Sunshine latest
Self-hosted game stream host for Moonlight.
confighttp.h File Reference

Declarations for the Web UI Config HTTP server. More...

#include <filesystem>
#include <functional>
#include <memory>
#include <string>
#include <string_view>
#include <libvirtualhid/license.hpp>
#include <nlohmann/json.hpp>
#include <Simple-Web-Server/server_https.hpp>
#include "thread_safe.h"
Include dependency graph for confighttp.h:
This graph shows which files directly or indirectly include this file:

Go to the source code of this file.

Macros

#define WEB_DIR   SUNSHINE_ASSETS_DIR "/web/"
 Macro for WEB DIR.

Functions

bool confighttp::authenticate (const resp_https_t &response, const req_https_t &request)
 Authenticate the user.
void confighttp::bad_request (const resp_https_t &response, const req_https_t &request, const std::string &error_message)
 Send a 400 Bad Request response.
void confighttp::browseDirectory (const resp_https_t &response, const req_https_t &request)
 Browse the server filesystem.
nlohmann::json confighttp::build_browse_entries (const std::filesystem::path &dir_path, const std::string &type_str)
 Lists, filters, and sorts the entries of a directory for the browse API.
nlohmann::json confighttp::build_driver_status (bool installed, const std::string &version, std::string_view minimum_version)
 Build a standard driver status response.
nlohmann::json confighttp::build_virtualhid_license_status (const lvh::LicenseResult &result)
 Convert a libvirtualhid license result into a Web UI response.
void confighttp::cancelPairing (const resp_https_t &response, const req_https_t &request)
 Cancel a client pairing request that is waiting for PIN approval. The body for the delete request should be JSON serialized in the following format:
bool confighttp::check_app_index (const resp_https_t &response, const req_https_t &request, int index)
 Validates the application index and sends an error response if invalid.
bool confighttp::check_content_type (const resp_https_t &response, const req_https_t &request, const std::string_view &contentType)
 Validate the request content type and send a bad request when mismatched.
std::string confighttp::generate_csrf_token (const std::string &client_id)
 Generate a new CSRF token for a client.
std::string confighttp::get_client_id (const req_https_t &request)
 Get a unique client identifier for CSRF token management.
nlohmann::json confighttp::get_vigembus_driver_status ()
 Build ViGEmBus fallback driver version and installation status.
nlohmann::json confighttp::get_virtualhid_driver_status ()
 Build libvirtualhid driver version and installation status.
nlohmann::json confighttp::get_windows_drives ()
 Builds a JSON array of available Windows drive letters.
void confighttp::getAsset (const resp_https_t &response, const req_https_t &request)
 Get an asset.
void confighttp::getCSRFToken (const resp_https_t &response, const req_https_t &request)
 Get a CSRF token for the authenticated user.
void confighttp::getLocale (const resp_https_t &response, const req_https_t &request)
 Get the locale setting. This endpoint does not require authentication.
void confighttp::getPage (const resp_https_t &response, const req_https_t &request, const char *html_file, const bool require_auth, const bool redirect_if_username)
 Get an HTML page.
void confighttp::getPendingPairings (const resp_https_t &response, const req_https_t &request)
 List client pairing requests that are waiting for PIN approval.
void confighttp::getVirtualInputLicense (const resp_https_t &response, const req_https_t &request)
 Get the current libvirtualhid machine license status.
void confighttp::getVirtualInputStatus (const resp_https_t &response, const req_https_t &request)
 Get virtual input driver version and installation status.
bool confighttp::is_browsable_executable (const std::filesystem::directory_entry &entry, const std::filesystem::file_status &status)
 Checks whether a directory entry qualifies as an executable file.
bool confighttp::is_driver_version_development (std::string_view version)
 Check whether a detected driver version identifies a development build.
bool confighttp::is_driver_version_supported (std::string_view version, std::string_view minimum_version)
 Check whether a detected driver version satisfies a minimum version.
void confighttp::not_found (const resp_https_t &response, const req_https_t &request, const std::string &error_message)
 Send a 404 Not Found response.
void confighttp::print_req (const req_https_t &request)
 Log the request details.
void confighttp::resetPortalToken (const resp_https_t &response, const req_https_t &request)
 Authenticate a Web UI request and delete the saved XDG Portal restore token.
void confighttp::savePin (const resp_https_t &response, const req_https_t &request)
 Submit a PIN and return whether the selected client completes pairing.
void confighttp::send_redirect (const resp_https_t &response, const req_https_t &request, const char *path)
 Send a redirect response.
void confighttp::send_response (const resp_https_t &response, const nlohmann::json &output_tree)
 Send a response.
void confighttp::send_unauthorized (const resp_https_t &response, const req_https_t &request)
 Send a 401 Unauthorized response.
void confighttp::start ()
 Start the HTTPS configuration server.
void confighttp::updateVirtualInputLicense (const resp_https_t &response, const req_https_t &request)
 Activate, validate, or deactivate the libvirtualhid machine license.
bool confighttp::validate_csrf_token (const resp_https_t &response, const req_https_t &request, const std::string &client_id)
 Validate CSRF token.

