uri_parser.js 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624
  1. 'use strict';
  2. const URL = require('url');
  3. const qs = require('querystring');
  4. const dns = require('dns');
  5. const MongoParseError = require('./error').MongoParseError;
  6. const ReadPreference = require('./topologies/read_preference');
  7. /**
  8. * The following regular expression validates a connection string and breaks the
  9. * provide string into the following capture groups: [protocol, username, password, hosts]
  10. */
  11. const HOSTS_RX = /(mongodb(?:\+srv|)):\/\/(?: (?:[^:]*) (?: : ([^@]*) )? @ )?([^/?]*)(?:\/|)(.*)/;
  12. /**
  13. * Determines whether a provided address matches the provided parent domain in order
  14. * to avoid certain attack vectors.
  15. *
  16. * @param {String} srvAddress The address to check against a domain
  17. * @param {String} parentDomain The domain to check the provided address against
  18. * @return {Boolean} Whether the provided address matches the parent domain
  19. */
  20. function matchesParentDomain(srvAddress, parentDomain) {
  21. const regex = /^.*?\./;
  22. const srv = `.${srvAddress.replace(regex, '')}`;
  23. const parent = `.${parentDomain.replace(regex, '')}`;
  24. return srv.endsWith(parent);
  25. }
  26. /**
  27. * Lookup a `mongodb+srv` connection string, combine the parts and reparse it as a normal
  28. * connection string.
  29. *
  30. * @param {string} uri The connection string to parse
  31. * @param {object} options Optional user provided connection string options
  32. * @param {function} callback
  33. */
  34. function parseSrvConnectionString(uri, options, callback) {
  35. const result = URL.parse(uri, true);
  36. if (result.hostname.split('.').length < 3) {
  37. return callback(new MongoParseError('URI does not have hostname, domain name and tld'));
  38. }
  39. result.domainLength = result.hostname.split('.').length;
  40. if (result.pathname && result.pathname.match(',')) {
  41. return callback(new MongoParseError('Invalid URI, cannot contain multiple hostnames'));
  42. }
  43. if (result.port) {
  44. return callback(new MongoParseError(`Ports not accepted with '${PROTOCOL_MONGODB_SRV}' URIs`));
  45. }
  46. // Resolve the SRV record and use the result as the list of hosts to connect to.
  47. const lookupAddress = result.host;
  48. dns.resolveSrv(`_mongodb._tcp.${lookupAddress}`, (err, addresses) => {
  49. if (err) return callback(err);
  50. if (addresses.length === 0) {
  51. return callback(new MongoParseError('No addresses found at host'));
  52. }
  53. for (let i = 0; i < addresses.length; i++) {
  54. if (!matchesParentDomain(addresses[i].name, result.hostname, result.domainLength)) {
  55. return callback(
  56. new MongoParseError('Server record does not share hostname with parent URI')
  57. );
  58. }
  59. }
  60. // Convert the original URL to a non-SRV URL.
  61. result.protocol = 'mongodb';
  62. result.host = addresses.map(address => `${address.name}:${address.port}`).join(',');
  63. // Default to SSL true if it's not specified.
  64. if (
  65. !('ssl' in options) &&
  66. (!result.search || !('ssl' in result.query) || result.query.ssl === null)
  67. ) {
  68. result.query.ssl = true;
  69. }
  70. // Resolve TXT record and add options from there if they exist.
  71. dns.resolveTxt(lookupAddress, (err, record) => {
  72. if (err) {
  73. if (err.code !== 'ENODATA') {
  74. return callback(err);
  75. }
  76. record = null;
  77. }
  78. if (record) {
  79. if (record.length > 1) {
  80. return callback(new MongoParseError('Multiple text records not allowed'));
  81. }
  82. record = qs.parse(record[0].join(''));
  83. if (Object.keys(record).some(key => key !== 'authSource' && key !== 'replicaSet')) {
  84. return callback(
  85. new MongoParseError('Text record must only set `authSource` or `replicaSet`')
  86. );
  87. }
  88. Object.assign(result.query, record);
  89. }
  90. // Set completed options back into the URL object.
