2016-09-29 21:10:40 -04:00
(function () {
'use strict';
var WebSocket = require('ws');
2017-04-27 19:29:16 -06:00
var PromiseA = require('bluebird');
2016-09-29 21:10:40 -04:00
var sni = require('sni');
2018-05-31 00:19:53 -06:00
var Packer = require('proxy-packer');
2016-09-29 21:10:40 -04:00
2017-06-05 11:28:53 -06:00
function timeoutPromise(duration) {
return new PromiseA(function (resolve) {
setTimeout(resolve, duration);
2018-05-31 00:19:53 -06:00
function run(state) {
2017-06-15 14:49:50 -06:00
// jshint latedef:false
2018-05-31 00:19:53 -06:00
var activityTimeout = state.activityTimeout || (2*60 - 5)*1000;
var pongTimeout = state.pongTimeout || 10*1000;
2017-05-25 13:46:09 -06:00
// Allow the tunnel client to be created with no token. This will prevent the connection from
// being established initialy and allows the caller to use `.append` for the first token so
// they can get a promise that will provide feedback about invalid tokens.
var tokens = [];
2018-05-31 00:19:53 -06:00
if (state.token) {
2017-05-25 13:46:09 -06:00
2017-04-10 11:39:27 -06:00
2016-09-30 15:04:27 -04:00
var wstunneler;
2017-04-07 18:49:52 -06:00
var authenticated = false;
2017-04-07 17:38:55 -06:00
2016-09-30 15:04:27 -04:00
var localclients = {};
2017-09-08 10:54:47 -06:00
var pausedClients = [];
2017-04-07 17:38:55 -06:00
var clientHandlers = {
2018-05-31 00:19:53 -06:00
add: function (conn, cid, tun) {
2017-09-08 10:54:47 -06:00
localclients[cid] = conn;
2018-05-31 00:19:53 -06:00
console.info("[connect] new client '" + cid + "' for '" + tun.name + ":" + tun.serviceport + "' "
+ "(" + clientHandlers.count() + " clients)");
2017-09-08 10:54:47 -06:00
2017-09-11 14:52:49 -06:00
conn.tunnelCid = cid;
2018-05-31 00:19:53 -06:00
conn.tunnelRead = tun.data.byteLength;
2017-09-11 14:52:49 -06:00
conn.tunnelWritten = 0;
2017-09-08 10:54:47 -06:00
conn.on('data', function onLocalData(chunk) {
if (conn.tunnelClosing) {
console.warn("[onLocalData] received data for '"+cid+"' over socket after connection was ended");
2017-09-11 14:52:49 -06:00
// This value is bytes written to the tunnel (ie read from the local connection)
conn.tunnelWritten += chunk.byteLength;
2017-09-08 10:54:47 -06:00
// If we have a lot of buffered data waiting to be sent over the websocket we want to slow
// down the data we are getting to send over. We also want to pause all active connections
// if any connections are paused to make things more fair so one connection doesn't get
// stuff waiting for all other connections to finish because it tried writing near the border.
2018-05-31 00:19:53 -06:00
var bufSize = wsHandlers.sendMessage(Packer.pack(tun, chunk));
2017-09-08 10:54:47 -06:00
if (pausedClients.length || bufSize > 1024*1024) {
2017-09-11 15:35:03 -06:00
// console.log('[onLocalData] paused connection', cid, 'to allow websocket to catch up');
2017-09-08 10:54:47 -06:00
2017-09-11 14:52:49 -06:00
var sentEnd = false;
conn.on('end', function onLocalEnd() {
console.info("[onLocalEnd] connection '" + cid + "' ended, will probably close soon");
conn.tunnelClosing = true;
if (!sentEnd) {
2018-05-31 00:19:53 -06:00
wsHandlers.sendMessage(Packer.pack(tun, null, 'end'));
2017-09-11 14:52:49 -06:00
sentEnd = true;
2017-09-08 10:54:47 -06:00
conn.on('error', function onLocalError(err) {
console.info("[onLocalError] connection '" + cid + "' errored:", err);
2017-09-11 14:52:49 -06:00
if (!sentEnd) {
2018-05-31 00:19:53 -06:00
wsHandlers.sendMessage(Packer.pack(tun, {message: err.message, code: err.code}, 'error'));
2017-09-11 14:52:49 -06:00
sentEnd = true;
2017-09-08 10:54:47 -06:00
conn.on('close', function onLocalClose(hadErr) {
delete localclients[cid];
2017-09-11 14:52:49 -06:00
console.log('[onLocalClose] closed "' + cid + '" read:'+conn.tunnelRead+', wrote:'+conn.tunnelWritten+' (' + clientHandlers.count() + ' clients)');
if (!sentEnd) {
2018-05-31 00:19:53 -06:00
wsHandlers.sendMessage(Packer.pack(tun, null, hadErr && 'error' || 'end'));
2017-09-11 14:52:49 -06:00
sentEnd = true;
2017-09-08 10:54:47 -06:00
2017-04-07 17:38:55 -06:00
2017-09-08 10:54:47 -06:00
, write: function (cid, opts) {
var conn = localclients[cid];
if (!conn) {
return false;
//console.log("[=>] received data from '" + cid + "' =>", opts.data.byteLength);
if (conn.tunnelClosing) {
console.warn("[onmessage] received data for '"+cid+"' over socket after connection was ended");
return true;
2017-09-11 14:52:49 -06:00
// It might seem weird to increase the "read" value in a function named `write`, but this
// is bytes read from the tunnel and written to the local connection.
