using System; using System.Collections.Generic; using System.Globalization; using System.Linq; using System.Net; using System.Net.Http; using System.Reflection; using System.Threading; using System.Threading.Tasks; using Octokit.Internal; #if !HAS_ENVIRONMENT using System.Runtime.InteropServices; #endif namespace Octokit { // NOTE: Every request method must go through the `RunRequest` code path. So if you need to add a new method // ensure it goes through there. :) /// /// A connection for making HTTP requests against URI endpoints. /// public class Connection : IConnection { static readonly Uri _defaultGitHubApiUrl = GitHubClient.GitHubApiUrl; static readonly ICredentialStore _anonymousCredentials = new InMemoryCredentialStore(Credentials.Anonymous); readonly Authenticator _authenticator; readonly JsonHttpPipeline _jsonPipeline; readonly IHttpClient _httpClient; /// /// Creates a new connection instance used to make requests of the GitHub API. /// /// /// See more information regarding User-Agent requirements here: https://developer.github.com/v3/#user-agent-required /// /// /// The name (and optionally version) of the product using this library, the name of your GitHub organization, or your GitHub username (in that order of preference). This is sent to the server as part of /// the user agent for analytics purposes, and used by GitHub to contact you if there are problems. /// public Connection(ProductHeaderValue productInformation) : this(productInformation, _defaultGitHubApiUrl, _anonymousCredentials) { } /// /// Creates a new connection instance used to make requests of the GitHub API. /// /// /// See more information regarding User-Agent requirements here: https://developer.github.com/v3/#user-agent-required /// /// /// The name (and optionally version) of the product using this library, the name of your GitHub organization, or your GitHub username (in that order of preference). This is sent to the server as part of /// the user agent for analytics purposes, and used by GitHub to contact you if there are problems. /// /// /// The client to use for executing requests /// public Connection(ProductHeaderValue productInformation, IHttpClient httpClient) : this(productInformation, _defaultGitHubApiUrl, _anonymousCredentials, httpClient, new SimpleJsonSerializer()) { } /// /// Creates a new connection instance used to make requests of the GitHub API. /// /// /// See more information regarding User-Agent requirements here: https://developer.github.com/v3/#user-agent-required /// /// /// The name (and optionally version) of the product using this library, the name of your GitHub organization, or your GitHub username (in that order of preference). This is sent to the server as part of /// the user agent for analytics purposes, and used by GitHub to contact you if there are problems. /// /// /// The address to point this client to such as https://api.github.com or the URL to a GitHub Enterprise /// instance public Connection(ProductHeaderValue productInformation, Uri baseAddress) : this(productInformation, baseAddress, _anonymousCredentials) { } /// /// Creates a new connection instance used to make requests of the GitHub API. /// /// /// See more information regarding User-Agent requirements here: https://developer.github.com/v3/#user-agent-required /// /// /// The name (and optionally version) of the product using this library, the name of your GitHub organization, or your GitHub username (in that order of preference). This is sent to the server as part of /// the user agent for analytics purposes, and used by GitHub to contact you if there are problems. /// /// Provides credentials to the client when making requests public Connection(ProductHeaderValue productInformation, ICredentialStore credentialStore) : this(productInformation, _defaultGitHubApiUrl, credentialStore) { } /// /// Creates a new connection instance used to make requests of the GitHub API. /// /// /// See more information regarding User-Agent requirements here: https://developer.github.com/v3/#user-agent-required /// /// /// The name (and optionally version) of the product using this library, the name of your GitHub organization, or your GitHub username (in that order of