mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-01 20:59:45 +09:00
51b93d1d27
Aligns the npm registry with what npm, pnpm and yarn expect: 1. Raise the publish body cap from https://github.com/go-gitea/gitea/pull/37890 to 256 MiB like npmjs, larger bodies get 413 2. Pick the tarball attachment by name, `npm publish --provenance` failed at random 3. Store and serve `libc`, so mismatched glibc/musl optional binaries are skipped 4. Treat root `*.gyp` files as an install script, like npm does 5. Always serve a `latest` dist-tag, yarn and pnpm fail without it 6. Take top-level metadata from `latest` and drop the per-version readme 7. Serve tarballs at the npmjs path `/<name>/-/<file>`, former URLs keep working 8. Add ETag revalidation for metadata, `npm ping` and `npm whoami` Tested with npm 12.1, pnpm 12.4, yarn 1.22 and yarn 4.18. --------- Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
155 lines
5.3 KiB
Go
155 lines
5.3 KiB
Go
// Copyright 2021 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package npm
|
|
|
|
import (
|
|
"context"
|
|
"encoding/base64"
|
|
"encoding/hex"
|
|
"fmt"
|
|
"slices"
|
|
"sort"
|
|
"time"
|
|
|
|
packages_model "gitea.dev/models/packages"
|
|
npm_module "gitea.dev/modules/packages/npm"
|
|
)
|
|
|
|
func createPackageMetadataResponse(registryURL string, pds []*packages_model.PackageDescriptor) *npm_module.PackageMetadata {
|
|
sort.Slice(pds, func(i, j int) bool {
|
|
return pds[i].SemVer.LessThan(pds[j].SemVer)
|
|
})
|
|
|
|
versions := make(map[string]*npm_module.PackageMetadataVersion)
|
|
distTags := make(map[string]string)
|
|
times := make(map[string]time.Time)
|
|
firstPublished, lastPublished := pds[0].Version.CreatedUnix, pds[0].Version.CreatedUnix
|
|
var latest *packages_model.PackageDescriptor
|
|
for _, pd := range pds {
|
|
semVer := pd.SemVer.String()
|
|
versions[semVer] = createPackageMetadataVersion(registryURL, pd)
|
|
times[semVer] = pd.Version.CreatedUnix.AsTimeInLocation(time.UTC)
|
|
firstPublished = min(firstPublished, pd.Version.CreatedUnix)
|
|
lastPublished = max(lastPublished, pd.Version.CreatedUnix)
|
|
|
|
for _, pvp := range pd.VersionProperties {
|
|
if pvp.Name == npm_module.TagProperty {
|
|
distTags[pvp.Value] = pd.Version.Version
|
|
if pvp.Value == "latest" {
|
|
latest = pd
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
// npm derives both from the versions currently served, so a deletion moves them
|
|
times["created"] = firstPublished.AsTimeInLocation(time.UTC)
|
|
times["modified"] = lastPublished.AsTimeInLocation(time.UTC)
|
|
|
|
if latest == nil { // yarn and pnpm fail without it, e.g. after its version got deleted
|
|
latest = pds[len(pds)-1]
|
|
for _, pd := range slices.Backward(pds) {
|
|
if pd.SemVer.Prerelease() == "" {
|
|
latest = pd
|
|
break
|
|
}
|
|
}
|
|
distTags["latest"] = latest.Version.Version
|
|
}
|
|
|
|
metadata := packages_model.DescriptorMetadata[*npm_module.Metadata](latest)
|
|
|
|
return &npm_module.PackageMetadata{
|
|
ID: latest.Package.Name,
|
|
Name: latest.Package.Name,
|
|
DistTags: distTags,
|
|
Description: metadata.Description,
|
|
Readme: metadata.Readme,
|
|
Maintainers: []npm_module.User{{Name: latest.Owner.Name}},