conn.tunnelRead += opts.data.byteLength;
2017-09-11 15:35:03 -06:00
if (!conn.remotePaused && conn.bufferSize > 1024*1024) {
wsHandlers.sendMessage(Packer.pack(opts, conn.tunnelRead, 'pause'));
conn.remotePaused = true;
conn.once('drain', function () {
wsHandlers.sendMessage(Packer.pack(opts, conn.tunnelRead, 'resume'));
conn.remotePaused = false;
2017-09-08 10:54:47 -06:00
return true;
2017-04-07 17:38:55 -06:00
, closeSingle: function (cid) {
if (!localclients[cid]) {
2017-04-07 18:01:47 -06:00
console.log('[closeSingle]', cid);
2017-09-08 10:54:47 -06:00
PromiseA.resolve().then(function () {
var conn = localclients[cid];
conn.tunnelClosing = true;
// If no data is buffered for writing then we don't need to wait for it to drain.
if (!conn.bufferSize) {
2017-06-05 11:28:53 -06:00
return timeoutPromise(500);
2017-09-08 10:54:47 -06:00
// Otherwise we want the connection to be able to finish, but we also want to impose
// a time limit for it to drain, since it shouldn't have more than 1MB buffered.
return new PromiseA(function (resolve) {
var timeoutId = setTimeout(resolve, 60*1000);
conn.once('drain', function () {
setTimeout(resolve, 500);
}).then(function () {
if (localclients[cid]) {
console.warn('[closeSingle]', cid, 'connection still present after calling `end`');
return timeoutPromise(500);
}).then(function () {
if (localclients[cid]) {
console.error('[closeSingle]', cid, 'connection still present after calling `destroy`');
2017-06-05 11:28:53 -06:00
delete localclients[cid];
2017-09-08 10:54:47 -06:00
}).catch(function (err) {
console.error('[closeSingle] failed to close connection', cid, err.toString());
delete localclients[cid];
2017-04-07 17:38:55 -06:00
, closeAll: function () {
2017-04-07 18:01:47 -06:00
2017-04-07 17:38:55 -06:00
Object.keys(localclients).forEach(function (cid) {
2017-06-05 11:28:53 -06:00
2017-04-07 17:38:55 -06:00
2017-04-07 18:01:47 -06:00
2017-04-07 17:38:55 -06:00
, count: function () {
return Object.keys(localclients).length;
2017-04-07 18:01:47 -06:00
2017-04-27 19:29:16 -06:00
var pendingCommands = {};
function sendCommand(name) {
var id = Math.ceil(1e9 * Math.random());
var cmd = [id, name].concat(Array.prototype.slice.call(arguments, 1));
wsHandlers.sendMessage(Packer.pack(null, cmd, 'control'));
setTimeout(function () {
if (pendingCommands[id]) {
console.warn('command', id, 'timed out');
message: 'response not received in time'
, code: 'E_TIMEOUT'
}, pongTimeout);
return new PromiseA(function (resolve, reject) {
pendingCommands[id] = function (err, result) {
delete pendingCommands[id];
if (err) {
} else {
2017-04-28 15:02:44 -06:00
function sendAllTokens() {
tokens.forEach(function (jwtoken) {
sendCommand('add_token', jwtoken)
.catch(function (err) {
console.error('failed re-adding token', jwtoken, 'after reconnect', err);
// Not sure if we should do something like remove the token here. It worked
// once or it shouldn't have stayed in the list, so it's less certain why
// it would have failed here.
