This PR adds a flag to the test method so we can choose to test for read-only access (needed for restore) or read-write (needed for backups). Additionally, this PR fixes a logic bug in that the BackendSourceProvider would not actually test the connection, but just check the placeholder element returned (which is always returned). With this PR the backend's ListAsync command is tested fully. Also renamed the methods on ISourceProvider to have the `...Async` prefix. This replaces #6939
439 lines
22 KiB
C#
439 lines
22 KiB
C#
// Copyright (C) 2026, The Duplicati Team
|
|
// https://duplicati.com, hello@duplicati.com
|
|
//
|
|
// Permission is hereby granted, free of charge, to any person obtaining a
|
|
// copy of this software and associated documentation files (the "Software"),
|
|
// to deal in the Software without restriction, including without limitation
|
|
// the rights to use, copy, modify, merge, publish, distribute, sublicense,
|
|
// and/or sell copies of the Software, and to permit persons to whom the
|
|
// Software is furnished to do so, subject to the following conditions:
|
|
//
|
|
// The above copyright notice and this permission notice shall be included in
|
|
// all copies or substantial portions of the Software.
|
|
//
|
|
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
|
|
// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
|
// FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
|
|
// DEALINGS IN THE SOFTWARE.
|
|
|
|
using Duplicati.Library.Backend.GoogleServices;
|
|
using Duplicati.Library.Common.IO;
|
|
using Duplicati.Library.Interface;
|
|
using Duplicati.Library.Utility;
|
|
using Duplicati.Library.Utility.Options;
|
|
using Google.Apis.Auth.OAuth2;
|
|
using System.Net;
|
|
using System.Net.Http.Json;
|
|
using System.Runtime.CompilerServices;
|
|
using System.Text;
|
|
|
|
namespace Duplicati.Library.Backend.GoogleCloudStorage
|
|
{
|
|
// ReSharper disable once UnusedMember.Global
|
|
// This class is instantiated dynamically in the BackendLoader.
|
|
public class GoogleCloudStorage : IBackend, IStreamingBackend, ILockingBackend, IRenameEnabledBackend
|
|
{
|
|
private static readonly string TOKEN_URL = AuthIdOptionsHelper.GetOAuthLoginUrl("gcs", null);
|
|
private const string PROJECT_OPTION = "gcs-project";
|
|
|
|
private const string LOCATION_OPTION = "gcs-location";
|
|
private const string STORAGECLASS_OPTION = "gcs-storage-class";
|
|
private const string SERVICE_ACCOUNT_JSON_OPTION = "gcs-service-account-json";
|
|
private const string SERVICE_ACCOUNT_FILE_OPTION = "gcs-service-account-file";
|
|
private const string RETENTION_POLICY_MODE_OPTION = "gcs-retention-policy-mode";
|
|
|
|
private const RetentionPolicyMode DEFAULT_RETENTION_POLICY_MODE = RetentionPolicyMode.Unlocked;
|
|
|
|
/// <summary>
|
|
/// The scope used to request access to Google Cloud Storage.
|
|
/// </summary>
|
|
private const string CREDENTIAL_SCOPE = "https://www.googleapis.com/auth/devstorage.read_write";
|
|
/// <summary>
|
|
/// The scope used to request full control access to Google Cloud Storage, needed for setting object retention.
|
|
/// </summary>
|
|
private const string CREDENTIAL_SCOPE_FULL_CONTROL = "https://www.googleapis.com/auth/devstorage.full_control";
|
|
|
|
private readonly string m_bucket;
|
|
private readonly string m_prefix;
|
|
private readonly string? m_project;
|
|
private readonly JsonWebHelperHttpClient m_oauth;
|
|
|
|
/// <summary>
|
|
/// Cached instance of the full control OAuth client.
|
|
/// </summary>
|
|
private JsonWebHelperHttpClient? m_oauth_fullcontrol;
|
|
/// <summary>
|
|
/// Only create the full control client when needed, but capture all parameters in the constructor.
