##// END OF EJS Templates
Backport PR #6003: Set kernel_id before checking websocket...
MinRK -
Show More
@@ -1,150 +1,150 b''
1 """Tornado handlers for WebSocket <-> ZMQ sockets.
1 """Tornado handlers for WebSocket <-> ZMQ sockets.
2
2
3 Authors:
3 Authors:
4
4
5 * Brian Granger
5 * Brian Granger
6 """
6 """
7
7
8 #-----------------------------------------------------------------------------
8 #-----------------------------------------------------------------------------
9 # Copyright (C) 2008-2011 The IPython Development Team
9 # Copyright (C) 2008-2011 The IPython Development Team
10 #
10 #
11 # Distributed under the terms of the BSD License. The full license is in
11 # Distributed under the terms of the BSD License. The full license is in
12 # the file COPYING, distributed as part of this software.
12 # the file COPYING, distributed as part of this software.
13 #-----------------------------------------------------------------------------
13 #-----------------------------------------------------------------------------
14
14
15 #-----------------------------------------------------------------------------
15 #-----------------------------------------------------------------------------
16 # Imports
16 # Imports
17 #-----------------------------------------------------------------------------
17 #-----------------------------------------------------------------------------
18
18
19 try:
19 try:
20 from urllib.parse import urlparse # Py 3
20 from urllib.parse import urlparse # Py 3
21 except ImportError:
21 except ImportError:
22 from urlparse import urlparse # Py 2
22 from urlparse import urlparse # Py 2
23
23
24 try:
24 try:
25 from http.cookies import SimpleCookie # Py 3
25 from http.cookies import SimpleCookie # Py 3
26 except ImportError:
26 except ImportError:
27 from Cookie import SimpleCookie # Py 2
27 from Cookie import SimpleCookie # Py 2
28 import logging
28 import logging
29 from tornado import web
29 from tornado import web
30 from tornado import websocket
30 from tornado import websocket
31
31
32 from zmq.utils import jsonapi
32 from zmq.utils import jsonapi
33
33
34 from IPython.kernel.zmq.session import Session
34 from IPython.kernel.zmq.session import Session
35 from IPython.utils.jsonutil import date_default
35 from IPython.utils.jsonutil import date_default
36 from IPython.utils.py3compat import PY3, cast_unicode
36 from IPython.utils.py3compat import PY3, cast_unicode
37
37
38 from .handlers import IPythonHandler
38 from .handlers import IPythonHandler
39
39
40 #-----------------------------------------------------------------------------
40 #-----------------------------------------------------------------------------
41 # ZMQ handlers
41 # ZMQ handlers
42 #-----------------------------------------------------------------------------
42 #-----------------------------------------------------------------------------
43
43
44 class ZMQStreamHandler(websocket.WebSocketHandler):
44 class ZMQStreamHandler(websocket.WebSocketHandler):
45
45
46 def same_origin(self):
46 def same_origin(self):
47 """Check to see that origin and host match in the headers."""
47 """Check to see that origin and host match in the headers."""
48
48
49 # The difference between version 8 and 13 is that in 8 the
49 # The difference between version 8 and 13 is that in 8 the
50 # client sends a "Sec-Websocket-Origin" header and in 13 it's
50 # client sends a "Sec-Websocket-Origin" header and in 13 it's
51 # simply "Origin".
51 # simply "Origin".
52 if self.request.headers.get("Sec-WebSocket-Version") in ("7", "8"):
52 if self.request.headers.get("Sec-WebSocket-Version") in ("7", "8"):
53 origin_header = self.request.headers.get("Sec-Websocket-Origin")
53 origin_header = self.request.headers.get("Sec-Websocket-Origin")
54 else:
54 else:
55 origin_header = self.request.headers.get("Origin")
55 origin_header = self.request.headers.get("Origin")
56
56
57 host = self.request.headers.get("Host")
57 host = self.request.headers.get("Host")
58
58
59 # If no header is provided, assume we can't verify origin
59 # If no header is provided, assume we can't verify origin
60 if(origin_header is None or host is None):
60 if(origin_header is None or host is None):
61 return False
61 return False
62
62
63 parsed_origin = urlparse(origin_header)
63 parsed_origin = urlparse(origin_header)
64 origin = parsed_origin.netloc
64 origin = parsed_origin.netloc
65
65
66 # Check to see that origin matches host directly, including ports
66 # Check to see that origin matches host directly, including ports
67 return origin == host
67 return origin == host
68
68
69 def clear_cookie(self, *args, **kwargs):
69 def clear_cookie(self, *args, **kwargs):
70 """meaningless for websockets"""
70 """meaningless for websockets"""
71 pass
71 pass
72
72
73 def _reserialize_reply(self, msg_list):
73 def _reserialize_reply(self, msg_list):
74 """Reserialize a reply message using JSON.
74 """Reserialize a reply message using JSON.
75
75
76 This takes the msg list from the ZMQ socket, unserializes it using
76 This takes the msg list from the ZMQ socket, unserializes it using
77 self.session and then serializes the result using JSON. This method
77 self.session and then serializes the result using JSON. This method
78 should be used by self._on_zmq_reply to build messages that can
78 should be used by self._on_zmq_reply to build messages that can
79 be sent back to the browser.