2018-06-01 03:13:04 -06:00
function displayGrants(grants) {
// TODO sortingHat.print();
console.log("Connect to your device by any of the following means:");
grants.forEach(function (arr) {
2018-06-01 03:34:55 -06:00
if ('ssh+https' === arr[0]) {
} else if ('ssh' === arr[0]) {
} else if ('tcp' === arr[0]) {
} else if ('https' === arr[0]) {
2018-06-01 03:13:04 -06:00
console.log('\t' + arr[0] + '://' + arr[1] + (arr[2] ? (':' + arr[2]) : ''));
2018-06-01 03:34:55 -06:00
if ('ssh+https' === arr[0]) {
console.log("\tex: ssh -o ProxyCommand='openssl s_client -connect %h:%p -quiet' " + arr[1] + " -p 443\n");
} else if ('ssh' === arr[0]) {
console.log("\tex: ssh " + arr[1] + " -p " + arr[2] + "\n");
} else if ('tcp' === arr[0]) {
console.log("\tex: netcat " + arr[1] + " " + arr[2] + "\n");
} else if ('https' === arr[0]) {
console.log("\tex: curl https://" + arr[1] + "\n");
2018-06-01 03:13:04 -06:00
2017-04-28 15:28:21 -06:00
var connCallback;
2017-04-07 17:38:55 -06:00
var packerHandlers = {
2017-04-27 19:29:16 -06:00
oncontrol: function (opts) {
var cmd, err;
try {
cmd = JSON.parse(opts.data.toString());
} catch (err) {}
if (!Array.isArray(cmd) || typeof cmd[0] !== 'number') {
console.warn('received bad command "' + opts.data.toString() + '"');
if (cmd[0] < 0) {
var cb = pendingCommands[-cmd[0]];
if (!cb) {
console.warn('received response for unknown request:', cmd);
} else {
cb.apply(null, cmd.slice(1));
2017-04-28 15:02:44 -06:00
if (cmd[0] === 0) {
console.warn('received dis-associated error from server', cmd[1]);
2017-04-28 15:28:21 -06:00
if (connCallback) {
2017-04-28 15:02:44 -06:00
if (cmd[1] === 'hello') {
// We only get the 'hello' event after the token has been validated
authenticated = true;
2017-04-28 15:28:21 -06:00
if (connCallback) {
2017-04-28 15:02:44 -06:00
// TODO: handle the versions and commands provided by 'hello' - isn't super important
2017-05-25 13:46:09 -06:00
// yet since there is only one version and set of commands.
2017-04-28 15:02:44 -06:00
err = null;
else {
err = { message: 'unknown command "'+cmd[1]+'"', code: 'E_UNKNOWN_COMMAND' };
2017-04-27 19:29:16 -06:00
2018-06-01 03:13:04 -06:00
if (cmd[1] === 'grant') {
2017-04-27 19:29:16 -06:00
wsHandlers.sendMessage(Packer.pack(null, [-cmd[0], err], 'control'));
2017-09-08 10:54:47 -06:00
2018-05-31 00:19:53 -06:00
, onmessage: function (tun) {
var cid = tun._id = Packer.addrToId(tun);
2016-09-30 15:04:27 -04:00
var str;
var m;
2018-05-31 00:19:53 -06:00
if ('http' === tun.service) {
str = tun.data.toString();
2016-09-30 15:04:27 -04:00
m = str.match(/(?:^|[\r\n])Host: ([^\r\n]+)[\r\n]*/im);
2018-05-31 00:19:53 -06:00
tun._name = tun._hostname = (m && m[1].toLowerCase() || '').split(':')[0];
2016-09-30 15:04:27 -04:00
2018-05-31 00:19:53 -06:00
else if ('https' === tun.service || 'tls' === tun.service) {
tun._name = tun._servername = sni(tun.data);
} else {
tun._name = '';
2017-06-05 11:20:58 -06:00
2018-05-31 00:19:53 -06:00
if (clientHandlers.write(cid, tun)) { return; }
2016-10-11 17:43:24 -06:00
2018-05-31 00:19:53 -06:00
require(state.sortingHat).assign(state, tun, function (err, conn) {
if (err) {
err.message = err.message.replace(/:tun_id/, tun._id);
packerHandlers._onConnectError(cid, tun, err);
2017-04-27 18:38:01 -06:00
