1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92
|
package server
import (
"fmt"
"net/http"
"os"
"path/filepath"
"github.com/kotakanbe/go-cve-dictionary/config"
"github.com/kotakanbe/go-cve-dictionary/db"
log "github.com/kotakanbe/go-cve-dictionary/log"
"github.com/labstack/echo"
"github.com/labstack/echo/middleware"
)
// Start starts CVE dictionary HTTP Server.
func Start(logDir string, driver db.DB) error {
e := echo.New()
e.Debug = config.Conf.Debug
// Middleware
e.Use(middleware.Logger())
e.Use(middleware.Recover())
// setup access logger
logPath := filepath.Join(logDir, "access.log")
if _, err := os.Stat(logPath); os.IsNotExist(err) {
if _, err := os.Create(logPath); err != nil {
return err
}
}
f, err := os.OpenFile(logPath, os.O_APPEND|os.O_WRONLY, 0600)
if err != nil {
return err
}
defer f.Close()
e.Use(middleware.LoggerWithConfig(middleware.LoggerConfig{
Output: f,
}))
// Routes
e.GET("/health", health())
e.GET("/cves/:id", getCve(driver))
e.POST("/cpes", getCveByCpeName(driver))
bindURL := fmt.Sprintf("%s:%s", config.Conf.Bind, config.Conf.Port)
log.Infof("Listening on %s", bindURL)
e.Start(bindURL)
return nil
}
// Handler
func health() echo.HandlerFunc {
return func(c echo.Context) error {
return c.String(http.StatusOK, "")
}
}
// Handler
func getCve(driver db.DB) echo.HandlerFunc {
return func(c echo.Context) error {
cveid := c.Param("id")
cveDetail, err := driver.Get(cveid)
if err != nil {
log.Errorf("%s", err)
return err
}
return c.JSON(http.StatusOK, &cveDetail)
}
}
type cpeName struct {
Name string `form:"name"`
}
func getCveByCpeName(driver db.DB) echo.HandlerFunc {
return func(c echo.Context) error {
cpe := cpeName{}
err := c.Bind(&cpe)
if err != nil {
log.Errorf("%s", err)
return err
}
cveDetails, err := driver.GetByCpeURI(cpe.Name)
if err != nil {
log.Errorf("%s", err)
return err
}
return c.JSON(http.StatusOK, &cveDetails)
}
}
|