|
|
/// </summary>
|
|
private readonly Func<JsonWebHelperHttpClient?> m_create_oauth_fullcontrol;
|
|
|
|
private readonly string? m_location;
|
|
private readonly string? m_storage_class;
|
|
private readonly RetentionPolicyMode m_retention_policy_mode;
|
|
private readonly TimeoutOptionsHelper.Timeouts m_timeouts;
|
|
|
|
public GoogleCloudStorage()
|
|
{
|
|
m_bucket = null!;
|
|
m_prefix = null!;
|
|
m_oauth = null!;
|
|
m_timeouts = null!;
|
|
m_create_oauth_fullcontrol = null!;
|
|
m_retention_policy_mode = RetentionPolicyMode.Locked;
|
|
}
|
|
|
|
public GoogleCloudStorage(string url, Dictionary<string, string?> options)
|
|
{
|
|
var uri = new Utility.Uri(url);
|
|
|
|
m_bucket = uri.Host ?? "";
|
|
m_prefix = Util.AppendDirSeparator("/" + uri.Path, "/");
|
|
|
|
// For GCS we do not use a leading slash
|
|
if (m_prefix.StartsWith("/", StringComparison.Ordinal))
|
|
m_prefix = m_prefix.Substring(1);
|
|
|
|
|
|
var serviceAccountFile = options.GetValueOrDefault(SERVICE_ACCOUNT_FILE_OPTION);
|
|
var serviceAccountJson = options.GetValueOrDefault(SERVICE_ACCOUNT_JSON_OPTION);
|
|
m_timeouts = TimeoutOptionsHelper.Parse(options);
|
|
m_project = options.GetValueOrDefault(PROJECT_OPTION);
|
|
m_location = options.GetValueOrDefault(LOCATION_OPTION);
|
|
m_storage_class = options.GetValueOrDefault(STORAGECLASS_OPTION);
|
|
|
|
m_retention_policy_mode = Utility.Utility.ParseEnumOption(options, RETENTION_POLICY_MODE_OPTION, DEFAULT_RETENTION_POLICY_MODE);
|
|
if (!string.IsNullOrWhiteSpace(serviceAccountJson))
|
|
{
|
|
m_oauth = new ServiceAccountHttpClient(GoogleCredential.FromJson(serviceAccountJson).CreateScoped(CREDENTIAL_SCOPE));
|
|
m_create_oauth_fullcontrol = () => new ServiceAccountHttpClient(GoogleCredential.FromJson(serviceAccountJson).CreateScoped(CREDENTIAL_SCOPE_FULL_CONTROL));
|
|
}
|
|
else if (!string.IsNullOrWhiteSpace(serviceAccountFile))
|
|
{
|
|
m_oauth = new ServiceAccountHttpClient(GoogleCredential.FromFile(serviceAccountFile).CreateScoped(CREDENTIAL_SCOPE));
|
|
m_create_oauth_fullcontrol = () => new ServiceAccountHttpClient(GoogleCredential.FromFile(serviceAccountFile).CreateScoped(CREDENTIAL_SCOPE_FULL_CONTROL));
|
|
}
|
|
else
|
|
{
|
|
var authId = AuthIdOptionsHelper.Parse(options)
|
|
.RequireCredentials(TOKEN_URL);
|
|
m_oauth = new OAuthHelperHttpClient(authId.AuthId!, this.ProtocolKey, authId.OAuthUrl)
|
|
{
|
|
AutoAuthHeader = true
|
|
};
|
|
|
|
// This does not work with the current OAuth server as it only grants read/write access.