2018-05-31 00:19:53 -06:00
clientHandlers.add(conn, cid, tun);
2018-05-31 04:10:47 -06:00
if (tun.data) { conn.write(tun.data); }
2018-05-31 00:19:53 -06:00
2017-09-08 10:54:47 -06:00
2016-10-11 17:43:24 -06:00
2017-09-08 10:54:47 -06:00
, onpause: function (opts) {
var cid = Packer.addrToId(opts);
if (localclients[cid]) {
2017-09-11 14:52:49 -06:00
console.log("[TunnelPause] pausing '"+cid+"', remote received", opts.data.toString(), 'of', localclients[cid].tunnelWritten, 'sent');
2017-09-08 10:54:47 -06:00
localclients[cid].manualPause = true;
} else {
2017-09-11 14:52:49 -06:00
console.log('[TunnelPause] remote tried pausing finished connection', cid);
// Often we have enough latency that we've finished sending before we're told to pause, so
// don't worry about sending back errors, since we won't be sending data over anyway.
// wsHandlers.sendMessage(Packer.pack(opts, {message: 'no matching connection', code: 'E_NO_CONN'}, 'error'));
2017-09-08 10:54:47 -06:00
, onresume: function (opts) {
var cid = Packer.addrToId(opts);
if (localclients[cid]) {
2017-09-11 14:52:49 -06:00
console.log("[TunnelResume] resuming '"+cid+"', remote received", opts.data.toString(), 'of', localclients[cid].tunnelWritten, 'sent');
2017-09-08 10:54:47 -06:00
localclients[cid].manualPause = false;
} else {
2017-09-11 14:52:49 -06:00
console.log('[TunnelResume] remote tried resuming finished connection', cid);
// wsHandlers.sendMessage(Packer.pack(opts, {message: 'no matching connection', code: 'E_NO_CONN'}, 'error'));
2017-09-08 10:54:47 -06:00
2016-09-30 15:04:27 -04:00
2017-09-08 10:54:47 -06:00
2016-09-30 15:04:27 -04:00
, onend: function (opts) {
2016-10-05 23:55:48 -06:00
var cid = Packer.addrToId(opts);
2016-09-30 15:04:27 -04:00
//console.log("[end] '" + cid + "'");
2017-04-07 17:38:55 -06:00
2016-09-30 15:04:27 -04:00
, onerror: function (opts) {
2016-10-05 23:55:48 -06:00
var cid = Packer.addrToId(opts);
2016-09-30 15:04:27 -04:00
//console.log("[error] '" + cid + "'", opts.code || '', opts.message);
2017-04-07 17:38:55 -06:00
2016-09-30 15:04:27 -04:00
2017-09-08 10:54:47 -06:00
2017-04-07 17:38:55 -06:00
, _onConnectError: function (cid, opts, err) {
console.info("[_onConnectError] opening '" + cid + "' failed because " + err.message);
2017-04-07 18:49:52 -06:00
wsHandlers.sendMessage(Packer.pack(opts, null, 'error'));
2016-09-30 15:04:27 -04:00
2017-04-07 18:01:47 -06:00
2017-04-10 11:39:27 -06:00
var lastActivity;
var timeoutId;
2016-09-30 15:04:27 -04:00
var wsHandlers = {
2017-04-10 11:39:27 -06:00
refreshTimeout: function () {
lastActivity = Date.now();
, checkTimeout: function () {
if (!wstunneler) {
console.warn('checkTimeout called when websocket already closed');
// Determine how long the connection has been "silent", ie no activity.
var silent = Date.now() - lastActivity;
// If we have had activity within the last activityTimeout then all we need to do is
// call this function again at the soonest time when the connection could be timed out.
if (silent < activityTimeout) {
timeoutId = setTimeout(wsHandlers.checkTimeout, activityTimeout-silent);
// Otherwise we check to see if the pong has also timed out, and if not we send a ping
// and call this function again when the pong will have timed out.