  91. result.search = qs.stringify(result.query);
  92. const finalString = URL.format(result);
  93. parseConnectionString(finalString, options, callback);
  94. });
  95. });
  96. }
  97. /**
  98. * Parses a query string item according to the connection string spec
  99. *
  100. * @param {string} key The key for the parsed value
  101. * @param {Array|String} value The value to parse
  102. * @return {Array|Object|String} The parsed value
  103. */
  104. function parseQueryStringItemValue(key, value) {
  105. if (Array.isArray(value)) {
  106. // deduplicate and simplify arrays
  107. value = value.filter((v, idx) => value.indexOf(v) === idx);
  108. if (value.length === 1) value = value[0];
  109. } else if (value.indexOf(':') > 0) {
  110. value = value.split(',').reduce((result, pair) => {
  111. const parts = pair.split(':');
  112. result[parts[0]] = parseQueryStringItemValue(key, parts[1]);
  113. return result;
  114. }, {});
  115. } else if (value.indexOf(',') > 0) {
  116. value = value.split(',').map(v => {
  117. return parseQueryStringItemValue(key, v);
  118. });
  119. } else if (value.toLowerCase() === 'true' || value.toLowerCase() === 'false') {
  120. value = value.toLowerCase() === 'true';
  121. } else if (!Number.isNaN(value) && !STRING_OPTIONS.has(key)) {
  122. const numericValue = parseFloat(value);
  123. if (!Number.isNaN(numericValue)) {
  124. value = parseFloat(value);
  125. }
  126. }
  127. return value;
  128. }
  129. // Options that are known boolean types
  130. const BOOLEAN_OPTIONS = new Set([
  131. 'slaveok',
  132. 'slave_ok',
  133. 'sslvalidate',
  134. 'fsync',
  135. 'safe',
  136. 'retrywrites',
  137. 'j'
  138. ]);
  139. // Known string options, only used to bypass Number coercion in `parseQueryStringItemValue`
  140. const STRING_OPTIONS = new Set(['authsource', 'replicaset']);
  141. // Supported text representations of auth mechanisms
  142. // NOTE: this list exists in native already, if it is merged here we should deduplicate
  143. const AUTH_MECHANISMS = new Set([
  144. 'GSSAPI',
  145. 'MONGODB-X509',
  146. 'MONGODB-CR',
  147. 'DEFAULT',
  148. 'SCRAM-SHA-1',
  149. 'SCRAM-SHA-256',
  150. 'PLAIN'
  151. ]);
  152. // Lookup table used to translate normalized (lower-cased) forms of connection string
  153. // options to their expected camelCase version
  154. const CASE_TRANSLATION = {
  155. replicaset: 'replicaSet',
  156. connecttimeoutms: 'connectTimeoutMS',
  157. sockettimeoutms: 'socketTimeoutMS',
  158. maxpoolsize: 'maxPoolSize',
  159. minpoolsize: 'minPoolSize',
  160. maxidletimems: 'maxIdleTimeMS',
  161. waitqueuemultiple: 'waitQueueMultiple',
  162. waitqueuetimeoutms: 'waitQueueTimeoutMS',
  163. wtimeoutms: 'wtimeoutMS',
  164. readconcern: 'readConcern',
  165. readconcernlevel: 'readConcernLevel',
  166. readpreference: 'readPreference',
  167. maxstalenessseconds: 'maxStalenessSeconds',
  168. readpreferencetags: 'readPreferenceTags',
  169. authsource: 'authSource',
  170. authmechanism: 'authMechanism',
  171. authmechanismproperties: 'authMechanismProperties',
  172. gssapiservicename: 'gssapiServiceName',
  173. localthresholdms: 'localThresholdMS',
  174. serverselectiontimeoutms: 'serverSelectionTimeoutMS',
  175. serverselectiontryonce: 'serverSelectionTryOnce',
  176. heartbeatfrequencyms: 'heartbeatFrequencyMS',
  177. retrywrites: 'retryWrites',
  178. uuidrepresentation: 'uuidRepresentation',
  179. zlibcompressionlevel: 'zlibCompressionLevel',
  180. tlsallowinvalidcertificates: 'tlsAllowInvalidCertificates',
  181. tlsallowinvalidhostnames: 'tlsAllowInvalidHostnames',
  182. tlsinsecure: 'tlsInsecure',
  183. tlscafile: 'tlsCAFile',