preference). This is sent to the server as part of /// the user agent for analytics purposes, and used by GitHub to contact you if there are problems. /// /// /// The address to point this client to such as https://api.github.com or the URL to a GitHub Enterprise /// instance /// Provides credentials to the client when making requests [System.Diagnostics.CodeAnalysis.SuppressMessage("Microsoft.Reliability", "CA2000:Dispose objects before losing scope")] public Connection(ProductHeaderValue productInformation, Uri baseAddress, ICredentialStore credentialStore) : this(productInformation, baseAddress, credentialStore, new HttpClientAdapter(HttpMessageHandlerFactory.CreateDefault), new SimpleJsonSerializer()) { } /// /// Creates a new connection instance used to make requests of the GitHub API. /// /// /// See more information regarding User-Agent requirements here: https://developer.github.com/v3/#user-agent-required /// /// /// The name (and optionally version) of the product using this library, the name of your GitHub organization, or your GitHub username (in that order of preference). This is sent to the server as part of /// the user agent for analytics purposes, and used by GitHub to contact you if there are problems. /// /// /// The address to point this client to such as https://api.github.com or the URL to a GitHub Enterprise /// instance /// Provides credentials to the client when making requests /// A raw used to make requests /// Class used to serialize and deserialize JSON requests public Connection( ProductHeaderValue productInformation, Uri baseAddress, ICredentialStore credentialStore, IHttpClient httpClient, IJsonSerializer serializer) { Ensure.ArgumentNotNull(productInformation, nameof(productInformation)); Ensure.ArgumentNotNull(baseAddress, nameof(baseAddress)); Ensure.ArgumentNotNull(credentialStore, nameof(credentialStore)); Ensure.ArgumentNotNull(httpClient, nameof(httpClient)); Ensure.ArgumentNotNull(serializer, nameof(serializer)); if (!baseAddress.IsAbsoluteUri) { throw new ArgumentException( string.Format(CultureInfo.InvariantCulture, "The base address '{0}' must be an absolute URI", baseAddress), nameof(baseAddress)); } UserAgent = FormatUserAgent(productInformation); BaseAddress = baseAddress; _authenticator = new Authenticator(credentialStore); _httpClient = httpClient; _jsonPipeline = new JsonHttpPipeline(serializer); } /// /// Gets the latest API Info - this will be null if no API calls have been made /// /// representing the information returned as part of an Api call public ApiInfo GetLastApiInfo() { // We've chosen to not wrap the _lastApiInfo in a lock. Originally the code was returning a reference - so there was a danger of // on thread writing to the object while another was reading. Now we are cloning the ApiInfo on request - thus removing the need (or overhead) // of putting locks in place. // See https://github.com/octokit/octokit.net/pull/855#discussion_r36774884 return _lastApiInfo == null ? null : _lastApiInfo.Clone(); } private ApiInfo _lastApiInfo; public Task> Get(Uri uri, IDictionary parameters, string accepts) { Ensure.ArgumentNotNull(uri, nameof(uri)); return SendData(uri.ApplyParameters(parameters), HttpMethod.Get, null, accepts, null, CancellationToken.None); } public Task> Get(Uri uri, IDictionary parameters, string accepts, CancellationToken cancellationToken) { Ensure.ArgumentNotNull(uri, nameof(uri)); return SendData(uri.ApplyParameters(parameters), HttpMethod.Get, null, accepts, null, cancellationToken); } public Task> Get(Uri uri, TimeSpan timeout) { Ensure.ArgumentNotNull(uri, nameof(uri)); return SendData(uri, HttpMethod.Get, null, null, null, timeout, CancellationToken.None); } /// /// Performs an asynchronous HTTP GET request that expects a containing HTML. /// /// URI endpoint to send request to /// Querystring parameters for the request /// representing the received HTTP response public Task> GetHtml(Uri uri, IDictionary parameters) { Ensure.ArgumentNotNull(uri, nameof(uri)); return GetHtml(new Request { Method = HttpMethod.Get, BaseAddress = BaseAddress, Endpoint = uri.ApplyParameters(parameters) }); } /// /// Performs an asynchronous HTTP GET request that expects a containing