httpbased.py 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229
  1. """
  2. 本模块提供基于Http轮训的后端通用类和函数
  3. .. attention::
  4. PyWebIO 的会话状态保存在进程内,所以不支持多进程部署的后端服务
  5. 比如使用 ``uWSGI`` 部署后端服务,并使用 ``--processes n`` 选项设置了多进程;
  6. 或者使用 ``nginx`` 等反向代理将流量负载到多个后端副本上。
  7. A note on run backend server with uWSGI:
  8. If you start uWSGI without threads, the Python GIL will not be enabled,
  9. so threads generated by your application will never run.
  10. `uWSGI doc <https://uwsgi-docs.readthedocs.io/en/latest/WSGIquickstart.html#a-note-on-python-threads>`_
  11. """
  12. import asyncio
  13. import fnmatch
  14. import logging
  15. import threading
  16. from typing import Dict
  17. import time
  18. from ..session import CoroutineBasedSession, AbstractSession, register_session_implement_for_target
  19. from ..session.base import get_session_info_from_headers
  20. from ..utils import random_str, LRUDict
  21. class HttpContext:
  22. """一次Http请求的上下文, 不同的后端框架需要根据框架提供的方法实现本类的方法"""
  23. def request_method(self):
  24. """返回当前请求的方法,大写"""
  25. pass
  26. def request_headers(self):
  27. """返回当前请求的header字典"""
  28. pass
  29. def request_url_parameter(self, name, default=None):
  30. """返回当前请求的URL参数"""
  31. pass
  32. def request_json(self):
  33. """返回当前请求的json反序列化后的内容,若请求数据不为json格式,返回None"""
  34. pass
  35. def set_header(self, name, value):
  36. """为当前响应设置header"""
  37. pass
  38. def set_status(self, status):
  39. """为当前响应设置http status"""
  40. pass
  41. def set_content(self, content, json_type=False):
  42. """设置响应的内容。方法应该仅被调用一次
  43. :param content:
  44. :param bool json_type: content是否要序列化成json格式,并将 content-type 设置为application/json
  45. """
  46. pass
  47. def get_response(self):
  48. """获取当前的响应对象,用于在私图函数中返回"""
  49. logger = logging.getLogger(__name__)
  50. _event_loop = None
  51. # todo: use lock to avoid thread race condition
  52. class HttpHandler:
  53. # type: Dict[str, AbstractSession]
  54. _webio_sessions = {} # WebIOSessionID -> WebIOSession()
  55. _webio_expire = LRUDict() # WebIOSessionID -> last active timestamp。按照最后活跃时间递增排列
  56. _last_check_session_expire_ts = 0 # 上次检查session有效期的时间戳
  57. DEFAULT_SESSION_EXPIRE_SECONDS = 60 # 超过60s会话不活跃则视为会话过期
  58. SESSIONS_CLEANUP_INTERVAL = 20 # 清理过期会话间隔(秒)
  59. WAIT_MS_ON_POST = 100 # 在处理完POST请求时,等待WAIT_MS_ON_POST毫秒再读取返回数据。Task的command可以立即返回
  60. @classmethod
  61. def _remove_expired_sessions(cls, session_expire_seconds):
  62. logger.debug("removing expired sessions")
  63. """清除当前会话列表中的过期会话"""
  64. while cls._webio_expire:
  65. sid, active_ts = cls._webio_expire.popitem(last=False)
  66. if time.time() - active_ts < session_expire_seconds:
  67. # 当前session未过期
  68. cls._webio_expire[sid] = active_ts
  69. cls._webio_expire.move_to_end(sid, last=False)
  70. break
  71. # 清理session
  72. logger.debug("session %s expired" % sid)
  73. session = cls._webio_sessions.get(sid)
  74. if session:
  75. session.close()
  76. del cls._webio_sessions[sid]
  77. @classmethod
  78. def _remove_webio_session(cls, sid):
  79. cls._webio_sessions.pop(sid, None)
  80. cls._webio_expire.pop(sid, None)
  81. def _process_cors(self, context: HttpContext):
  82. """处理跨域请求:检查请求来源并根据可访问性设置headers"""
  83. origin = context.request_headers().get('Origin', '')
  84. if self.check_origin(origin):
  85. context.set_header('Access-Control-Allow-Origin', origin)
  86. context.set_header('Access-Control-Allow-Methods', 'GET, POST')
  87. context.set_header('Access-Control-Allow-Headers', 'content-type, webio-session-id')
  88. context.set_header('Access-Control-Expose-Headers', 'webio-session-id')
  89. context.set_header('Access-Control-Max-Age', str(1440 * 60))
  90. def handle_request(self, context: HttpContext):
  91. """处理请求"""
  92. cls = type(self)
  93. if _event_loop:
  94. asyncio.set_event_loop(_event_loop)
  95. request_headers = context.request_headers()
  96. if context.request_method() == 'OPTIONS': # preflight request for CORS
  97. self._process_cors(context)