  184. tlscertificatekeyfile: 'tlsCertificateKeyFile',
  185. tlscertificatekeyfilepassword: 'tlsCertificateKeyFilePassword',
  186. wtimeout: 'wTimeoutMS',
  187. j: 'journal'
  188. };
  189. /**
  190. * Sets the value for `key`, allowing for any required translation
  191. *
  192. * @param {object} obj The object to set the key on
  193. * @param {string} key The key to set the value for
  194. * @param {*} value The value to set
  195. * @param {object} options The options used for option parsing
  196. */
  197. function applyConnectionStringOption(obj, key, value, options) {
  198. // simple key translation
  199. if (key === 'journal') {
  200. key = 'j';
  201. } else if (key === 'wtimeoutms') {
  202. key = 'wtimeout';
  203. }
  204. // more complicated translation
  205. if (BOOLEAN_OPTIONS.has(key)) {
  206. value = value === 'true' || value === true;
  207. } else if (key === 'appname') {
  208. value = decodeURIComponent(value);
  209. } else if (key === 'readconcernlevel') {
  210. obj['readConcernLevel'] = value;
  211. key = 'readconcern';
  212. value = { level: value };
  213. }
  214. // simple validation
  215. if (key === 'compressors') {
  216. value = Array.isArray(value) ? value : [value];
  217. if (!value.every(c => c === 'snappy' || c === 'zlib')) {
  218. throw new MongoParseError(
  219. 'Value for `compressors` must be at least one of: `snappy`, `zlib`'
  220. );
  221. }
  222. }
  223. if (key === 'authmechanism' && !AUTH_MECHANISMS.has(value)) {
  224. throw new MongoParseError(
  225. 'Value for `authMechanism` must be one of: `DEFAULT`, `GSSAPI`, `PLAIN`, `MONGODB-X509`, `SCRAM-SHA-1`, `SCRAM-SHA-256`'
  226. );
  227. }
  228. if (key === 'readpreference' && !ReadPreference.isValid(value)) {
  229. throw new MongoParseError(
  230. 'Value for `readPreference` must be one of: `primary`, `primaryPreferred`, `secondary`, `secondaryPreferred`, `nearest`'
  231. );
  232. }
  233. if (key === 'zlibcompressionlevel' && (value < -1 || value > 9)) {
  234. throw new MongoParseError('zlibCompressionLevel must be an integer between -1 and 9');
  235. }
  236. // special cases
  237. if (key === 'compressors' || key === 'zlibcompressionlevel') {
  238. obj.compression = obj.compression || {};
  239. obj = obj.compression;
  240. }
  241. if (key === 'authmechanismproperties') {
  242. if (typeof value.SERVICE_NAME === 'string') obj.gssapiServiceName = value.SERVICE_NAME;
  243. if (typeof value.SERVICE_REALM === 'string') obj.gssapiServiceRealm = value.SERVICE_REALM;
  244. if (typeof value.CANONICALIZE_HOST_NAME !== 'undefined') {
  245. obj.gssapiCanonicalizeHostName = value.CANONICALIZE_HOST_NAME;
  246. }
  247. }
  248. if (key === 'readpreferencetags' && Array.isArray(value)) {
  249. value = splitArrayOfMultipleReadPreferenceTags(value);
  250. }
  251. // set the actual value
  252. if (options.caseTranslate && CASE_TRANSLATION[key]) {
  253. obj[CASE_TRANSLATION[key]] = value;
  254. return;
  255. }
  256. obj[key] = value;
  257. }
  258. const USERNAME_REQUIRED_MECHANISMS = new Set([
  259. 'GSSAPI',
  260. 'MONGODB-CR',
  261. 'PLAIN',
  262. 'SCRAM-SHA-1',
  263. 'SCRAM-SHA-256'
  264. ]);
  265. function splitArrayOfMultipleReadPreferenceTags(value) {
  266. const parsedTags = [];
  267. for (let i = 0; i < value.length; i++) {
  268. parsedTags[i] = {};
  269. value[i].split(',').forEach(individualTag => {
  270. const splitTag = individualTag.split(':');
  271. parsedTags[i][splitTag[0]] = splitTag[1];
  272. });
  273. }
  274. return parsedTags;
  275. }
  276. /**
  277. * Modifies the parsed connection string object taking into account expectations we
  278. * have for authentication-related options.