raw data. /// /// URI endpoint to send request to /// Querystring parameters for the request /// representing the received HTTP response /// The property will be null if the points to a directory instead of a file public Task> GetRaw(Uri uri, IDictionary parameters) { Ensure.ArgumentNotNull(uri, nameof(uri)); return GetRaw(new Request { Method = HttpMethod.Get, BaseAddress = BaseAddress, Endpoint = uri.ApplyParameters(parameters) }); } public Task> Patch(Uri uri, object body) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(body, nameof(body)); return SendData(uri, HttpVerb.Patch, body, null, null, CancellationToken.None); } public Task> Patch(Uri uri, object body, string accepts) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(body, nameof(body)); Ensure.ArgumentNotNull(accepts, nameof(accepts)); return SendData(uri, HttpVerb.Patch, body, accepts, null, CancellationToken.None); } /// /// Performs an asynchronous HTTP POST request. /// /// URI endpoint to send request to /// An optional token to monitor for cancellation requests /// representing the received HTTP response public async Task Post(Uri uri, CancellationToken cancellationToken = default) { Ensure.ArgumentNotNull(uri, nameof(uri)); var response = await SendData(uri, HttpMethod.Post, null, null, null, cancellationToken).ConfigureAwait(false); return response.HttpResponse.StatusCode; } public async Task Post(Uri uri, object body, string accepts, CancellationToken cancellationToken = default) { Ensure.ArgumentNotNull(uri, nameof(uri)); var response = await SendData(uri, HttpMethod.Post, body, accepts, null, cancellationToken).ConfigureAwait(false); return response.HttpResponse.StatusCode; } public Task> Post(Uri uri, CancellationToken cancellationToken = default) { Ensure.ArgumentNotNull(uri, nameof(uri)); return SendData(uri, HttpMethod.Post, null, null, null, cancellationToken); } public Task> Post(Uri uri, object body, string accepts, string contentType, CancellationToken cancellationToken = default) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(body, nameof(body)); return SendData(uri, HttpMethod.Post, body, accepts, contentType, cancellationToken); } public Task> Post( Uri uri, object body, string accepts, string contentType, IDictionary parameters, CancellationToken cancellationToken = default) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(body, nameof(body)); return SendData(uri.ApplyParameters(parameters), HttpMethod.Post, body, accepts, contentType, cancellationToken); } /// /// Performs an asynchronous HTTP POST request. /// Attempts to map the response body to an object of type /// /// The type to map the response to /// URI endpoint to send request to /// The object to serialize as the body of the request /// Specifies accepted response media types. /// Specifies the media type of the request body /// Two Factor Authentication Code /// An optional token to monitor for cancellation requests /// representing the received HTTP response public Task> Post( Uri uri, object body, string accepts, string contentType, string twoFactorAuthenticationCode, CancellationToken cancellationToken = default) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(body, nameof(body)); Ensure.ArgumentNotNullOrEmptyString(twoFactorAuthenticationCode, nameof(twoFactorAuthenticationCode)); return SendData(uri, HttpMethod.Post, body, accepts, contentType, cancellationToken, twoFactorAuthenticationCode); } public Task> Post(Uri uri, object body, string accepts, string contentType, TimeSpan timeout, CancellationToken cancellationToken = default) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(body, nameof(body)); return SendData(uri, HttpMethod.Post, body, accepts, contentType, timeout, cancellationToken); } public Task> Post(Uri uri, object body, string accepts, string contentType, Uri baseAddress, CancellationToken cancellationToken = default) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(body, nameof(body)); return SendData(uri, HttpMethod.Post, body, accepts, contentType, cancellationToken, baseAddress: baseAddress); } public Task> Put(Uri uri, object body) { return SendData(uri, HttpMethod.Put, body, null, null, CancellationToken.None); } public