79 be sent back to the browser.
80 """
80 """
81 idents, msg_list = self.session.feed_identities(msg_list)
81 idents, msg_list = self.session.feed_identities(msg_list)
82 msg = self.session.unserialize(msg_list)
82 msg = self.session.unserialize(msg_list)
83 try:
83 try:
84 msg['header'].pop('date')
84 msg['header'].pop('date')
85 except KeyError:
85 except KeyError:
86 pass
86 pass
87 try:
87 try:
88 msg['parent_header'].pop('date')
88 msg['parent_header'].pop('date')
89 except KeyError:
89 except KeyError:
90 pass
90 pass
91 msg.pop('buffers')
91 msg.pop('buffers')
92 return jsonapi.dumps(msg, default=date_default)
92 return jsonapi.dumps(msg, default=date_default)
93
93
94 def _on_zmq_reply(self, msg_list):
94 def _on_zmq_reply(self, msg_list):
95 # Sometimes this gets triggered when the on_close method is scheduled in the
95 # Sometimes this gets triggered when the on_close method is scheduled in the
96 # eventloop but hasn't been called.
96 # eventloop but hasn't been called.
97 if self.stream.closed(): return
97 if self.stream.closed(): return
98 try:
98 try:
99 msg = self._reserialize_reply(msg_list)
99 msg = self._reserialize_reply(msg_list)
100 except Exception:
100 except Exception:
101 self.log.critical("Malformed message: %r" % msg_list, exc_info=True)
101 self.log.critical("Malformed message: %r" % msg_list, exc_info=True)
102 else:
102 else:
103 self.write_message(msg)
103 self.write_message(msg)
104
104
105 def allow_draft76(self):
105 def allow_draft76(self):
106 """Allow draft 76, until browsers such as Safari update to RFC 6455.
106 """Allow draft 76, until browsers such as Safari update to RFC 6455.
107
107
108 This has been disabled by default in tornado in release 2.2.0, and
108 This has been disabled by default in tornado in release 2.2.0, and
109 support will be removed in later versions.
109 support will be removed in later versions.
110 """
110 """
111 return True
111 return True
112
112
113
113
114 class AuthenticatedZMQStreamHandler(ZMQStreamHandler, IPythonHandler):
114 class AuthenticatedZMQStreamHandler(ZMQStreamHandler, IPythonHandler):
115
115
116 def open(self, kernel_id):
116 def open(self, kernel_id):
117 self.kernel_id = cast_unicode(kernel_id, 'ascii')
117 # Check to see that origin matches host directly, including ports
118 # Check to see that origin matches host directly, including ports
118 if not self.same_origin():
119 if not self.same_origin():
119 self.log.warn("Cross Origin WebSocket Attempt.")
120 self.log.warn("Cross Origin WebSocket Attempt.")
120 raise web.HTTPError(404)
121 raise web.HTTPError(404)
121
122
122 self.kernel_id = cast_unicode(kernel_id, 'ascii')
123 self.session = Session(config=self.config)
123 self.session = Session(config=self.config)
124 self.save_on_message = self.on_message
124 self.save_on_message = self.on_message
125 self.on_message = self.on_first_message
125 self.on_message = self.on_first_message
126
126
127 def _inject_cookie_message(self, msg):
127 def _inject_cookie_message(self, msg):
128 """Inject the first message, which is the document cookie,
128 """Inject the first message, which is the document cookie,
129 for authentication."""
129 for authentication."""
130 if not PY3 and isinstance(msg, unicode):
130 if not PY3 and isinstance(msg, unicode):
131 # Cookie constructor doesn't accept unicode strings
131 # Cookie constructor doesn't accept unicode strings
132 # under Python 2.x for some reason
132 # under Python 2.x for some reason
133 msg = msg.encode('utf8', 'replace')
133 msg = msg.encode('utf8', 'replace')
134 try:
134 try:
135 identity, msg = msg.split(':', 1)
135 identity, msg = msg.split(':', 1)
136 self.session.session = cast_unicode(identity, 'ascii')
136 self.session.session = cast_unicode(identity, 'ascii')
137 except Exception:
137 except Exception:
138 logging.error("First ws message didn't have the form 'identity:[cookie]' - %r", msg)
138 logging.error("First ws message didn't have the form 'identity:[cookie]' - %r", msg)
139
139
140 try:
140 try:
141 self.request._cookies = SimpleCookie(msg)
141 self.request._cookies = SimpleCookie(msg)
142 except:
142 except:
143 self.log.warn("couldn't parse cookie string: %s",msg, exc_info=True)
143 self.log.warn("couldn't parse cookie string: %s",msg, exc_info=True)
144
144
145 def on_first_message(self, msg):
145 def on_first_message(self, msg):
146 self._inject_cookie_message(msg)
146 self._inject_cookie_message(msg)
147 if self.get_current_user() is None:
147 if self.get_current_user() is None:
148 self.log.warn("Couldn't authenticate WebSocket connection")
148 self.log.warn("Couldn't authenticate WebSocket connection")
149 raise web.HTTPError(403)
149 raise web.HTTPError(403)
150 self.on_message = self.save_on_message
150 self.on_message = self.save_on_message
General Comments 0
You need to be logged in to leave comments. Login now