Add WITH_PROXY flag
This commit is contained in:
@@ -6,6 +6,11 @@ override LDFLAGS += uSockets/*.o -lz
|
|||||||
DESTDIR ?=
|
DESTDIR ?=
|
||||||
prefix ?= /usr/local
|
prefix ?= /usr/local
|
||||||
|
|
||||||
|
# WITH_PROXY enables PROXY Protocol v2 support
|
||||||
|
ifeq ($(WITH_PROXY),1)
|
||||||
|
override CXXFLAGS += -DWITH_PROXY
|
||||||
|
endif
|
||||||
|
|
||||||
# WITH_OPENSSL=1 enables OpenSSL 1.1+ support
|
# WITH_OPENSSL=1 enables OpenSSL 1.1+ support
|
||||||
ifeq ($(WITH_OPENSSL),1)
|
ifeq ($(WITH_OPENSSL),1)
|
||||||
# With problems on macOS, make sure to pass needed LDFLAGS required to find these
|
# With problems on macOS, make sure to pass needed LDFLAGS required to find these
|
||||||
|
|||||||
+7
-2
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Authored by Alex Hultman, 2018-2019.
|
* Authored by Alex Hultman, 2018-2020.
|
||||||
* Intellectual property of third-party.
|
* Intellectual property of third-party.
|
||||||
|
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
@@ -126,8 +126,13 @@ private:
|
|||||||
// clients need to know the cursor after http parse, not servers!
|
// clients need to know the cursor after http parse, not servers!
|
||||||
// how far did we read then? we need to know to continue with websocket parsing data? or?
|
// how far did we read then? we need to know to continue with websocket parsing data? or?
|
||||||
|
|
||||||
|
void *proxyParser = nullptr;
|
||||||
|
#ifdef WITH_PROXY
|
||||||
|
proxyParser = &httpResponseData->proxyParser;
|
||||||
|
#endif
|
||||||
|
|
||||||
/* The return value is entirely up to us to interpret. The HttpParser only care for whether the returned value is DIFFERENT or not from passed user */
|
/* The return value is entirely up to us to interpret. The HttpParser only care for whether the returned value is DIFFERENT or not from passed user */
|
||||||
void *returnedSocket = httpResponseData->consumePostPadded(data, length, s, [httpContextData](void *s, uWS::HttpRequest *httpRequest) -> void * {
|
void *returnedSocket = httpResponseData->consumePostPadded(data, length, s, proxyParser, [httpContextData](void *s, uWS::HttpRequest *httpRequest) -> void * {
|
||||||
/* For every request we reset the timeout and hang until user makes action */
|
/* For every request we reset the timeout and hang until user makes action */
|
||||||
/* Warning: if we are in shutdown state, resetting the timer is a security issue! */
|
/* Warning: if we are in shutdown state, resetting the timer is a security issue! */
|
||||||
us_socket_timeout(SSL, (us_socket_t *) s, 0);
|
us_socket_timeout(SSL, (us_socket_t *) s, 0);
|
||||||
|
|||||||
+30
-25
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Authored by Alex Hultman, 2018-2019.
|
* Authored by Alex Hultman, 2018-2020.
|
||||||
* Intellectual property of third-party.
|
* Intellectual property of third-party.