Variables

const std::map< std::string, std::string > mime_types
 File-extension to MIME-type mapping used when serving the Web UI.
constexpr auto confighttp::PORT_HTTPS = 1
 GameStream port offset for port https.

Detailed Description

Declarations for the Web UI Config HTTP server.

Function Documentation

◆ authenticate()

bool confighttp::authenticate ( const resp_https_t & response,
const req_https_t & request )

Authenticate the user.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.
Returns
True if the user is authenticated, false otherwise.

◆ bad_request()

void confighttp::bad_request ( const resp_https_t & response,
const req_https_t & request,
const std::string & error_message )

Send a 400 Bad Request response.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.
error_messageThe error message to include in the response.

◆ browseDirectory()

void confighttp::browseDirectory ( const resp_https_t & response,
const req_https_t & request )

Browse the server filesystem.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.
Note
On Windows, an empty or root path returns the list of available drive letters.
On non-Windows, an empty path defaults to the filesystem root ("/").

◆ build_browse_entries()

nlohmann::json confighttp::build_browse_entries ( const std::filesystem::path & dir_path,
const std::string & type_str )

Lists, filters, and sorts the entries of a directory for the browse API.

Parameters
dir_pathThe directory to list.
type_strFilter type: "directory", "executable", "file", or "any".
Returns
Sorted JSON array of entry objects with name/type/path fields.

◆ build_driver_status()

nlohmann::json confighttp::build_driver_status ( bool installed,
const std::string & version,
std::string_view minimum_version )

Build a standard driver status response.

Parameters
installedWhether the driver was detected.
versionDetected driver version.
minimum_versionMinimum supported driver version, or empty for any version.
Returns
Driver status JSON object.

◆ build_virtualhid_license_status()

nlohmann::json confighttp::build_virtualhid_license_status ( const lvh::LicenseResult & result)

Convert a libvirtualhid license result into a Web UI response.

Parameters
resultLicense operation result.
Returns
License status JSON object without the submitted license key.

◆ cancelPairing()

void confighttp::cancelPairing ( const resp_https_t & response,
const req_https_t & request )

Cancel a client pairing request that is waiting for PIN approval. The body for the delete request should be JSON serialized in the following format:

Cancel an explicitly selected pairing request.

{
"pairing_id": "<pairing_id>"
}

Parameters
responseHTTP response object to populate.
requestHTTP request data from the client.

◆ check_app_index()

bool confighttp::check_app_index ( const resp_https_t & response,
const req_https_t & request,
int index )

Validates the application index and sends an error response if invalid.

Check app index.

Parameters
responseHTTP response object to populate.
requestHTTP request data from the client.
indexZero-based index of the item being addressed.
Returns
True when the request passes validation and processing may continue.

◆ check_content_type()

bool confighttp::check_content_type ( const resp_https_t & response,
const req_https_t & request,
const std::string_view & contentType )

Validate the request content type and send a bad request when mismatched.

Check content type.

Parameters
responseHTTP response object to populate.
requestHTTP request data from the client.
contentTypeExpected HTTP content type.
Returns
True when the request passes validation and processing may continue.

◆ generate_csrf_token()

std::string confighttp::generate_csrf_token ( const std::string & client_id)

Generate a new CSRF token for a client.

Parameters
client_idA unique identifier for the client (e.g., session ID or username).
Returns
The generated CSRF token.

◆ get_client_id()

std::string confighttp::get_client_id ( const req_https_t & request)

Get a unique client identifier for CSRF token management.

Parameters
requestThe HTTP request object.
Returns
A unique identifier based on username or IP address.

◆ get_vigembus_driver_status()

nlohmann::json confighttp::get_vigembus_driver_status ( )

Build ViGEmBus fallback driver version and installation status.

Returns
ViGEmBus fallback driver status JSON.

◆ get_virtualhid_driver_status()

nlohmann::json confighttp::get_virtualhid_driver_status ( )

Build libvirtualhid driver version and installation status.

Returns
libvirtualhid driver status JSON.

◆ get_windows_drives()

nlohmann::json confighttp::get_windows_drives ( )

Builds a JSON array of available Windows drive letters.

Returns
JSON array of drive-letter entries.

◆ getAsset()

void confighttp::getAsset ( const resp_https_t & response,
const req_https_t & request )

Get an asset.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.

◆ getCSRFToken()

void confighttp::getCSRFToken ( const resp_https_t & response,
const req_https_t & request )

Get a CSRF token for the authenticated user.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.

◆ getLocale()

void confighttp::getLocale ( const resp_https_t & response,
const req_https_t & request )

Get the locale setting. This endpoint does not require authentication.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.

◆ getPage()

void confighttp::getPage ( const resp_https_t & response,
const req_https_t & request,
const char * html_file,
const bool require_auth,
const bool redirect_if_username )

Get an HTML page.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.
html_fileThe HTML file to serve (relative to WEB_DIR).
require_authWhether to require authentication (default: true).
redirect_if_usernameIf true, redirect to "/" when the username is set (for welcome page).

◆ getPendingPairings()

void confighttp::getPendingPairings ( const resp_https_t & response,
const req_https_t & request )

List client pairing requests that are waiting for PIN approval.