Task> Put(Uri uri, object body, string twoFactorAuthenticationCode) { return SendData(uri, HttpMethod.Put, body, null, null, CancellationToken.None, twoFactorAuthenticationCode); } public Task> Put(Uri uri, object body, string twoFactorAuthenticationCode, string accepts) { return SendData(uri, HttpMethod.Put, body, accepts, null, CancellationToken.None, twoFactorAuthenticationCode); } Task> SendData( Uri uri, HttpMethod method, object body, string accepts, string contentType, TimeSpan timeout, CancellationToken cancellationToken, string twoFactorAuthenticationCode = null, Uri baseAddress = null) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.GreaterThanZero(timeout, nameof(timeout)); var request = new Request { Method = method, BaseAddress = baseAddress ?? BaseAddress, Endpoint = uri, Timeout = timeout }; return SendDataInternal(body, accepts, contentType, cancellationToken, twoFactorAuthenticationCode, request); } Task> SendData( Uri uri, HttpMethod method, object body, string accepts, string contentType, CancellationToken cancellationToken, string twoFactorAuthenticationCode = null, Uri baseAddress = null) { Ensure.ArgumentNotNull(uri, nameof(uri)); var request = new Request { Method = method, BaseAddress = baseAddress ?? BaseAddress, Endpoint = uri }; return SendDataInternal(body, accepts, contentType, cancellationToken, twoFactorAuthenticationCode, request); } Task> SendDataInternal(object body, string accepts, string contentType, CancellationToken cancellationToken, string twoFactorAuthenticationCode, Request request) { if (!string.IsNullOrEmpty(accepts)) { request.Headers["Accept"] = accepts; } if (!string.IsNullOrEmpty(twoFactorAuthenticationCode)) { request.Headers["X-GitHub-OTP"] = twoFactorAuthenticationCode; } if (body != null) { request.Body = body; // Default Content Type per: http://developer.github.com/v3/ request.ContentType = contentType ?? "application/x-www-form-urlencoded"; } return Run(request, cancellationToken); } /// /// Performs an asynchronous HTTP PATCH request. /// /// URI endpoint to send request to /// representing the received HTTP response public async Task Patch(Uri uri) { Ensure.ArgumentNotNull(uri, nameof(uri)); var request = new Request { Method = HttpVerb.Patch, BaseAddress = BaseAddress, Endpoint = uri }; var response = await Run(request, CancellationToken.None).ConfigureAwait(false); return response.HttpResponse.StatusCode; } /// /// Performs an asynchronous HTTP PATCH request. /// /// URI endpoint to send request to /// Specifies accept response media type /// representing the received HTTP response public async Task Patch(Uri uri, string accepts) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(accepts, nameof(accepts)); var response = await SendData(uri, new HttpMethod("PATCH"), null, accepts, null, CancellationToken.None).ConfigureAwait(false); return response.HttpResponse.StatusCode; } /// /// Performs an asynchronous HTTP PUT request that expects an empty response. /// /// URI endpoint to send request to /// The returned public async Task Put(Uri uri) { Ensure.ArgumentNotNull(uri, nameof(uri)); var request = new Request { Method = HttpMethod.Put, BaseAddress = BaseAddress, Endpoint = uri }; var response = await Run(request, CancellationToken.None).ConfigureAwait(false); return response.HttpResponse.StatusCode; } /// /// Performs an asynchronous HTTP PUT request that expects an empty response. /// /// URI endpoint to send request to /// Specifies accepted response media types. /// The returned public async Task Put(Uri uri, string accepts) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(accepts, nameof(accepts)); var response = await SendData(uri, HttpMethod.Put, null, accepts, null, CancellationToken.None).ConfigureAwait(false); return response.HttpResponse.StatusCode; } /// /// Performs an asynchronous HTTP DELETE request that expects an empty response. /// /// URI endpoint to send request to /// The returned public async Task Delete(Uri uri) { Ensure.ArgumentNotNull(uri, nameof(uri)); var request = new Request { Method = HttpMethod.Delete, BaseAddress = BaseAddress, Endpoint = uri }; var response = await Run(request, CancellationToken.None).ConfigureAwait(false); return