|
||||||
|
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
@@ -28,8 +28,13 @@
|
|||||||
#include "f2/function2.hpp"
|
#include "f2/function2.hpp"
|
||||||
|
|
||||||
#include "BloomFilter.h"
|
#include "BloomFilter.h"
|
||||||
|
|
||||||
|
|
||||||
|
// if using proxy parser, depend on the layout of HttpResponesData
|
||||||
#include "ProxyParser.h"
|
#include "ProxyParser.h"
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
namespace uWS {
|
namespace uWS {
|
||||||
|
|
||||||
/* We require at least this much post padding */
|
/* We require at least this much post padding */
|
||||||
@@ -178,8 +183,28 @@ private:
|
|||||||
|
|
||||||
// the only caller of getHeaders
|
// the only caller of getHeaders
|
||||||
template <int CONSUME_MINIMALLY>
|
template <int CONSUME_MINIMALLY>
|
||||||
std::pair<int, void *> fenceAndConsumePostPadded(char *data, int length, void *user, HttpRequest *req, fu2::unique_function<void *(void *, HttpRequest *)> &requestHandler, fu2::unique_function<void *(void *, std::string_view, bool)> &dataHandler) {
|
std::pair<int, void *> fenceAndConsumePostPadded(char *data, int length, void *user, void *reserved, HttpRequest *req, fu2::unique_function<void *(void *, HttpRequest *)> &requestHandler, fu2::unique_function<void *(void *, std::string_view, bool)> &dataHandler) {
|
||||||
|
|
||||||
|
/* How much data we CONSUMED (to throw away) */
|
||||||
int consumedTotal = 0;
|
int consumedTotal = 0;
|
||||||
|
|
||||||
|
#ifdef WITH_PROXY
|
||||||
|
/* ProxyParser is passed as reserved parameter */
|
||||||
|
ProxyParser *pp = (ProxyParser *) reserved;
|
||||||
|
|
||||||
|
/* Parse PROXY protocol */
|
||||||
|
auto [done, offset] = pp->parse({data, length});
|
||||||
|
if (!done) {
|
||||||
|
return {0, user};
|
||||||
|
} else {
|
||||||
|
/* We have consumed this data so skip it */
|
||||||
|
data += offset;
|
||||||
|
length -= offset;
|
||||||
|
consumedTotal += offset;
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
|
/* Fence one byte past end of our buffer (buffer has post padded margins) */
|
||||||
data[length] = '\r';
|
data[length] = '\r';
|
||||||
|
|
||||||
for (int consumed; length && (consumed = getHeaders(data, data + length, req->headers, &req->bf)); ) {
|
for (int consumed; length && (consumed = getHeaders(data, data + length, req->headers, &req->bf)); ) {
|
||||||
@@ -236,13 +261,7 @@ private:
|
|||||||
}
|
}
|
||||||
|
|
||||||
public:
|
public:
|
||||||
|
void *consumePostPadded(char *data, int length, void *user, void *reserved, fu2::unique_function<void *(void *, HttpRequest *)> &&requestHandler, fu2::unique_function<void *(void *, std::string_view, bool)> &&dataHandler, fu2::unique_function<void *(void *)> &&errorHandler) {
|
||||||
/* We do this to prolong the validity of parsed headers by keeping only the fallback buffer alive */
|
|
||||||
/*std::string &&salvageFallbackBuffer() {
|
|
||||||
return std::move(fallback);
|
|
||||||
}*/
|
|
||||||
|
|
||||||
void *consumePostPadded(char *data, int length, void *user, fu2::unique_function<void *(void *, HttpRequest *)> &&requestHandler, fu2::unique_function<void *(void *, std::string_view, bool)> &&dataHandler, fu2::unique_function<void *(void *)> &&errorHandler) {
|
|
||||||
|
|
||||||
HttpRequest req;
|
HttpRequest req;
|
||||||
|
|
||||||
@@ -276,11 +295,8 @@ public:
|
|||||||
fallback.reserve(fallback.length() + maxCopyDistance + std::max<int>(MINIMUM_HTTP_POST_PADDING, sizeof(std::string)));
