpServletRequest request,
            javax.servlet.http.HttpServletResponse response) throws javax.servlet.ServletException,
            java.io.IOException {
        processRequest(request, response);
    }
 
    @Override
    protected void doGet(javax.servlet.http.HttpServletRequest request,
            javax.servlet.http.HttpServletResponse response) throws javax.servlet.ServletException,
            java.io.IOException {
        processRequest(request, response);
    }
}