2022-07-19 22:15:54 +02:00
|
|
|
package proxy
|
|
|
|
|
|
|
|
import (
|
2022-08-10 21:15:35 +02:00
|
|
|
"context"
|
|
|
|
"fmt"
|
2022-08-15 23:29:31 +02:00
|
|
|
"github.com/openziti-test-kitchen/zrok/model"
|
2022-07-20 20:36:14 +02:00
|
|
|
"github.com/openziti-test-kitchen/zrok/util"
|
2022-07-20 20:16:01 +02:00
|
|
|
"github.com/openziti/sdk-golang/ziti"
|
|
|
|
"github.com/openziti/sdk-golang/ziti/config"
|
2022-08-15 23:52:24 +02:00
|
|
|
"github.com/openziti/sdk-golang/ziti/edge"
|
2022-07-20 20:16:01 +02:00
|
|
|
"github.com/pkg/errors"
|
2022-07-26 19:30:19 +02:00
|
|
|
"github.com/sirupsen/logrus"
|
2022-08-10 21:15:35 +02:00
|
|
|
"net"
|
2022-07-19 22:15:54 +02:00
|
|
|
"net/http"
|
2022-08-10 21:15:35 +02:00
|
|
|
"net/http/httputil"
|
|
|
|
"net/url"
|
2022-07-26 23:30:06 +02:00
|
|
|
"strings"
|
2022-07-19 22:15:54 +02:00
|
|
|
)
|
|
|
|
|
2022-08-10 21:15:35 +02:00
|
|
|
type Config struct {
|
|
|
|
IdentityPath string
|
|
|
|
Address string
|
|
|
|
}
|
|
|
|
|
2022-07-19 22:15:54 +02:00
|
|
|
func Run(cfg *Config) error {
|
2022-07-20 20:16:01 +02:00
|
|
|
zCfg, err := config.NewFromFile(cfg.IdentityPath)
|
|
|
|
if err != nil {
|
|
|
|
return errors.Wrap(err, "error loading config")
|
|
|
|
}
|
2022-08-15 23:29:31 +02:00
|
|
|
zCfg.ConfigTypes = []string{model.ZrokProxyConfig}
|
2022-07-20 20:16:01 +02:00
|
|
|
zCtx := ziti.NewContextWithConfig(zCfg)
|
2022-08-10 21:02:47 +02:00
|
|
|
zDialCtx := ZitiDialContext{Context: zCtx}
|
2022-07-21 21:26:44 +02:00
|
|
|
zTransport := http.DefaultTransport.(*http.Transport).Clone()
|
|
|
|
zTransport.DialContext = zDialCtx.Dial
|
2022-07-21 21:46:14 +02:00
|
|
|
|
2022-08-15 23:52:24 +02:00
|
|
|
proxy, err := NewServiceProxy(zCtx, &resolver{})
|
2022-07-20 20:36:14 +02:00
|
|
|
if err != nil {
|
2022-07-21 22:01:39 +02:00
|
|
|
return err
|
2022-07-20 20:36:14 +02:00
|
|
|
}
|
2022-07-21 21:46:14 +02:00
|
|
|
proxy.Transport = zTransport
|
2022-08-16 19:16:44 +02:00
|
|
|
return http.ListenAndServe(cfg.Address, basicAuth(util.NewProxyHandler(proxy), "zrok", &resolver{}, zCtx))
|
2022-07-19 22:15:54 +02:00
|
|
|
}
|
2022-07-26 19:30:19 +02:00
|
|
|
|
2022-08-10 21:15:35 +02:00
|
|
|
type resolver struct{}
|
2022-07-26 19:30:19 +02:00
|
|
|
|
|
|
|
func (r *resolver) Service(host string) string {
|
2022-07-27 18:58:16 +02:00
|
|
|
logrus.Debugf("host = '%v'", host)
|
2022-07-26 23:30:06 +02:00
|
|
|
tokens := strings.Split(host, ".")
