frp/pkg/util/vhost/vhost.go

301 lines
7.4 KiB
Go
Raw Normal View History

2016-04-18 07:16:40 +00:00
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package vhost
import (
2019-10-12 12:13:12 +00:00
"context"
2016-04-18 07:16:40 +00:00
"fmt"
2019-10-12 12:13:12 +00:00
"net"
2016-04-18 07:16:40 +00:00
"strings"
"time"
2022-08-28 17:02:53 +00:00
"github.com/fatedier/golib/errors"
2020-09-23 05:49:14 +00:00
"github.com/fatedier/frp/pkg/util/log"
2023-05-29 06:10:34 +00:00
utilnet "github.com/fatedier/frp/pkg/util/net"
2020-09-23 05:49:14 +00:00
"github.com/fatedier/frp/pkg/util/xlog"
2016-04-18 07:16:40 +00:00
)
2020-05-24 09:48:37 +00:00
type RouteInfo string
const (
RouteInfoKey RouteInfo = "routeInfo"
2020-05-24 09:48:37 +00:00
)
type RequestRouteInfo struct {
URL string
Host string
HTTPUser string
RemoteAddr string
URLHost string
Endpoint string
}
2022-08-28 17:02:53 +00:00
type (
muxFunc func(net.Conn) (net.Conn, map[string]string, error)
2023-03-07 11:53:32 +00:00
authFunc func(conn net.Conn, username, password string, reqInfoMap map[string]string) (bool, error)
2022-08-28 17:02:53 +00:00
hostRewriteFunc func(net.Conn, string) (net.Conn, error)
2023-03-07 11:53:32 +00:00
successHookFunc func(net.Conn, map[string]string) error
2022-08-28 17:02:53 +00:00
)
2016-04-18 07:16:40 +00:00
2023-03-07 11:53:32 +00:00
// Muxer is a functional component used for https and tcpmux proxies.
// It accepts connections and extracts vhost information from the beginning of the connection data.
// It then routes the connection to its appropriate listener.
2020-05-24 09:48:37 +00:00
type Muxer struct {
2023-03-07 11:53:32 +00:00
listener net.Listener
timeout time.Duration
vhostFunc muxFunc
2023-03-07 11:53:32 +00:00
checkAuth authFunc
successHook successHookFunc
rewriteHost hostRewriteFunc
2020-05-24 09:48:37 +00:00
registryRouter *Routers
2016-04-18 07:16:40 +00:00
}
func NewMuxer(
listener net.Listener,
vhostFunc muxFunc,
timeout time.Duration,
) (mux *Muxer, err error) {
2020-05-24 09:48:37 +00:00
mux = &Muxer{
listener: listener,
timeout: timeout,
vhostFunc: vhostFunc,
2020-05-24 09:48:37 +00:00
registryRouter: NewRouters(),
2016-04-18 07:16:40 +00:00
}
go mux.run()
return mux, nil
}
2023-03-07 11:53:32 +00:00
func (v *Muxer) SetCheckAuthFunc(f authFunc) *Muxer {
v.checkAuth = f
return v
}
func (v *Muxer) SetSuccessHookFunc(f successHookFunc) *Muxer {
v.successHook = f
return v
}
func (v *Muxer) SetRewriteHostFunc(f hostRewriteFunc) *Muxer {
v.rewriteHost = f
return v
}
type ChooseEndpointFunc func() (string, error)
2019-10-12 12:13:12 +00:00
type CreateConnFunc func(remoteAddr string) (net.Conn, error)
2017-12-13 15:44:27 +00:00
type CreateConnByEndpointFunc func(endpoint, remoteAddr string) (net.Conn, error)
2020-05-24 09:48:37 +00:00
// RouteConfig is the params used to match HTTP requests
type RouteConfig struct {
Domain string
Location string
RewriteHost string
Username string
Password string
Headers map[string]string