|
fallback.reserve(fallback.length() + maxCopyDistance + std::max<int>(MINIMUM_HTTP_POST_PADDING, sizeof(std::string)));
|
||||||
fallback.append(data, maxCopyDistance);
|
fallback.append(data, maxCopyDistance);
|
||||||
|
|
||||||
// parse proxy here
|
|
||||||
|
|
||||||
|
|
||||||
// break here on break
|
// break here on break
|
||||||
std::pair<int, void *> consumed = fenceAndConsumePostPadded<true>(fallback.data(), (int) fallback.length(), user, &req, requestHandler, dataHandler);
|
std::pair<int, void *> consumed = fenceAndConsumePostPadded<true>(fallback.data(), (int) fallback.length(), user, reserved, &req, requestHandler, dataHandler);
|
||||||
if (consumed.second != user) {
|
if (consumed.second != user) {
|
||||||
return consumed.second;
|
return consumed.second;
|
||||||
}
|
}
|
||||||
@@ -322,18 +338,7 @@ public:
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// parse proxy here
|
std::pair<int, void *> consumed = fenceAndConsumePostPadded<false>(data, length, user, reserved, &req, requestHandler, dataHandler);
|
||||||
/* Parse proxy header */
|
|
||||||
ProxyParser pp;
|
|
||||||
auto [done, offset] = pp.parse({data, length});
|
|
||||||
|
|
||||||
if (!done) {
|
|
||||||
|
|
||||||
} else {
|
|
||||||
printf("Proxy parser is done\n");
|
|
||||||
}
|
|
||||||
|
|
||||||
std::pair<int, void *> consumed = fenceAndConsumePostPadded<false>(data, length, user, &req, requestHandler, dataHandler);
|
|
||||||
if (consumed.second != user) {
|
if (consumed.second != user) {
|
||||||
return consumed.second;
|
return consumed.second;
|
||||||
}
|
}
|
||||||
|
|||||||
+1
-1
@@ -55,7 +55,7 @@ private:
|
|||||||
/* If we have proxy support */
|
/* If we have proxy support */
|
||||||
#ifdef WITH_PROXY
|
#ifdef WITH_PROXY
|
||||||
void getProxiedRemoteAddress() {
|
void getProxiedRemoteAddress() {
|
||||||
|
getHttpResponseData()->proxyParser.getSourceIp();
|
||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Authored by Alex Hultman, 2018-2019.
|
* Authored by Alex Hultman, 2018-2020.
|
||||||
* Intellectual property of third-party.
|
* Intellectual property of third-party.
|
||||||
|
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
@@ -25,6 +25,8 @@
|
|||||||
|
|
||||||
#include "f2/function2.hpp"
|
#include "f2/function2.hpp"
|
||||||
|
|
||||||
|
#include "ProxyParser.h"
|
||||||
|
|
||||||
namespace uWS {
|
namespace uWS {
|
||||||
|
|
||||||
template <bool SSL>
|
template <bool SSL>
|
||||||
@@ -50,6 +52,11 @@ private:
|
|||||||
|
|
||||||
/* Current state (content-length sent, status sent, write called, etc */
|
/* Current state (content-length sent, status sent, write called, etc */
|
||||||
int state = 0;
|
int state = 0;
|
||||||
|
|
||||||
|
#ifdef WITH_PROXY
|
||||||
|
// proxy protocol
|
||||||
|
ProxyParser proxyParser;
|
||||||
|
#endif
|
||||||
};
|
};
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
+77
-25
@@ -2,43 +2,95 @@
|
|||||||
|
|
||||||
// implements PROXY v2 protocol
|
// implements PROXY v2 protocol
|
||||||
|
|
||||||
|
#ifndef PROXY_PARSER
|
||||||
|
#define PROXY_PARSER
|
||||||
|
|
||||||
|
#ifdef WITH_PROXY
|
||||||
|
|
||||||
|
struct proxy_hdr_v2 {
|
||||||
|
uint8_t sig[12]; /* hex 0D 0A 0D 0A 00 0D 0A 51 55 49 54 0A */
|
||||||
|
uint8_t ver_cmd; /* protocol version and command */
|
||||||
|
uint8_t fam; /* protocol family and address */
|
||||||
|