|
|
|
|
if len(tokens) > 0 {
|
|
|
|
return tokens[0]
|
|
|
|
}
|
2022-07-26 19:30:19 +02:00
|
|
|
return "zrok"
|
|
|
|
}
|
2022-08-10 21:15:35 +02:00
|
|
|
|
|
|
|
type ZitiDialContext struct {
|
|
|
|
Context ziti.Context
|
|
|
|
}
|
|
|
|
|
|
|
|
func (self *ZitiDialContext) Dial(_ context.Context, _ string, addr string) (net.Conn, error) {
|
2022-08-15 21:18:40 +02:00
|
|
|
svcName := strings.Split(addr, ":")[0] // ignore :port (we get passed 'host:port')
|
|
|
|
return self.Context.Dial(svcName)
|
2022-08-10 21:15:35 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
type ProxyServiceResolver interface {
|
|
|
|
Service(host string) string
|
|
|
|
}
|
|
|
|
|
2022-08-15 23:52:24 +02:00
|
|
|
func NewServiceProxy(ctx ziti.Context, p ProxyServiceResolver) (*httputil.ReverseProxy, error) {
|
|
|
|
proxy := hostTargetReverseProxy(ctx, p)
|
2022-08-10 21:15:35 +02:00
|
|
|
director := proxy.Director
|
|
|
|
proxy.Director = func(req *http.Request) {
|
|
|
|
director(req)
|
|
|
|
logrus.Debugf("-> %v", req.URL.String())
|
|
|
|
req.Header.Set("X-Proxy", "zrok")
|
|
|
|
}
|
|
|
|
proxy.ModifyResponse = func(resp *http.Response) error {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
proxy.ErrorHandler = func(w http.ResponseWriter, r *http.Request, err error) {
|
|
|
|
logrus.Errorf("error proxying: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
return proxy, nil
|
|
|
|
}
|
|
|
|
|
2022-08-15 23:52:24 +02:00
|
|
|
func hostTargetReverseProxy(ctx ziti.Context, r ProxyServiceResolver) *httputil.ReverseProxy {
|
2022-08-10 21:15:35 +02:00
|
|
|
director := func(req *http.Request) {
|
|
|
|
targetSvc := r.Service(req.Host)
|
2022-08-15 23:52:24 +02:00
|
|
|
if svc, found := getRefreshedService(targetSvc, ctx); found {
|
|
|
|
if cfg, found := svc.Configs[model.ZrokProxyConfig]; found {
|
|
|
|
logrus.Infof("auth model: %v", cfg)
|
2022-08-10 21:15:35 +02:00
|
|
|
} else {
|
2022-08-15 23:52:24 +02:00
|
|
|
logrus.Warn("no config!")
|
2022-08-10 21:15:35 +02:00
|
|
|
}
|
2022-08-15 23:52:24 +02:00
|
|
|
if target, err := url.Parse(fmt.Sprintf("http://%v", targetSvc)); err == nil {
|
|
|
|
targetQuery := target.RawQuery
|
|
|
|
req.URL.Scheme = target.Scheme
|
|
|
|
req.URL.Host = target.Host
|
|
|
|
req.URL.Path, req.URL.RawPath = joinURLPath(target, req.URL)
|
|
|
|
if targetQuery == "" || req.URL.RawQuery == "" {
|
|
|
|
req.URL.RawQuery = targetQuery + req.URL.RawQuery
|
|
|
|
} else {
|
|
|
|
req.URL.RawQuery = targetQuery + "&" + req.URL.RawQuery
|
|
|
|
}
|
|
|
|
if _, ok := req.Header["User-Agent"]; !ok {
|
|
|
|
// explicitly disable User-Agent so it's not set to default value
|
|
|
|
req.Header.Set("User-Agent", "")
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
logrus.Errorf("error proxying: %v", err)
|
2022-08-10 21:15:35 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return &httputil.ReverseProxy{Director: director}
|
|
|
|
}
|
|
|
|
|
|
|
|
func joinURLPath(a, b *url.URL) (path, rawpath string) {
|
|
|
|
if a.RawPath == "" && b.RawPath == "" {
|
|
|
|
return singleJoiningSlash(a.Path, b.Path), ""
|
|
|
|
}
|
|
|
|
// Same as singleJoiningSlash, but uses EscapedPath to determine
|
|
|
|
// whether a slash should be added
|
|
|
|
apath := a.EscapedPath()
|
|
|
|
bpath := b.EscapedPath()
|
|
|
|
|
|
|
|
aslash := strings.HasSuffix(apath, "/")
|
|
|
|
bslash := strings.HasPrefix(bpath, "/")
|
|
|
|
|
|
|
|
switch {
|
|
|
|
case aslash && bslash:
|
|
|
|
return a.Path + b.Path[1:], apath + bpath[1:]
|
|
|
|
case !aslash && !bslash:
|
|
|
|
return a.Path + "/" + b.Path, apath + "/" + bpath
|
|
|
|
}
|
|
|
|
return a.Path + b.Path, apath + bpath
|
|
|
|
}
|
|
|
|
|
|
|
|