else if (silent < activityTimeout + pongTimeout) {
console.log('pinging tunnel server');
try {
} catch (err) {
console.warn('failed to ping tunnel server', err);
timeoutId = setTimeout(wsHandlers.checkTimeout, pongTimeout);
// Last case means the ping we sent before didn't get a response soon enough, so we
// need to close the websocket connection.
else {
console.log('connection timed out');
wstunneler.close(1000, 'connection timeout');
, onOpen: function () {
2018-05-31 00:19:53 -06:00
console.info("[open] connected to '" + state.relay + "'");
2017-04-10 11:39:27 -06:00
timeoutId = setTimeout(wsHandlers.checkTimeout, activityTimeout);
2017-09-08 10:54:47 -06:00
wstunneler._socket.on('drain', function () {
2017-09-11 15:35:03 -06:00
// the websocket library has it's own buffer apart from node's socket buffer, but that one
// is much more difficult to watch, so we watch for the lower level buffer to drain and
// then check to see if the upper level buffer is still too full to write to. Note that
// the websocket library buffer has something to do with compression, so I'm not requiring
// that to be 0 before we start up again.
if (wstunneler.bufferedAmount > 128*1024) {
2017-09-08 10:54:47 -06:00
pausedClients.forEach(function (conn) {
if (!conn.manualPause) {
2017-09-11 15:35:03 -06:00
// console.log('resuming connection', conn.tunnelCid, 'now the websocket has caught up');
2017-09-08 10:54:47 -06:00
pausedClients.length = 0;
2016-09-29 21:10:40 -04:00
2016-09-30 15:04:27 -04:00
, onClose: function () {
2017-04-07 17:38:55 -06:00
console.log('ON CLOSE');
2017-04-10 11:39:27 -06:00
2017-04-07 18:49:52 -06:00
wstunneler = null;
2017-04-07 17:38:55 -06:00
2017-10-02 18:29:00 -06:00
var error = new Error('websocket connection closed before response');
error.code = 'E_CONN_CLOSED';
2017-04-27 19:29:16 -06:00
Object.keys(pendingCommands).forEach(function (id) {
2017-10-02 18:29:00 -06:00
2017-04-27 19:29:16 -06:00
2017-10-02 18:29:00 -06:00
if (connCallback) {
2017-04-07 17:38:55 -06:00
2016-09-30 15:04:27 -04:00
if (!authenticated) {
console.info('[close] failed on first attempt... check authentication.');
2017-04-10 11:39:27 -06:00
timeoutId = null;
2016-09-30 15:04:27 -04:00
2017-04-28 10:57:48 -06:00
else if (tokens.length) {
2016-09-30 15:04:27 -04:00
console.info('[retry] disconnected and waiting...');
2017-04-10 11:39:27 -06:00
timeoutId = setTimeout(connect, 5000);
2016-09-30 15:04:27 -04:00
2016-09-30 01:46:00 -04:00
2016-09-30 15:04:27 -04:00
, onError: function (err) {
console.error("[tunnel error] " + err.message);
2016-09-30 01:23:03 -04:00
2017-10-02 18:29:00 -06:00
if (connCallback) {
2016-09-30 15:04:27 -04:00
2016-09-30 01:46:00 -04:00
2017-04-07 18:49:52 -06:00
, sendMessage: function (msg) {
if (wstunneler) {
try {
2017-04-10 11:39:27 -06:00
wstunneler.send(msg, {binary: true});
2017-09-11 15:35:03 -06:00
return wstunneler.bufferedAmount;
2017-04-07 18:49:52 -06:00
} catch (err) {
2017-04-26 17:37:52 -06:00
// There is a chance that this occurred after the websocket was told to close
// and before it finished, in which case we don't need to log the error.