  279. *
  280. * @param {object} parsed The parsed connection string result
  281. * @return The parsed connection string result possibly modified for auth expectations
  282. */
  283. function applyAuthExpectations(parsed) {
  284. if (parsed.options == null) {
  285. return;
  286. }
  287. const options = parsed.options;
  288. const authSource = options.authsource || options.authSource;
  289. if (authSource != null) {
  290. parsed.auth = Object.assign({}, parsed.auth, { db: authSource });
  291. }
  292. const authMechanism = options.authmechanism || options.authMechanism;
  293. if (authMechanism != null) {
  294. if (
  295. USERNAME_REQUIRED_MECHANISMS.has(authMechanism) &&
  296. (!parsed.auth || parsed.auth.username == null)
  297. ) {
  298. throw new MongoParseError(`Username required for mechanism \`${authMechanism}\``);
  299. }
  300. if (authMechanism === 'GSSAPI') {
  301. if (authSource != null && authSource !== '$external') {
  302. throw new MongoParseError(
  303. `Invalid source \`${authSource}\` for mechanism \`${authMechanism}\` specified.`
  304. );
  305. }
  306. parsed.auth = Object.assign({}, parsed.auth, { db: '$external' });
  307. }
  308. if (authMechanism === 'MONGODB-X509') {
  309. if (parsed.auth && parsed.auth.password != null) {
  310. throw new MongoParseError(`Password not allowed for mechanism \`${authMechanism}\``);
  311. }
  312. if (authSource != null && authSource !== '$external') {
  313. throw new MongoParseError(
  314. `Invalid source \`${authSource}\` for mechanism \`${authMechanism}\` specified.`
  315. );
  316. }
  317. parsed.auth = Object.assign({}, parsed.auth, { db: '$external' });
  318. }
  319. if (authMechanism === 'PLAIN') {
  320. if (parsed.auth && parsed.auth.db == null) {
  321. parsed.auth = Object.assign({}, parsed.auth, { db: '$external' });
  322. }
  323. }
  324. }
  325. // default to `admin` if nothing else was resolved
  326. if (parsed.auth && parsed.auth.db == null) {
  327. parsed.auth = Object.assign({}, parsed.auth, { db: 'admin' });
  328. }
  329. return parsed;
  330. }
  331. /**
  332. * Parses a query string according the connection string spec.
  333. *
  334. * @param {String} query The query string to parse
  335. * @param {object} [options] The options used for options parsing
  336. * @return {Object|Error} The parsed query string as an object, or an error if one was encountered
  337. */
  338. function parseQueryString(query, options) {
  339. const result = {};
  340. let parsedQueryString = qs.parse(query);
  341. checkTLSOptions(parsedQueryString);
  342. for (const key in parsedQueryString) {
  343. const value = parsedQueryString[key];
  344. if (value === '' || value == null) {
  345. throw new MongoParseError('Incomplete key value pair for option');
  346. }
  347. const normalizedKey = key.toLowerCase();
  348. const parsedValue = parseQueryStringItemValue(normalizedKey, value);
  349. applyConnectionStringOption(result, normalizedKey, parsedValue, options);
  350. }
  351. // special cases for known deprecated options
  352. if (result.wtimeout && result.wtimeoutms) {
  353. delete result.wtimeout;
  354. console.warn('Unsupported option `wtimeout` specified');
  355. }
  356. return Object.keys(result).length ? result : null;
  357. }
  358. /**
  359. * Checks a query string for invalid tls options according to the URI options spec.