|
|
m_create_oauth_fullcontrol = () => null;
|
|
}
|
|
}
|
|
|
|
private class ListBucketResponse
|
|
{
|
|
public string? nextPageToken { get; set; }
|
|
public BucketResourceItem[]? items { get; set; }
|
|
}
|
|
|
|
private class BucketResourceItem
|
|
{
|
|
public string? name { get; set; }
|
|
public DateTime? updated { get; set; }
|
|
public long? size { get; set; }
|
|
}
|
|
|
|
private class CreateBucketRequest
|
|
{
|
|
public string? name { get; set; }
|
|
public string? location { get; set; }
|
|
public string? storageClass { get; set; }
|
|
}
|
|
|
|
private class ObjectMetadata
|
|
{
|
|
public Retention? retention { get; set; }
|
|
}
|
|
|
|
private class Retention
|
|
{
|
|
public string? mode { get; set; }
|
|
public DateTime? retainUntilTime { get; set; }
|
|
}
|
|
|
|
private enum RetentionPolicyMode
|
|
{
|
|
Locked,
|
|
Unlocked
|
|
}
|
|
|
|
private async Task<T> HandleListExceptions<T>(Func<Task<T>> func)
|
|
{
|
|
try
|
|
{
|
|
return await func().ConfigureAwait(false);
|
|
}
|
|
catch (HttpRequestException wex)
|
|
{
|
|
if (wex.StatusCode == HttpStatusCode.Forbidden)
|
|
throw new FolderMissingException();
|
|
throw;
|
|
}
|
|
}
|
|
|
|
#region IBackend implementation
|
|
/// <inheritdoc />
|
|
public async IAsyncEnumerable<IFileEntry> ListAsync([EnumeratorCancellation] CancellationToken cancelToken)
|
|
{
|
|
var url = WebApi.GoogleCloudStorage.ListUrl(m_bucket, Utility.Uri.UrlEncode(m_prefix));
|
|
while (true)
|
|
{
|
|
var resp = await HandleListExceptions(() =>
|
|
Utility.Utility.WithTimeout(m_timeouts.ListTimeout, cancelToken, async ct =>
|
|
{
|
|
using var req = await m_oauth.CreateRequestAsync(url, HttpMethod.Get, ct).ConfigureAwait(false);
|
|
req.Headers.Add("Accept", "application/json");
|
|
|
|
using var resp = await m_oauth.GetResponseAsync(req, HttpCompletionOption.ResponseHeadersRead, ct).ConfigureAwait(false);
|
|
return await resp.Content.ReadFromJsonAsync<ListBucketResponse>(ct).ConfigureAwait(false)
|
|
?? throw new Exception("Failed to parse response");
|
|
})).ConfigureAwait(false);
|
|
|
|
if (resp.items != null)
|
|
foreach (var f in resp.items)
|
|
{
|
|
var name = f.name ?? "";
|
|
if (name.StartsWith(m_prefix, StringComparison.OrdinalIgnoreCase))
|
|
name = name.Substring(m_prefix.Length);
|
|
if (f.size == null)
|
|
yield return new FileEntry(name);
|
|
else if (f.updated == null)
|
|
yield return new FileEntry(name, f.size.Value);
|
|
else
|
|
yield return new FileEntry(name, f.size.Value, f.updated.Value, f.updated.Value);
|
|
}
|
|
|
|
var token = resp.nextPageToken;
|
|
if (string.IsNullOrWhiteSpace(token))
|
|
break;
|
|
url = WebApi.GoogleCloudStorage.ListUrl(m_bucket, Utility.Uri.UrlEncode(m_prefix), token);
|
|
}
|
|
}
|
|
|
|
public async Task PutAsync(string remotename, string filename, CancellationToken cancelToken)
|
|
{
|
|
using (var fs = File.OpenRead(filename))
|
|
await PutAsync(remotename, fs, cancelToken).ConfigureAwait(false);
|
|
}
|
|
|
|
public async Task GetAsync(string remotename, string filename, CancellationToken cancelToken)
|
|
{
|
|
using (var fs = File.Create(filename))
|
|
await GetAsync(remotename, fs, cancelToken).ConfigureAwait(false);
|
|
}
|
|
public async Task DeleteAsync(string remotename, CancellationToken cancelToken)