response.HttpResponse.StatusCode; } /// /// Performs an asynchronous HTTP DELETE request that expects an empty response. /// /// URI endpoint to send request to /// Two Factor Code /// The returned public async Task Delete(Uri uri, string twoFactorAuthenticationCode) { Ensure.ArgumentNotNull(uri, nameof(uri)); var response = await SendData(uri, HttpMethod.Delete, null, null, null, CancellationToken.None, twoFactorAuthenticationCode).ConfigureAwait(false); return response.HttpResponse.StatusCode; } /// /// Performs an asynchronous HTTP DELETE request that expects an empty response. /// /// URI endpoint to send request to /// The object to serialize as the body of the request /// The returned public async Task Delete(Uri uri, object data) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(data, nameof(data)); var request = new Request { Method = HttpMethod.Delete, Body = data, BaseAddress = BaseAddress, Endpoint = uri }; var response = await Run(request, CancellationToken.None).ConfigureAwait(false); return response.HttpResponse.StatusCode; } /// /// Performs an asynchronous HTTP DELETE request that expects an empty response. /// /// URI endpoint to send request to /// The object to serialize as the body of the request /// Specifies accept response media type /// The returned public async Task Delete(Uri uri, object data, string accepts) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(accepts, nameof(accepts)); var response = await SendData(uri, HttpMethod.Delete, data, accepts, null, CancellationToken.None).ConfigureAwait(false); return response.HttpResponse.StatusCode; } /// /// Performs an asynchronous HTTP DELETE request. /// /// The API resource's type. /// URI endpoint to send request to /// The object to serialize as the body of the request public Task> Delete(Uri uri, object data) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(data, nameof(data)); return SendData(uri, HttpMethod.Delete, data, null, null, CancellationToken.None); } /// /// Performs an asynchronous HTTP DELETE request. /// Attempts to map the response body to an object of type /// /// The type to map the response to /// URI endpoint to send request to /// The object to serialize as the body of the request /// Specifies accept response media type public Task> Delete(Uri uri, object data, string accepts) { Ensure.ArgumentNotNull(uri, nameof(uri)); Ensure.ArgumentNotNull(accepts, nameof(accepts)); return SendData(uri, HttpMethod.Delete, data, accepts, null, CancellationToken.None); } /// /// Base address for the connection. /// public Uri BaseAddress { get; private set; } public string UserAgent { get; private set; } /// /// Gets the used to provide credentials for the connection. /// public ICredentialStore CredentialStore { get { return _authenticator.CredentialStore; } } /// /// Gets or sets the credentials used by the connection. /// /// /// You can use this property if you only have a single hard-coded credential. Otherwise, pass in an /// to the constructor. /// Setting this property will change the to use /// the default with just these credentials. /// public Credentials Credentials { get { var credentialTask = CredentialStore.GetCredentials(); if (credentialTask == null) return Credentials.Anonymous; return credentialTask.Result ?? Credentials.Anonymous; } // Note this is for convenience. We probably shouldn't allow this to be mutable. set { Ensure.ArgumentNotNull(value, nameof(value)); _authenticator.CredentialStore = new InMemoryCredentialStore(value); } } async Task> GetHtml(IRequest request) { request.Headers.Add("Accept", AcceptHeaders.StableVersionHtml); var response = await RunRequest(request, CancellationToken.None).ConfigureAwait(false); return new ApiResponse(response, response.Body as string); } async Task> GetRaw(IRequest request) { request.Headers.Add("Accept", AcceptHeaders.RawContentMediaType); var response = await RunRequest(request, CancellationToken.None).ConfigureAwait(false); return new ApiResponse(response, response.Body as byte[]); } async Task> Run(IRequest request, CancellationToken cancellationToken) { _jsonPipeline.SerializeRequest(request); var response = await RunRequest(request, cancellationToken).ConfigureAwait(false); return _jsonPipeline.DeserializeResponse(response); } // THIS IS THE METHOD THAT EVERY REQUEST MUST GO THROUGH! async Task RunRequest(IRequest request, CancellationToken cancellationToken) { request.Headers.Add("User-Agent", UserAgent); await _authenticator.Apply(request).ConfigureAwait(false); var response = await _httpClient.Send(request, cancellationToken).ConfigureAwait(false); if (response != null) { // Use the clone method to avoid keeping hold of the original (just in case it effect the lifetime of the whole response _lastApiInfo = response.ApiInfo.Clone(); } HandleErrors(response); return response; } static readonly Dictionary> _httpExceptionMap = new Dictionary> { { HttpStatusCode.Unauthorized, GetExceptionForUnauthorized }, { HttpStatusCode.Forbidden, GetExceptionForForbidden }, { HttpStatusCode.NotFound, response => new NotFoundException(response) }, { (HttpStatusCode)422, response => new ApiValidationException(response) }, { (HttpStatusCode)451, response => new LegalRestrictionException(response) } }; static void HandleErrors(IResponse response) { Func exceptionFunc; if (_httpExceptionMap.TryGetValue(response.StatusCode, out exceptionFunc)) { throw exceptionFunc(response); } if ((int)response.StatusCode >= 400) { throw new ApiException(response); } } static Exception GetExceptionForUnauthorized(IResponse response) { var twoFactorType = ParseTwoFactorType(response); return twoFactorType == TwoFactorType.None ? new AuthorizationException(response) : new TwoFactorRequiredException(response, twoFactorType); } static Exception GetExceptionForForbidden(IResponse response) { string body = response.Body as string ?? ""; if (body.Contains("rate limit exceeded")) { return new RateLimitExceededException(response); } if (body.Contains("number of login attempts exceeded")) { return new LoginAttemptsExceededException(response); } if (body.Contains("abuse-rate-limits") || body.Contains("abuse detection mechanism")) { return new AbuseException(response); } return new ForbiddenException(response); } internal static TwoFactorType ParseTwoFactorType(IResponse restResponse) { if (restResponse == null || restResponse.Headers == null || !restResponse.Headers.Any()) return TwoFactorType.None; var otpHeader = restResponse.Headers.FirstOrDefault(header => header.Key.Equals("X-GitHub-OTP", StringComparison.OrdinalIgnoreCase)); if (string.IsNullOrEmpty(otpHeader.Value)) return TwoFactorType.None; var factorType = otpHeader.Value; var parts = factorType.Split(new[] { ';' }, StringSplitOptions.RemoveEmptyEntries); if (parts.Length > 0 && parts[0] == "required") { var secondPart = parts.Length > 1 ? parts[1].Trim() : null; switch (secondPart) { case "sms": return TwoFactorType.Sms; case "app": return TwoFactorType.AuthenticatorApp; default: return TwoFactorType.Unknown; } } return TwoFactorType.None; } static string FormatUserAgent(ProductHeaderValue productInformation) { return string.Format(CultureInfo.InvariantCulture, "{0} ({1}; {2}; Octokit {3})", productInformation, GetPlatformInformation(), GetCultureInformation(), GetVersionInformation()); } private static string _platformInformation; static string GetPlatformInformation() { if (string.IsNullOrEmpty(_platformInformation)) { try { _platformInformation = string.Format(CultureInfo.InvariantCulture, #if !HAS_ENVIRONMENT "{0}; {1}", RuntimeInformation.OSDescription.Trim(), RuntimeInformation.OSArchitecture.ToString().ToLowerInvariant().Trim() #else "{0} {1}; {2}", Environment.OSVersion.Platform, Environment.OSVersion.Version.ToString(3), Environment.Is64BitOperatingSystem ? "amd64" : "x86" #endif ); } catch { _platformInformation = "Unknown Platform"; } } return _platformInformation; } static string GetCultureInformation() { return CultureInfo.CurrentCulture.Name; } private static string _versionInformation; static string GetVersionInformation() { if (string.IsNullOrEmpty(_versionInformation)) { _versionInformation = typeof(IGitHubClient) .GetTypeInfo() .Assembly .GetCustomAttribute() .InformationalVersion; } return _versionInformation; } /// /// Set the GitHub Api request timeout. /// /// The Timeout value public void SetRequestTimeout(TimeSpan timeout) { _httpClient.SetRequestTimeout(timeout); } } }