List authenticated pairing requests awaiting operator approval.

Parameters
responseHTTP response object to populate.
requestHTTP request data from the client.

◆ getVirtualInputLicense()

void confighttp::getVirtualInputLicense ( const resp_https_t & response,
const req_https_t & request )

Get the current libvirtualhid machine license status.

Parameters
responseHTTP response object.
requestAuthenticated HTTP request.

◆ getVirtualInputStatus()

void confighttp::getVirtualInputStatus ( const resp_https_t & response,
const req_https_t & request )

Get virtual input driver version and installation status.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.

◆ is_browsable_executable()

bool confighttp::is_browsable_executable ( const std::filesystem::directory_entry & entry,
const std::filesystem::file_status & status )

Checks whether a directory entry qualifies as an executable file.

Parameters
entryThe directory entry to check.
statusThe cached file status for the entry.
Returns
True if the file should be included in an executable-type listing.

◆ is_driver_version_development()

bool confighttp::is_driver_version_development ( std::string_view version)

Check whether a detected driver version identifies a development build.

Numeric versions beginning with 0.0 and containing at least three components are development builds.

Parameters
versionDetected driver version.
Returns
True when the version identifies a development build.

◆ is_driver_version_supported()

bool confighttp::is_driver_version_supported ( std::string_view version,
std::string_view minimum_version )

Check whether a detected driver version satisfies a minimum version.

Empty minimum versions accept any detected version. Non-empty minimum versions require a fully numeric dotted version string. Development versions beginning with 0.0 are always accepted.

Parameters
versionDetected driver version.
minimum_versionMinimum supported driver version, or empty for any version.
Returns
True when the driver version is supported.

◆ not_found()

void confighttp::not_found ( const resp_https_t & response,
const req_https_t & request,
const std::string & error_message )

Send a 404 Not Found response.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.
error_messageThe error message to include in the response.

◆ print_req()

void confighttp::print_req ( const req_https_t & request)

Log the request details.

Parameters
requestThe HTTP request object.

◆ resetPortalToken()

void confighttp::resetPortalToken ( const resp_https_t & response,
const req_https_t & request )

Authenticate a Web UI request and delete the saved XDG Portal restore token.

On platforms without XDG Portal capture, this operation succeeds without changing the filesystem.

Parameters
responseHTTP response used for authentication, CSRF, and status output.
requestHTTP request carrying the client identity and CSRF token.

◆ savePin()

void confighttp::savePin ( const resp_https_t & response,
const req_https_t & request )

Submit a PIN and return whether the selected client completes pairing.

Apply a PIN to an explicitly selected pairing request.

The request remains open for up to the configured ping_timeout while Moonlight completes the cryptographic handshake. A wrong PIN, protocol failure, cancellation, or timeout returns {"status":false}. The body for the post request should be JSON serialized in the following format:

{
"pairing_id": "<pairing_id>",
"pin": "<pin>",
"name": "Friendly Client Name"
}

Parameters
responseHTTP response object to populate.
requestHTTP request data from the client.

◆ send_redirect()

void confighttp::send_redirect ( const resp_https_t & response,
const req_https_t & request,
const char * path )

Send a redirect response.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.
pathThe path to redirect to.

◆ send_response()

void confighttp::send_response ( const resp_https_t & response,
const nlohmann::json & output_tree )

Send a response.

Parameters
responseThe HTTP response object.
output_treeThe JSON tree to send.

◆ send_unauthorized()

void confighttp::send_unauthorized ( const resp_https_t & response,
const req_https_t & request )

Send a 401 Unauthorized response.

Parameters
responseThe HTTP response object.
requestThe HTTP request object.

◆ updateVirtualInputLicense()

void confighttp::updateVirtualInputLicense ( const resp_https_t & response,
const req_https_t & request )

Activate, validate, or deactivate the libvirtualhid machine license.

Submitted license keys are used only for the synchronous broker call. They are never logged or saved in Sunshine's configuration, and extracted mutable copies are overwritten before the handler returns.

Parameters
responseHTTP response object.
requestAuthenticated HTTP request with a JSON action.

◆ validate_csrf_token()

bool confighttp::validate_csrf_token ( const resp_https_t & response,
const req_https_t & request,
const std::string & client_id )

Validate CSRF token.

Parameters
responseHTTP response object to populate.
requestHTTP request data from the client.
client_idClient identifier used to look up the CSRF token.
Returns
True when the request passes validation and processing may continue.

Variable Documentation

◆ mime_types

const std::map<std::string, std::string> mime_types
Initial value:
= {
{"css", "text/css"},
{"gif", "image/gif"},
{"htm", "text/html"},
{"html", "text/html"},
{"ico", "image/x-icon"},
{"jpeg", "image/jpeg"},
{"jpg", "image/jpeg"},
{"js", "application/javascript"},
{"json", "application/json"},
{"png", "image/png"},
{"svg", "image/svg+xml"},
{"ttf", "font/ttf"},
{"txt", "text/plain"},
{"woff2", "font/woff2"},
{"xml", "text/xml"},
}

File-extension to MIME-type mapping used when serving the Web UI.