|
|
{
|
|
using var req = await m_oauth.CreateRequestAsync(WebApi.GoogleCloudStorage.DeleteUrl(m_bucket, Library.Utility.Uri.UrlPathEncode(m_prefix + remotename)), HttpMethod.Delete, cancelToken);
|
|
|
|
await Utility.Utility.WithTimeout(m_timeouts.ShortTimeout, cancelToken, async ct
|
|
=>
|
|
{
|
|
using var resp = await m_oauth.GetResponseAsync(req, HttpCompletionOption.ResponseContentRead, ct).ConfigureAwait(false);
|
|
}).ConfigureAwait(false);
|
|
}
|
|
|
|
public async Task<DateTime?> GetObjectLockUntilAsync(string remotename, CancellationToken cancellationToken)
|
|
{
|
|
var url = WebApi.GoogleCloudStorage.MetadataUrl(m_bucket, Utility.Uri.UrlPathEncode(m_prefix + remotename));
|
|
|
|
try
|
|
{
|
|
using var req = await m_oauth.CreateRequestAsync(url, HttpMethod.Get, cancellationToken).ConfigureAwait(false);
|
|
req.Headers.Add("Accept", "application/json");
|
|
|
|
using var resp = await m_oauth.GetResponseAsync(req, HttpCompletionOption.ResponseHeadersRead, cancellationToken).ConfigureAwait(false);
|
|
var metadata = await resp.Content.ReadFromJsonAsync<ObjectMetadata>(cancellationToken).ConfigureAwait(false);
|
|
|
|
return metadata?.retention?.retainUntilTime;
|
|
}
|
|
catch (HttpRequestException hrex)
|
|
{
|
|
if (hrex.StatusCode == HttpStatusCode.NotFound)
|
|
throw new FileMissingException();
|
|
throw;
|
|
}
|
|
}
|
|
|
|
public async Task SetObjectLockUntilAsync(string remotename, DateTime lockUntilUtc, CancellationToken cancellationToken)
|
|
{
|
|
var url = WebApi.GoogleCloudStorage.MetadataUrl(m_bucket, Utility.Uri.UrlPathEncode(m_prefix + remotename));
|
|
|
|
var metadata = new ObjectMetadata
|
|
{
|
|
retention = new Retention
|
|
{
|
|
mode = m_retention_policy_mode.ToString(),
|
|
retainUntilTime = lockUntilUtc
|
|
}
|
|
};
|
|
|
|
try
|
|
{
|
|
if (m_oauth_fullcontrol == null)
|
|
m_oauth_fullcontrol = m_create_oauth_fullcontrol();
|
|
|
|
if (m_oauth_fullcontrol == null)
|
|
throw new UserInformationException(Strings.GoogleCloudStorage.MissingFullControlScopeError, "GoogleCloudStorageMissingFullControlScope");
|
|
|
|
using var req = await m_oauth_fullcontrol.CreateRequestAsync(url, new HttpMethod("PATCH"), cancellationToken).ConfigureAwait(false);
|
|
req.Content = JsonContent.Create(metadata);
|
|
req.Headers.Add("Accept", "application/json");
|
|
|
|
using var resp = await m_oauth_fullcontrol.GetResponseAsync(req, HttpCompletionOption.ResponseHeadersRead, cancellationToken).ConfigureAwait(false);
|
|
}
|
|
catch (HttpRequestException hrex)
|
|
{
|
|
if (hrex.StatusCode == HttpStatusCode.NotFound)
|
|
throw new FileMissingException();
|
|
throw;
|
|
}
|
|
}
|
|
|
|
public Task TestAsync(bool alsoWrite, CancellationToken cancelToken)
|
|
=> this.TestBackendAsync(alsoWrite, cancelToken);
|
|
|
|
public async Task CreateFolderAsync(CancellationToken cancelToken)
|
|
{
|
|
if (string.IsNullOrEmpty(m_project))
|
|
throw new UserInformationException(Strings.GoogleCloudStorage.ProjectIDMissingError(PROJECT_OPTION), "GoogleCloudStorageMissingProjectID");
|
|
|
|
using var req = await m_oauth.CreateRequestAsync(WebApi.GoogleCloudStorage.CreateFolderUrl(m_project), HttpMethod.Post, cancelToken);
|
|