func singleJoiningSlash(a, b string) string {
|
|
|
|
aslash := strings.HasSuffix(a, "/")
|
|
|
|
bslash := strings.HasPrefix(b, "/")
|
|
|
|
switch {
|
|
|
|
case aslash && bslash:
|
|
|
|
return a + b[1:]
|
|
|
|
case !aslash && !bslash:
|
|
|
|
return a + "/" + b
|
|
|
|
}
|
|
|
|
return a + b
|
|
|
|
}
|
2022-08-15 23:52:24 +02:00
|
|
|
|
|
|
|
func getRefreshedService(name string, ctx ziti.Context) (*edge.Service, bool) {
|
|
|
|
svc, found := ctx.GetService(name)
|
|
|
|
if !found {
|
|
|
|
if err := ctx.RefreshServices(); err != nil {
|
|
|
|
logrus.Errorf("error refreshing services: %v", err)
|
|
|
|
return nil, false
|
|
|
|
}
|
|
|
|
return ctx.GetService(name)
|
|
|
|
}
|
|
|
|
return svc, found
|
|
|
|
}
|
2022-08-16 17:27:31 +02:00
|
|
|
|
2022-08-16 19:16:44 +02:00
|
|
|
func basicAuth(handler http.Handler, realm string, rslv ProxyServiceResolver, ctx ziti.Context) http.HandlerFunc {
|
2022-08-16 17:27:31 +02:00
|
|
|
return func(w http.ResponseWriter, r *http.Request) {
|
2022-08-16 17:41:04 +02:00
|
|
|
svcName := rslv.Service(r.Host)
|
|
|
|
if svc, found := getRefreshedService(svcName, ctx); found {
|
|
|
|
if cfg, found := svc.Configs[model.ZrokProxyConfig]; found {
|
|
|
|
if scheme, found := cfg["auth_scheme"]; found {
|
|
|
|
switch scheme {
|
2022-08-16 19:16:44 +02:00
|
|
|
case string(model.None):
|
|
|
|
logrus.Infof("auth scheme none '%v'", svcName)
|
2022-08-16 17:41:04 +02:00
|
|
|
handler.ServeHTTP(w, r)
|
|
|
|
return
|
|
|
|
|
2022-08-16 19:16:44 +02:00
|
|
|
case string(model.Basic):
|
|
|
|
logrus.Infof("auth scheme basic '%v", svcName)
|
2022-08-16 17:41:04 +02:00
|
|
|
inUser, inPass, ok := r.BasicAuth()
|
|
|
|
if !ok {
|
|
|
|
writeUnauthorizedResponse(w, realm)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
authed := false
|
2022-08-16 19:16:44 +02:00
|
|
|
if v, found := cfg["basic_auth"]; found {
|
|
|
|
if basicAuth, ok := v.(map[string]interface{}); ok {
|
|
|
|
if v, found := basicAuth["users"]; found {
|
|
|
|
if arr, ok := v.([]interface{}); ok {
|
|
|
|
for _, v := range arr {
|
|
|
|
if um, ok := v.(map[string]interface{}); ok {
|
|
|
|
username := ""
|
|
|
|
if v, found := um["username"]; found {
|
|
|
|
if un, ok := v.(string); ok {
|
|
|
|
username = un
|
|
|
|
}
|
|
|
|
}
|
|
|
|
password := ""
|
|
|
|
if v, found := um["password"]; found {
|
|
|
|
if pw, ok := v.(string); ok {
|
|
|
|
password = pw
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if username == inUser && password == inPass {
|
|
|
|
authed = true
|
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2022-08-16 17:41:04 +02:00
|
|
|
}
|
|
|
|
}
|
2022-08-16 19:16:44 +02:00
|
|
|
|
2022-08-16 17:41:04 +02:00
|
|
|
if !authed {
|
|
|
|
writeUnauthorizedResponse(w, realm)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
handler.ServeHTTP(w, r)
|
2022-08-16 19:16:44 +02:00
|
|
|
|
|
|
|
default:
|
|
|
|
logrus.Infof("invalid auth scheme '%v'", scheme)
|
|
|
|
writeUnauthorizedResponse(w, realm)
|
|
|
|
return
|
2022-08-16 17:41:04 +02:00
|
|
|
}
|
2022-08-16 19:16:44 +02:00
|
|
|
} else {
|
|
|
|
logrus.Infof("no auth scheme for '%v'", svcName)
|
2022-08-16 17:41:04 +02:00
|
|
|
}
|
2022-08-16 19:16:44 +02:00
|
|
|
} else {
|
|
|
|
logrus.Infof("no proxy config for '%v'", svcName)
|
2022-08-16 17:27:31 +02:00
|
|
|
}
|
2022-08-16 19:16:44 +02:00
|
|
|
} else {
|
|
|
|
logrus.Infof("service '%v' not found", svcName)
|
2022-08-16 17:27:31 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func writeUnauthorizedResponse(w http.ResponseWriter, realm string) {
|
|
|
|
w.Header().Set("WWW-Authenticate", `Basic realm="`+realm+`"`)
|
|
|
|
w.WriteHeader(401)
|
|
|
|
w.Write([]byte("No Authorization\n"))
|
|
|
|
}
|