  360. *
  361. * @param {string} queryString The query string to check
  362. * @throws {MongoParseError}
  363. */
  364. function checkTLSOptions(queryString) {
  365. const queryStringKeys = Object.keys(queryString);
  366. if (
  367. queryStringKeys.indexOf('tlsInsecure') !== -1 &&
  368. (queryStringKeys.indexOf('tlsAllowInvalidCertificates') !== -1 ||
  369. queryStringKeys.indexOf('tlsAllowInvalidHostnames') !== -1)
  370. ) {
  371. throw new MongoParseError(
  372. 'The `tlsInsecure` option cannot be used with `tlsAllowInvalidCertificates` or `tlsAllowInvalidHostnames`.'
  373. );
  374. }
  375. const tlsValue = assertTlsOptionsAreEqual('tls', queryString, queryStringKeys);
  376. const sslValue = assertTlsOptionsAreEqual('ssl', queryString, queryStringKeys);
  377. if (tlsValue != null && sslValue != null) {
  378. if (tlsValue !== sslValue) {
  379. throw new MongoParseError('All values of `tls` and `ssl` must be the same.');
  380. }
  381. }
  382. }
  383. /**
  384. * Checks a query string to ensure all tls/ssl options are the same.
  385. *
  386. * @param {string} key The key (tls or ssl) to check
  387. * @param {string} queryString The query string to check
  388. * @throws {MongoParseError}
  389. * @return The value of the tls/ssl option
  390. */
  391. function assertTlsOptionsAreEqual(optionName, queryString, queryStringKeys) {
  392. const queryStringHasTLSOption = queryStringKeys.indexOf(optionName) !== -1;
  393. let optionValue;
  394. if (Array.isArray(queryString[optionName])) {
  395. optionValue = queryString[optionName][0];
  396. } else {
  397. optionValue = queryString[optionName];
  398. }
  399. if (queryStringHasTLSOption) {
  400. if (Array.isArray(queryString[optionName])) {
  401. const firstValue = queryString[optionName][0];
  402. queryString[optionName].forEach(tlsValue => {
  403. if (tlsValue !== firstValue) {
  404. throw new MongoParseError('All values of ${optionName} must be the same.');
  405. }
  406. });
  407. }
  408. }
  409. return optionValue;
  410. }
  411. const PROTOCOL_MONGODB = 'mongodb';
  412. const PROTOCOL_MONGODB_SRV = 'mongodb+srv';
  413. const SUPPORTED_PROTOCOLS = [PROTOCOL_MONGODB, PROTOCOL_MONGODB_SRV];
  414. /**
  415. * Parses a MongoDB connection string
  416. *
  417. * @param {*} uri the MongoDB connection string to parse
  418. * @param {object} [options] Optional settings.
