|
| 1 | +// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. |
| 2 | +// SPDX-License-Identifier: Apache-2.0 |
| 3 | + |
| 4 | +package directinvoke |
| 5 | + |
| 6 | +import ( |
| 7 | + "fmt" |
| 8 | + "io" |
| 9 | + "net/http" |
| 10 | + |
| 11 | + "github.com/go-chi/chi" |
| 12 | + "go.amzn.com/lambda/interop" |
| 13 | + "go.amzn.com/lambda/metering" |
| 14 | +) |
| 15 | + |
| 16 | +const ( |
| 17 | + InvokeIDHeader = "Invoke-Id" |
| 18 | + InvokedFunctionArnHeader = "Invoked-Function-Arn" |
| 19 | + VersionIDHeader = "Invoked-Function-Version" |
| 20 | + ReservationTokenHeader = "Reservation-Token" |
| 21 | + CustomerHeadersHeader = "Customer-Headers" |
| 22 | + ContentTypeHeader = "Content-Type" |
| 23 | + |
| 24 | + ErrorTypeHeader = "Error-Type" |
| 25 | + |
| 26 | + EndOfResponseTrailer = "End-Of-Response" |
| 27 | + |
| 28 | + SandboxErrorType = "Error.Sandbox" |
| 29 | +) |
| 30 | + |
| 31 | +const ( |
| 32 | + EndOfResponseComplete = "Complete" |
| 33 | + EndOfResponseTruncated = "Truncated" |
| 34 | + EndOfResponseOversized = "Oversized" |
| 35 | +) |
| 36 | + |
| 37 | +var MaxDirectResponseSize int64 = interop.MaxPayloadSize // this is intentionally not a constant so we can configure it via CLI |
| 38 | + |
| 39 | +func renderBadRequest(w http.ResponseWriter, r *http.Request, errorType string) { |
| 40 | + w.Header().Set(ErrorTypeHeader, errorType) |
| 41 | + w.WriteHeader(http.StatusBadRequest) |
| 42 | + w.Header().Set(EndOfResponseTrailer, EndOfResponseComplete) |
| 43 | +} |
| 44 | + |
| 45 | +// ReceiveDirectInvoke parses invoke and verifies it against Token message. Uses deadline provided by Token |
| 46 | +// Renders BadRequest in case of error |
| 47 | +func ReceiveDirectInvoke(w http.ResponseWriter, r *http.Request, token interop.Token) (*interop.Invoke, error) { |
| 48 | + w.Header().Set("Trailer", EndOfResponseTrailer) |
| 49 | + |
| 50 | + custHeaders := CustomerHeaders{} |
| 51 | + if err := custHeaders.Load(r.Header.Get(CustomerHeadersHeader)); err != nil { |
| 52 | + renderBadRequest(w, r, interop.ErrMalformedCustomerHeaders.Error()) |
| 53 | + return nil, interop.ErrMalformedCustomerHeaders |
| 54 | + } |
| 55 | + |
| 56 | + now := metering.Monotime() |
| 57 | + inv := &interop.Invoke{ |
| 58 | + ID: r.Header.Get(InvokeIDHeader), |
| 59 | + ReservationToken: chi.URLParam(r, "reservationtoken"), |
| 60 | + InvokedFunctionArn: r.Header.Get(InvokedFunctionArnHeader), |
| 61 | + VersionID: r.Header.Get(VersionIDHeader), |
| 62 | + ContentType: r.Header.Get(ContentTypeHeader), |
| 63 | + CognitoIdentityID: custHeaders.CognitoIdentityID, |
| 64 | + CognitoIdentityPoolID: custHeaders.CognitoIdentityPoolID, |
| 65 | + TraceID: token.TraceID, |
| 66 | + LambdaSegmentID: token.LambdaSegmentID, |
| 67 | + ClientContext: custHeaders.ClientContext, |
| 68 | + Payload: r.Body, |
| 69 | + CorrelationID: "invokeCorrelationID", |
| 70 | + DeadlineNs: fmt.Sprintf("%d", now+token.FunctionTimeout.Nanoseconds()), |
| 71 | + NeedDebugLogs: token.NeedDebugLogs, |
| 72 | + InvokeReceivedTime: now, |
| 73 | + } |
| 74 | + |
| 75 | + if inv.ID != token.InvokeID { |
| 76 | + renderBadRequest(w, r, interop.ErrInvalidInvokeID.Error()) |
| 77 | + return nil, interop.ErrInvalidInvokeID |
| 78 | + } |
| 79 | + |
| 80 | + if inv.ReservationToken != token.ReservationToken { |
| 81 | + renderBadRequest(w, r, interop.ErrInvalidReservationToken.Error()) |
| 82 | + return nil, interop.ErrInvalidReservationToken |
| 83 | + } |
| 84 | + |
| 85 | + if inv.VersionID != token.VersionID { |
| 86 | + renderBadRequest(w, r, interop.ErrInvalidFunctionVersion.Error()) |
| 87 | + return nil, interop.ErrInvalidFunctionVersion |
| 88 | + } |
| 89 | + |
| 90 | + if now > token.InvackDeadlineNs { |
| 91 | + renderBadRequest(w, r, interop.ErrReservationExpired.Error()) |
| 92 | + return nil, interop.ErrReservationExpired |
| 93 | + } |
| 94 | + |
| 95 | + w.Header().Set(VersionIDHeader, token.VersionID) |
| 96 | + w.Header().Set(ReservationTokenHeader, token.ReservationToken) |
| 97 | + w.Header().Set(InvokeIDHeader, token.InvokeID) |
| 98 | + |
| 99 | + return inv, nil |
| 100 | +} |
| 101 | + |
| 102 | +func SendDirectInvokeResponse(additionalHeaders map[string]string, payload io.Reader, w http.ResponseWriter) error { |
| 103 | + for k, v := range additionalHeaders { |
| 104 | + w.Header().Add(k, v) |
| 105 | + } |
| 106 | + |
| 107 | + n, err := io.Copy(w, io.LimitReader(payload, MaxDirectResponseSize+1)) // +1 because we do allow 10MB but not 10MB + 1 byte |
| 108 | + if err != nil { |
| 109 | + w.Header().Set(EndOfResponseTrailer, EndOfResponseTruncated) |
| 110 | + } else if n == MaxDirectResponseSize+1 { |
| 111 | + w.Header().Set(EndOfResponseTrailer, EndOfResponseOversized) |
| 112 | + } else { |
| 113 | + w.Header().Set(EndOfResponseTrailer, EndOfResponseComplete) |
| 114 | + } |
| 115 | + return err |
| 116 | +} |
0 commit comments