RouteByHTTPUser string
2017-12-13 15:44:27 +00:00
CreateConnFn CreateConnFunc
ChooseEndpointFn ChooseEndpointFunc
CreateConnByEndpointFn CreateConnByEndpointFunc
2017-03-09 18:01:17 +00:00
}
2023-03-07 11:53:32 +00:00
// listen for a new domain name, if rewriteHost is not empty and rewriteHost func is not nil,
2017-03-09 18:01:17 +00:00
// then rewrite the host header to rewriteHost
2020-05-24 09:48:37 +00:00
func (v *Muxer) Listen(ctx context.Context, cfg *RouteConfig) (l *Listener, err error) {
2016-12-24 17:53:23 +00:00
l = &Listener{
name: cfg.Domain,
location: cfg.Location,
routeByHTTPUser: cfg.RouteByHTTPUser,
rewriteHost: cfg.RewriteHost,
2023-03-07 11:53:32 +00:00
username: cfg.Username,
password: cfg.Password,
mux: v,
accept: make(chan net.Conn),
ctx: ctx,
}
err = v.registryRouter.Add(cfg.Domain, cfg.Location, cfg.RouteByHTTPUser, l)
2019-07-30 16:41:58 +00:00
if err != nil {
return
}
2016-12-24 17:53:23 +00:00
return l, nil
2016-04-18 07:16:40 +00:00
}
func (v *Muxer) getListener(name, path, httpUser string) (*Listener, bool) {
findRouter := func(inName, inPath, inHTTPUser string) (*Listener, bool) {
2022-08-28 17:02:53 +00:00
vr, ok := v.registryRouter.Get(inName, inPath, inHTTPUser)
if ok {
return vr.payload.(*Listener), true
}
// Try to check if there is one proxy that doesn't specify routerByHTTPUser, it means match all.
vr, ok = v.registryRouter.Get(inName, inPath, "")
if ok {
return vr.payload.(*Listener), true
}
return nil, false
}
2016-12-24 17:53:23 +00:00
// first we check the full hostname
// if not exist, then check the wildcard_domain such as *.example.com
l, ok := findRouter(name, path, httpUser)
if ok {
return l, true
2016-08-22 16:58:51 +00:00
}
2016-08-22 16:58:51 +00:00
domainSplit := strings.Split(name, ".")
for {
if len(domainSplit) < 3 {
break
}
domainSplit[0] = "*"
name = strings.Join(domainSplit, ".")
l, ok = findRouter(name, path, httpUser)
if ok {
return l, true
}
domainSplit = domainSplit[1:]
}
// Finally, try to check if there is one proxy that domain is "*" means match all domains.
l, ok = findRouter("*", path, httpUser)
if ok {
return l, true
}
return nil, false
2016-04-18 07:16:40 +00:00
}
2020-05-24 09:48:37 +00:00
func (v *Muxer) run() {
2016-04-18 07:16:40 +00:00
for {
conn, err := v.listener.Accept()
if err != nil {
return
}
go v.handle(conn)
}
}
2020-05-24 09:48:37 +00:00
func (v *Muxer) handle(c net.Conn) {
2016-04-18 07:16:40 +00:00
if err := c.SetDeadline(time.Now().Add(v.timeout)); err != nil {
2022-08-28 17:02:53 +00:00
_ = c.Close()
2016-04-18 07:16:40 +00:00
return
}
sConn, reqInfoMap, err := v.vhostFunc(c)
2016-04-18 07:16:40 +00:00
if err != nil {
log.Debug("get hostname from http/https request error: %v", err)
2022-08-28 17:02:53 +00:00
_ = c.Close()
2016-04-18 07:16:40 +00:00
return
}
2016-12-24 17:53:23 +00:00
name := strings.ToLower(reqInfoMap["Host"])
path := strings.ToLower(reqInfoMap["Path"])
httpUser := reqInfoMap["HTTPUser"]