|
|
Time: times,
|
|
Homepage: metadata.ProjectURL,
|
|
Keywords: metadata.Keywords,
|
|
Author: npm_module.User{Name: metadata.Author},
|
|
License: metadata.License,
|
|
Versions: versions,
|
|
Repository: metadata.Repository,
|
|
}
|
|
}
|
|
|
|
func createPackageMetadataVersion(registryURL string, pd *packages_model.PackageDescriptor) *npm_module.PackageMetadataVersion {
|
|
hashBytes, _ := hex.DecodeString(pd.Files[0].Blob.HashSHA512)
|
|
|
|
metadata := packages_model.DescriptorMetadata[*npm_module.Metadata](pd)
|
|
|
|
return &npm_module.PackageMetadataVersion{
|
|
ID: fmt.Sprintf("%s@%s", pd.Package.Name, pd.Version.Version),
|
|
Name: pd.Package.Name,
|
|
Version: pd.Version.Version,
|
|
Description: metadata.Description,
|
|
Author: npm_module.User{Name: metadata.Author},
|
|
Maintainers: []npm_module.User{{Name: pd.Owner.Name}},
|
|
Homepage: metadata.ProjectURL,
|
|
License: metadata.License,
|
|
Repository: metadata.Repository,
|
|
Keywords: metadata.Keywords,
|
|
Dependencies: metadata.Dependencies,
|
|
BundleDependencies: metadata.BundleDependencies,
|
|
DevDependencies: metadata.DevelopmentDependencies,
|
|
PeerDependencies: metadata.PeerDependencies,
|
|
PeerDependenciesMeta: metadata.PeerDependenciesMeta,
|
|
OptionalDependencies: metadata.OptionalDependencies,
|
|
Bin: metadata.Bin,
|
|
HasInstallScript: metadata.HasInstallScript,
|
|
HasShrinkwrap: metadata.HasShrinkwrap,
|
|
Engines: metadata.Engines,
|
|
CPU: metadata.CPU,
|
|
OS: metadata.OS,
|
|
Libc: metadata.Libc,
|
|
Directories: metadata.Directories,
|
|
Funding: metadata.Funding,
|
|
AcceptDependencies: metadata.AcceptDependencies,
|
|
Deprecated: metadata.Deprecated,
|
|
Dist: npm_module.PackageDistribution{
|
|
Shasum: pd.Files[0].Blob.HashSHA1,
|
|
Integrity: "sha512-" + base64.StdEncoding.EncodeToString(hashBytes),
|
|
Tarball: fmt.Sprintf("%s/%s/-/%s", registryURL, pd.Package.Name, pd.Files[0].File.LowerName), // npmjs shape, which npm parses for allowScripts and yarn keeps registry-relative
|
|
},
|
|
}
|
|
}
|
|
|
|
func createPackageSearchResponse(ctx context.Context, pds []*packages_model.PackageDescriptor, total int64) *npm_module.PackageSearch {
|
|
objects := make([]*npm_module.PackageSearchObject, 0, len(pds))
|
|
for _, pd := range pds {
|
|
metadata := packages_model.DescriptorMetadata[*npm_module.Metadata](pd)
|
|
|
|
scope := metadata.Scope
|
|
if scope == "" {
|
|
scope = "unscoped"
|
|
}
|
|
|
|
objects = append(objects, &npm_module.PackageSearchObject{
|
|
Package: &npm_module.PackageSearchPackage{
|
|
Scope: scope,
|
|
Name: metadata.Name,
|
|
Version: pd.Version.Version,
|
|
Date: pd.Version.CreatedUnix.AsLocalTime(),
|
|
Description: metadata.Description,
|
|
Author: npm_module.User{Name: metadata.Author},
|
|
Publisher: npm_module.User{Name: pd.Owner.Name},
|
|
Maintainers: []npm_module.User{}, // npm cli needs this field
|
|
Keywords: metadata.Keywords,
|
|
Links: &npm_module.PackageSearchPackageLinks{
|
|
Registry: buildNpmRegistryURL(ctx, pd.Owner),
|
|
Homepage: metadata.ProjectURL,
|
|
},
|
|
},
|
|
})
|
|
}
|
|
|
|
return &npm_module.PackageSearch{
|
|
Objects: objects,
|
|
Total: total,
|
|
}
|
|
}
|