if (wstunneler.readyState !== wstunneler.CLOSING) {
console.warn('[sendMessage] error sending websocket message', err);
2017-04-07 18:49:52 -06:00
function connect() {
2017-04-28 10:57:48 -06:00
if (!tokens.length) {
2018-05-29 01:44:50 -06:00
console.warn("[Non-fatal Error] No tokens. Nothing to do.");
2017-04-07 18:49:52 -06:00
2017-04-28 15:28:21 -06:00
if (wstunneler) {
console.warn('attempted to connect with connection already active');
2017-04-10 11:39:27 -06:00
timeoutId = null;
2018-05-31 00:19:53 -06:00
var machine = Packer.create(packerHandlers);
2017-04-07 18:49:52 -06:00
2018-05-31 00:19:53 -06:00
console.info("[connect] '" + state.relay + "'");
var tunnelUrl = state.relay.replace(/\/$/, '') + '/?access_token=' + tokens[0];
wstunneler = new WebSocket(tunnelUrl, { rejectUnauthorized: !state.insecure });
2017-04-07 18:49:52 -06:00
wstunneler.on('open', wsHandlers.onOpen);
wstunneler.on('close', wsHandlers.onClose);
wstunneler.on('error', wsHandlers.onError);
2017-04-10 11:39:27 -06:00
// Our library will automatically handle sending the pong respose to ping requests.
wstunneler.on('ping', wsHandlers.refreshTimeout);
wstunneler.on('pong', wsHandlers.refreshTimeout);
2017-04-07 18:49:52 -06:00
wstunneler.on('message', function (data, flags) {
2017-04-10 11:39:27 -06:00
2017-04-07 18:49:52 -06:00
if (data.error || '{' === data[0]) {
machine.fns.addChunk(data, flags);
2017-06-15 14:49:50 -06:00
var connPromise;
2017-04-14 16:27:25 -06:00
return {
end: function() {
2017-04-28 10:57:48 -06:00
tokens.length = 0;
2017-04-14 16:27:25 -06:00
if (timeoutId) {
timeoutId = null;
2017-04-07 18:49:52 -06:00
2017-04-14 16:27:25 -06:00
if (wstunneler) {
try {
} catch(e) {
console.error("[error] wstunneler.close()");
2016-09-30 01:46:00 -04:00
2017-04-27 19:29:16 -06:00
, append: function (token) {
2017-04-28 10:57:48 -06:00
if (tokens.indexOf(token) >= 0) {
return PromiseA.resolve();
2017-04-28 15:28:21 -06:00
var prom;
if (tokens.length === 1 && !wstunneler) {
// We just added the only token in the list, and the websocket connection isn't up
// so we need to restart the connection.
if (timeoutId) {
// Handle the case were the last token was removed and this token added between
// reconnect attempts to make sure we don't try openning multiple connections.
timeoutId = null;
// We want this case to behave as much like the other case as we can, but we don't have
// the same kind of reponses when we open brand new connections, so we have to rely on
// the 'hello' and the 'un-associated' error commands to determine if the token is good.
2017-06-15 14:49:50 -06:00
prom = connPromise = new PromiseA(function (resolve, reject) {
2017-04-28 15:28:21 -06:00
connCallback = function (err) {
connCallback = null;
2017-06-15 14:49:50 -06:00
connPromise = null;
2017-04-28 15:28:21 -06:00
if (err) {
} else {
2017-06-15 14:49:50 -06:00
else if (connPromise) {
prom = connPromise.then(function () {
return sendCommand('add_token', token);
2017-04-28 15:28:21 -06:00
else {
prom = sendCommand('add_token', token);
2017-04-28 10:57:48 -06:00
prom.catch(function (err) {
console.error('adding token', token, 'failed:', err);
// Most probably an invalid token of some kind, so we don't really want to keep it.
2017-10-02 18:29:00 -06:00
tokens.splice(tokens.indexOf(token), 1);
2017-04-28 10:57:48 -06:00
return prom;
2017-04-27 19:29:16 -06:00
, clear: function (token) {
2017-04-28 10:57:48 -06:00
if (typeof token === 'undefined') {
token = '*';
if (token === '*') {
tokens.length = 0;
} else {
var index = tokens.indexOf(token);
if (index < 0) {
return PromiseA.resolve();
var prom = sendCommand('delete_token', token);
prom.catch(function (err) {
console.error('clearing token', token, 'failed:', err);
return prom;
2017-04-27 19:29:16 -06:00
2017-04-14 16:27:25 -06:00
2016-09-30 15:04:27 -04:00
2016-09-30 01:46:00 -04:00
2016-09-30 15:04:27 -04:00
module.exports.connect = run;
2017-04-14 16:27:25 -06:00
module.exports.createConnection = run;
2016-09-29 21:10:40 -04:00