uint16_t len; /* number of following bytes part of the header */
|
||||||
|
};
|
||||||
|
|
||||||
|
/* Byte swap for little-endian systems */
|
||||||
|
template <typename T>
|
||||||
|
T _cond_byte_swap(T value) {
|
||||||
|
uint32_t endian_test = 1;
|
||||||
|
if (*((char *)&endian_test)) {
|
||||||
|
union {
|
||||||
|
T i;
|
||||||
|
uint8_t b[sizeof(T)];
|
||||||
|
} src = { value }, dst;
|
||||||
|
|
||||||
|
for (unsigned int i = 0; i < sizeof(value); i++) {
|
||||||
|
dst.b[i] = src.b[sizeof(value) - 1 - i];
|
||||||
|
}
|
||||||
|
|
||||||
|
return dst.i;
|
||||||
|
}
|
||||||
|
return value;
|
||||||
|
}
|
||||||
|
|
||||||
struct ProxyParser {
|
struct ProxyParser {
|
||||||
int done = false;
|
private:
|
||||||
|
unsigned char sourceIp[16];
|
||||||
|
unsigned char destIp[16];
|
||||||
|
uint16_t sourcePort, destPort;
|
||||||
|
|
||||||
// 16 byte IP, 2 byte port
|
public:
|
||||||
// 16 byte our IP, 2 byte our port
|
/* Returns 4 or 16 bytes */
|
||||||
|
std::string_view getSourceIP() {
|
||||||
|
return {"hello", 5};
|
||||||
|
}
|
||||||
|
|
||||||
// return true when done, always return next offset for http parsing
|
/* Returns [done, consumed] where done = false on failure */
|
||||||
std::pair<bool, unsigned int> parse(std::string_view data) {
|
std::pair<bool, unsigned int> parse(std::string_view data) {
|
||||||
|
|
||||||
/* If already parsed, we're done */
|
/* We require at least one byte to be done */
|
||||||
if (done) {
|
if (!data.length()) {
|
||||||
|
return {false, 0};
|
||||||
|
}
|
||||||
|
|
||||||
|
/* HTTP does not start with \r, but PROXY always does */
|
||||||
|
if (data[0] != '\r') {
|
||||||
|
//printf("This is HTTP\n");
|
||||||
|
/* This is HTTP, so be done */
|
||||||
return {true, 0};
|
return {true, 0};
|
||||||
}
|
}
|
||||||
|
|
||||||
// we require 4 bytes to determine if this is http or not
|
/* We assume we are parsing PROXY V2 here */
|
||||||
if (data.length() < 4) {
|
printf("This is PROXY v2\n");
|
||||||
// we are not done, buffer everything
|
|
||||||
|
/* We require 16 bytes here */
|
||||||
|
if (data.length() < 16) {
|
||||||
return {false, 0};
|
return {false, 0};
|
||||||
} else {
|
|
||||||
|
|
||||||
|
|
||||||
// is this proxy protocol?
|
|
||||||
if (memcmp("\r\n\r\n", data.data(), 4) == 0) {
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
} else {
|
|
||||||
// it cannot be proxy protocol here, so we are done now
|
|
||||||
done = true;
|
|
||||||
return {true, 0};
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
struct proxy_hdr_v2 header;
|
||||||
|
memcpy(&header, data.data(), 16);
|
||||||
|
|
||||||
|
if (memcmp(header.sig, "\x0D\x0A\x0D\x0A\x00\x0D\x0A\x51\x55\x49\x54\x0A", 12)) {
|
||||||
|
/* This is not PROXY protocol at all */
|
||||||
|
return {false, 0};
|
||||||
|
}
|
||||||
|
|
||||||
|
printf("Version: %d\n", (header.ver_cmd & 0xf0) >> 4);
|
||||||
|
printf("Command: %d\n", (header.ver_cmd & 0x0f));
|
||||||
|
|
||||||
|
uint16_t hostLength = _cond_byte_swap<uint16_t>(header.len);
|
||||||
|
|
||||||
|
printf("Length: %d\n", hostLength);
|
||||||
|
|
||||||
|
printf("Family: %d\n", (header.fam & 0xf0) >> 4);
|
||||||
|
printf("Transport: %d\n", (header.fam & 0x0f));
|
||||||
|
|
||||||
|
return {true, 16 + hostLength};
|
||||||
}
|
}
|
||||||
|
|
||||||
};
|
};
|
||||||
|
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#endif
|
||||||
Reference in New Issue
Block a user