  419. * @param {boolean} [options.caseTranslate] Whether the parser should translate options back into camelCase after normalization
  420. * @param {parseCallback} callback
  421. */
  422. function parseConnectionString(uri, options, callback) {
  423. if (typeof options === 'function') (callback = options), (options = {});
  424. options = Object.assign({}, { caseTranslate: true }, options);
  425. // Check for bad uris before we parse
  426. try {
  427. URL.parse(uri);
  428. } catch (e) {
  429. return callback(new MongoParseError('URI malformed, cannot be parsed'));
  430. }
  431. const cap = uri.match(HOSTS_RX);
  432. if (!cap) {
  433. return callback(new MongoParseError('Invalid connection string'));
  434. }
  435. const protocol = cap[1];
  436. if (SUPPORTED_PROTOCOLS.indexOf(protocol) === -1) {
  437. return callback(new MongoParseError('Invalid protocol provided'));
  438. }
  439. if (protocol === PROTOCOL_MONGODB_SRV) {
  440. return parseSrvConnectionString(uri, options, callback);
  441. }
  442. const dbAndQuery = cap[4].split('?');
  443. const db = dbAndQuery.length > 0 ? dbAndQuery[0] : null;
  444. const query = dbAndQuery.length > 1 ? dbAndQuery[1] : null;
  445. let parsedOptions;
  446. try {
  447. parsedOptions = parseQueryString(query, options);
  448. } catch (parseError) {
  449. return callback(parseError);
  450. }
  451. parsedOptions = Object.assign({}, parsedOptions, options);
  452. const auth = { username: null, password: null, db: db && db !== '' ? qs.unescape(db) : null };
  453. if (parsedOptions.auth) {
  454. // maintain support for legacy options passed into `MongoClient`
  455. if (parsedOptions.auth.username) auth.username = parsedOptions.auth.username;
  456. if (parsedOptions.auth.user) auth.username = parsedOptions.auth.user;
  457. if (parsedOptions.auth.password) auth.password = parsedOptions.auth.password;
  458. }
  459. if (cap[4].split('?')[0].indexOf('@') !== -1) {
  460. return callback(new MongoParseError('Unescaped slash in userinfo section'));
  461. }
  462. const authorityParts = cap[3].split('@');
  463. if (authorityParts.length > 2) {
  464. return callback(new MongoParseError('Unescaped at-sign in authority section'));
  465. }
  466. if (authorityParts.length > 1) {
  467. const authParts = authorityParts.shift().split(':');
  468. if (authParts.length > 2) {
  469. return callback(new MongoParseError('Unescaped colon in authority section'));
  470. }
  471. auth.username = qs.unescape(authParts[0]);
  472. auth.password = authParts[1] ? qs.unescape(authParts[1]) : null;
  473. }
  474. let hostParsingError = null;
  475. const hosts = authorityParts
  476. .shift()
  477. .split(',')
  478. .map(host => {
  479. let parsedHost = URL.parse(`mongodb://${host}`);
  480. if (parsedHost.path === '/:') {
  481. hostParsingError = new MongoParseError('Double colon in host identifier');
  482. return null;
  483. }
  484. // heuristically determine if we're working with a domain socket
  485. if (host.match(/\.sock/)) {
  486. parsedHost.hostname = qs.unescape(host);
  487. parsedHost.port = null;
  488. }
  489. if (Number.isNaN(parsedHost.port)) {
  490. hostParsingError = new MongoParseError('Invalid port (non-numeric string)');
  491. return;
  492. }
  493. const result = {
  494. host: parsedHost.hostname,
  495. port: parsedHost.port ? parseInt(parsedHost.port) : 27017
  496. };
  497. if (result.port === 0) {
  498. hostParsingError = new MongoParseError('Invalid port (zero) with hostname');
  499. return;
  500. }
  501. if (result.port > 65535) {
  502. hostParsingError = new MongoParseError('Invalid port (larger than 65535) with hostname');
  503. return;
  504. }
  505. if (result.port < 0) {
  506. hostParsingError = new MongoParseError('Invalid port (negative number)');
  507. return;
  508. }
  509. return result;
  510. })
  511. .filter(host => !!host);
  512. if (hostParsingError) {
  513. return callback(hostParsingError);
  514. }
  515. if (hosts.length === 0 || hosts[0].host === '' || hosts[0].host === null) {
  516. return callback(new MongoParseError('No hostname or hostnames provided in connection string'));
  517. }
  518. const result = {
  519. hosts: hosts,
  520. auth: auth.db || auth.username ? auth : null,
  521. options: Object.keys(parsedOptions).length ? parsedOptions : null
  522. };
  523. if (result.auth && result.auth.db) {
  524. result.defaultDatabase = result.auth.db;
  525. }
  526. try {
  527. applyAuthExpectations(result);
  528. } catch (authError) {
  529. return callback(authError);
  530. }
  531. callback(null, result);
  532. }
  533. module.exports = parseConnectionString;