  98. context.set_status(204)
  99. return context.get_response()
  100. if request_headers.get('Origin'): # set headers for CORS request
  101. self._process_cors(context)
  102. if context.request_url_parameter('test'): # 测试接口,当会话使用给予http的backend时,返回 ok
  103. context.set_content('ok')
  104. return context.get_response()
  105. webio_session_id = None
  106. # webio-session-id 的请求头为空时,创建新 Session
  107. if 'webio-session-id' not in request_headers or not request_headers['webio-session-id']:
  108. if context.request_method() == 'POST': # 不能在POST请求中创建Session,防止CSRF攻击
  109. context.set_status(403)
  110. return context.get_response()
  111. webio_session_id = random_str(24)
  112. context.set_header('webio-session-id', webio_session_id)
  113. session_info = get_session_info_from_headers(context.request_headers())
  114. webio_session = self.session_cls(self.target, session_info=session_info)
  115. cls._webio_sessions[webio_session_id] = webio_session
  116. elif request_headers['webio-session-id'] not in cls._webio_sessions: # WebIOSession deleted
  117. context.set_content([dict(command='close_session')], json_type=True)
  118. return context.get_response()
  119. else:
  120. webio_session_id = request_headers['webio-session-id']
  121. webio_session = cls._webio_sessions[webio_session_id]
  122. if context.request_method() == 'POST': # client push event
  123. if context.request_json() is not None:
  124. webio_session.send_client_event(context.request_json())
  125. time.sleep(cls.WAIT_MS_ON_POST / 1000.0)
  126. elif context.request_method() == 'GET': # client pull messages
  127. pass
  128. cls._webio_expire[webio_session_id] = time.time()
  129. # clean up at intervals
  130. if time.time() - cls._last_check_session_expire_ts > self.session_cleanup_interval:
  131. cls._last_check_session_expire_ts = time.time()
  132. self._remove_expired_sessions(self.session_expire_seconds)
  133. context.set_content(webio_session.get_task_commands(), json_type=True)
  134. if webio_session.closed():
  135. self._remove_webio_session(webio_session_id)
  136. return context.get_response()
  137. def __init__(self, target, session_cls,
  138. session_expire_seconds=None,
  139. session_cleanup_interval=None,
  140. allowed_origins=None, check_origin=None):
  141. """获取用于与后端实现进行整合的view函数,基于http请求与前端进行通讯
  142. :param target: 任务函数。任务函数为协程函数时,使用 :ref:`基于协程的会话实现 <coroutine_based_session>` ;任务函数为普通函数时,使用基于线程的会话实现。
  143. :param int session_expire_seconds: 会话不活跃过期时间。
  144. :param int session_cleanup_interval: 会话清理间隔。
  145. :param list allowed_origins: 除当前域名外,服务器还允许的请求的来源列表。
  146. 来源包含协议和域名和端口部分,允许使用 Unix shell 风格的匹配模式:
  147. - ``*`` 为通配符
  148. - ``?`` 匹配单个字符
  149. - ``[seq]`` 匹配seq内的字符
  150. - ``[!seq]`` 匹配不在seq内的字符
  151. 比如 ``https://*.example.com`` 、 ``*://*.example.com``
  152. :param callable check_origin: 请求来源检查函数。接收请求来源(包含协议和域名和端口部分)字符串,
  153. 返回 ``True/False`` 。若设置了 ``check_origin`` , ``allowed_origins`` 参数将被忽略
  154. """
  155. cls = type(self)
  156. self.target = target
  157. self.session_cls = session_cls
  158. self.check_origin = check_origin
  159. self.session_expire_seconds = session_expire_seconds or cls.DEFAULT_SESSION_EXPIRE_SECONDS
  160. self.session_cleanup_interval = session_cleanup_interval or cls.SESSIONS_CLEANUP_INTERVAL
  161. if check_origin is None:
  162. self.check_origin = lambda origin: any(
  163. fnmatch.fnmatch(origin, patten)
  164. for patten in allowed_origins or []
  165. )
  166. def run_event_loop(debug=False):
  167. """运行事件循环
  168. 基于协程的会话在启动基于线程的http服务器之前需要启动一个单独的线程来运行事件循环。
  169. :param debug: Set the debug mode of the event loop.
  170. See also: https://docs.python.org/3/library/asyncio-dev.html#asyncio-debug-mode
  171. """
  172. global _event_loop
  173. CoroutineBasedSession.event_loop_thread_id = threading.current_thread().ident
  174. _event_loop = asyncio.new_event_loop()
  175. _event_loop.set_debug(debug)
  176. asyncio.set_event_loop(_event_loop)
  177. _event_loop.run_forever()