req.Content = JsonContent.Create(new CreateBucketRequest
|
|
{
|
|
name = m_bucket,
|
|
location = m_location,
|
|
storageClass = m_storage_class
|
|
});
|
|
|
|
await Utility.Utility.WithTimeout(m_timeouts.ShortTimeout, cancelToken, async ct =>
|
|
{
|
|
using var resp = await m_oauth.GetResponseAsync(req, HttpCompletionOption.ResponseContentRead, ct).ConfigureAwait(false);
|
|
var res = await resp.Content.ReadFromJsonAsync<BucketResourceItem>(ct).ConfigureAwait(false);
|
|
if (res == null)
|
|
throw new Exception("Create folder succeeded, but no data was returned");
|
|
}).ConfigureAwait(false);
|
|
}
|
|
|
|
/// <inheritdoc/>
|
|
public string DisplayName => Strings.GoogleCloudStorage.DisplayName;
|
|
|
|
/// <inheritdoc/>
|
|
public string ProtocolKey => "gcs";
|
|
|
|
/// <inheritdoc/>
|
|
public IList<ICommandLineArgument> SupportedCommands
|
|
{
|
|
get
|
|
{
|
|
StringBuilder locations = new StringBuilder();
|
|
StringBuilder storageClasses = new StringBuilder();
|
|
|
|
foreach (var s in WebApi.GoogleCloudStorage.KNOWN_GCS_LOCATIONS)
|
|
locations.AppendLine(string.Format("{0}: {1}", s.Key, s.Value));
|
|
foreach (var s in WebApi.GoogleCloudStorage.KNOWN_GCS_STORAGE_CLASSES)
|
|
storageClasses.AppendLine(string.Format("{0}: {1}", s.Key, s.Value));
|
|
|
|
return [
|
|
new CommandLineArgument(LOCATION_OPTION, CommandLineArgument.ArgumentType.String, Strings.GoogleCloudStorage.LocationDescriptionShort, Strings.GoogleCloudStorage.LocationDescriptionLong(locations.ToString())),
|
|
new CommandLineArgument(STORAGECLASS_OPTION, CommandLineArgument.ArgumentType.String, Strings.GoogleCloudStorage.StorageclassDescriptionShort, Strings.GoogleCloudStorage.StorageclassDescriptionLong(storageClasses.ToString())),
|
|
.. AuthIdOptionsHelper.GetOptions(TOKEN_URL),
|
|
new CommandLineArgument(SERVICE_ACCOUNT_JSON_OPTION, CommandLineArgument.ArgumentType.Password, Strings.GoogleCloudStorage.ServiceAccountJsonDescriptionShort, Strings.GoogleCloudStorage.ServiceAccountJsonDescriptionLong),
|
|
new CommandLineArgument(SERVICE_ACCOUNT_FILE_OPTION, CommandLineArgument.ArgumentType.String, Strings.GoogleCloudStorage.ServiceAccountFileDescriptionShort, Strings.GoogleCloudStorage.ServiceAccountFileDescriptionLong),
|
|
new CommandLineArgument(RETENTION_POLICY_MODE_OPTION, CommandLineArgument.ArgumentType.String, Strings.GoogleCloudStorage.RetentionPolicyModeDescriptionShort, Strings.GoogleCloudStorage.RetentionPolicyModeDescriptionLong, DEFAULT_RETENTION_POLICY_MODE.ToString(), null, Enum.GetNames(typeof(RetentionPolicyMode))),
|
|
new CommandLineArgument(PROJECT_OPTION, CommandLineArgument.ArgumentType.String, Strings.GoogleCloudStorage.ProjectDescriptionShort, Strings.GoogleCloudStorage.ProjectDescriptionLong),
|
|
.. TimeoutOptionsHelper.GetOptions(),
|
|
];
|
|
}
|
|
}
|
|
|
|
/// <inheritdoc/>
|
|
public string Description => Strings.GoogleCloudStorage.Description;
|
|
|
|
/// <inheritdoc/>
|
|
public Task<string[]> GetDNSNamesAsync(CancellationToken cancelToken) => Task.FromResult(WebApi.GoogleCloudStorage.Hosts());
|
|
|
|
#endregion
|
|
|
|
/// <inheritdoc/>
|
|
public bool SupportsStreaming => true;
|
|
|
|
/// <inheritdoc/>
|
|
public async Task PutAsync(string remotename, Stream stream, CancellationToken cancelToken)