l, ok := v.getListener(name, path, httpUser)
2016-04-18 07:16:40 +00:00
if !ok {
res := notFoundResponse()
2022-08-28 17:02:53 +00:00
if res.Body != nil {
defer res.Body.Close()
}
_ = res.Write(c)
log.Debug("http request for host [%s] path [%s] httpUser [%s] not found", name, path, httpUser)
2022-08-28 17:02:53 +00:00
_ = c.Close()
2016-04-18 07:16:40 +00:00
return
}
2019-10-12 12:13:12 +00:00
xl := xlog.FromContextSafe(l.ctx)
2023-03-07 11:53:32 +00:00
if v.successHook != nil {
if err := v.successHook(c, reqInfoMap); err != nil {
xl.Info("success func failure on vhost connection: %v", err)
2022-08-28 17:02:53 +00:00
_ = c.Close()
return
}
}
2016-04-18 07:16:40 +00:00
2023-03-07 11:53:32 +00:00
// if checkAuth func is exist and username/password is set
// then verify user access
2023-03-07 11:53:32 +00:00
if l.mux.checkAuth != nil && l.username != "" {
ok, err := l.mux.checkAuth(c, l.username, l.password, reqInfoMap)
if !ok || err != nil {
xl.Debug("auth failed for user: %s", l.username)
2022-08-28 17:02:53 +00:00
_ = c.Close()
return
}
}
2016-04-18 07:16:40 +00:00
if err = sConn.SetDeadline(time.Time{}); err != nil {
2022-08-28 17:02:53 +00:00
_ = c.Close()
2016-04-18 07:16:40 +00:00
return
}
2017-03-08 18:03:47 +00:00
c = sConn
2016-04-18 07:16:40 +00:00
xl.Debug("new request host [%s] path [%s] httpUser [%s]", name, path, httpUser)
err = errors.PanicToError(func() {
l.accept <- c
})
if err != nil {
2019-10-12 12:13:12 +00:00
xl.Warn("listener is already closed, ignore this request")
}
2016-04-18 07:16:40 +00:00
}
type Listener struct {
name string
location string
routeByHTTPUser string
rewriteHost string
2023-03-07 11:53:32 +00:00
username string
password string
mux *Muxer // for closing Muxer
accept chan net.Conn
ctx context.Context
2016-04-18 07:16:40 +00:00
}
2019-10-12 12:13:12 +00:00
func (l *Listener) Accept() (net.Conn, error) {
xl := xlog.FromContextSafe(l.ctx)
2016-04-18 07:16:40 +00:00
conn, ok := <-l.accept
if !ok {
return nil, fmt.Errorf("Listener closed")
}
2023-03-07 11:53:32 +00:00
// if rewriteHost func is exist
// rewrite http requests with a modified host header
// if l.rewriteHost is empty, nothing to do
2023-03-07 11:53:32 +00:00
if l.mux.rewriteHost != nil {
sConn, err := l.mux.rewriteHost(conn, l.rewriteHost)
if err != nil {
2019-10-12 12:13:12 +00:00
xl.Warn("host header rewrite failed: %v", err)
2017-03-11 18:03:24 +00:00
return nil, fmt.Errorf("host header rewrite failed")
}
2019-10-12 12:13:12 +00:00
xl.Debug("rewrite host to [%s] success", l.rewriteHost)
2017-03-08 18:03:47 +00:00
conn = sConn
}
2023-05-29 06:10:34 +00:00
return utilnet.NewContextConn(l.ctx, conn), nil
2016-04-18 07:16:40 +00:00
}
func (l *Listener) Close() error {
l.mux.registryRouter.Del(l.name, l.location, l.routeByHTTPUser)
2016-04-18 07:16:40 +00:00
close(l.accept)
return nil
}
func (l *Listener) Name() string {
return l.name
}
2019-10-12 12:13:12 +00:00
func (l *Listener) Addr() net.Addr {
return (*net.TCPAddr)(nil)
}