|
|
{
|
|
var item = new BucketResourceItem { name = m_prefix + remotename };
|
|
|
|
var url = WebApi.GoogleCloudStorage.PutUrl(m_bucket);
|
|
var res = await GoogleCommon.ChunkedUploadWithResumeAsync<BucketResourceItem, BucketResourceItem>(m_oauth, item, url, stream, m_timeouts.ShortTimeout, m_timeouts.ReadWriteTimeout, cancelToken, HttpMethod.Post).ConfigureAwait(false);
|
|
|
|
if (res == null)
|
|
throw new Exception("Upload succeeded, but no data was returned");
|
|
}
|
|
|
|
public async Task GetAsync(string remotename, Stream stream, CancellationToken cancelToken)
|
|
{
|
|
try
|
|
{
|
|
var url = WebApi.GoogleCloudStorage.GetUrl(m_bucket, Utility.Uri.UrlPathEncode(m_prefix + remotename));
|
|
using var req = await m_oauth.CreateRequestAsync(url, HttpMethod.Get, cancelToken);
|
|
using var resp = await Library.Utility.Utility.WithTimeout(m_timeouts.ShortTimeout, cancelToken, ct => m_oauth.GetResponseAsync(req, HttpCompletionOption.ResponseHeadersRead, ct)).ConfigureAwait(false);
|
|
using var source = await Library.Utility.Utility.WithTimeout(m_timeouts.ShortTimeout, cancelToken, ct => resp.Content.ReadAsStreamAsync(cancelToken)).ConfigureAwait(false);
|
|
|
|
using (var ts = source.ObserveReadTimeout(m_timeouts.ReadWriteTimeout))
|
|
await Utility.Utility.CopyStreamAsync(ts, stream, cancelToken).ConfigureAwait(false);
|
|
}
|
|
catch (HttpRequestException hrex)
|
|
{
|
|
if (hrex.StatusCode == HttpStatusCode.NotFound)
|
|
throw new FileMissingException();
|
|
throw;
|
|
}
|
|
}
|
|
|
|
public async Task RenameAsync(string oldname, string newname, CancellationToken cancellationToken)
|
|
{
|
|
var url = WebApi.GoogleCloudStorage.RewriteUrl(m_bucket, Utility.Uri.UrlPathEncode(m_prefix + oldname), m_bucket, Utility.Uri.UrlPathEncode(m_prefix + newname));
|
|
|
|
// Perform rewrite (copy)
|
|
await Utility.Utility.WithTimeout(m_timeouts.ShortTimeout, cancellationToken, async ct =>
|
|
{
|
|
using var req = await m_oauth.CreateRequestAsync(url, HttpMethod.Post, ct).ConfigureAwait(false);
|
|
req.Content = new StringContent("", Encoding.UTF8, "application/json"); // Empty body
|
|
using var resp = await m_oauth.GetResponseAsync(req, HttpCompletionOption.ResponseContentRead, ct).ConfigureAwait(false);
|
|
|
|
var res = await resp.Content.ReadFromJsonAsync<RewriteResponse>(ct).ConfigureAwait(false);
|
|
while (res != null && res.done == false)
|
|
{
|
|
var token = res.rewriteToken;
|
|
var nextUrl = url + "?rewriteToken=" + token;
|
|
using var nextReq = await m_oauth.CreateRequestAsync(nextUrl, HttpMethod.Post, ct).ConfigureAwait(false);
|
|
nextReq.Content = new StringContent("", Encoding.UTF8, "application/json");
|
|
using var nextResp = await m_oauth.GetResponseAsync(nextReq, HttpCompletionOption.ResponseContentRead, ct).ConfigureAwait(false);
|
|
res = await nextResp.Content.ReadFromJsonAsync<RewriteResponse>(ct).ConfigureAwait(false);
|
|
}
|
|
}).ConfigureAwait(false);
|
|
|
|
// Delete old file
|
|
await DeleteAsync(oldname, cancellationToken).ConfigureAwait(false);
|
|
}
|
|
|
|
private class RewriteResponse
|
|
{
|
|
public bool done { get; set; }
|
|
public string? rewriteToken { get; set; }
|
|
}
|
|
public void Dispose()
|
|
{
|
|
}
|
|
}
|
|
}
|
|
|