feat: support arbitrary URL proxy via single token
Build and Push to GHCR / build-and-push (push) Has been cancelled
Build and Push to GHCR / build-and-push (push) Has been cancelled
Allow proxying to any URL through the single-token auth path: - /TOKEN/https://target.com/path - /TOKEN/https:/target.com/path (browser-normalized) - /TOKEN/target.com/path (auto-prefixed with https:// for known domains) Also fix single-mode path handling that previously dropped parts[2] when SplitN produced 3 parts. via [HAPI](https://hapi.run) Co-Authored-By: HAPI <[email protected]>
This commit is contained in:
+80
@@ -16,6 +16,80 @@ import (
|
||||
"mirror-proxy/internal/proxy"
|
||||
)
|
||||
|
||||
import (
|
||||
"net/url"
|
||||
)
|
||||
|
||||
// extractTargetURL 从请求路径中提取目标 URL
|
||||
// 支持格式: /https://target.com/path 或 /http://target.com/path 或 /target.com/path
|
||||
// 如果匹配,修改 r.URL.Path 为目标路径并返回目标 URL
|
||||
func extractTargetURL(r *http.Request) (string, bool) {
|
||||
path := strings.TrimPrefix(r.URL.Path, "/")
|
||||
|
||||
// 完整 URL 格式: https://... 或 http://...
|
||||
if strings.HasPrefix(path, "https://") {
|
||||
u, err := url.Parse(path)
|
||||
if err == nil {
|
||||
r.URL.Path = u.Path
|
||||
if u.RawQuery != "" {
|
||||
r.URL.RawQuery = u.RawQuery
|
||||
}
|
||||
return path, true
|
||||
}
|
||||
}
|
||||
if strings.HasPrefix(path, "http://") {
|
||||
u, err := url.Parse(path)
|
||||
if err == nil {
|
||||
r.URL.Path = u.Path
|
||||
if u.RawQuery != "" {
|
||||
r.URL.RawQuery = u.RawQuery
|
||||
}
|
||||
return path, true
|
||||
}
|
||||
}
|
||||
|
||||
// 浏览器规范化后的格式: https:/... 或 http:/...
|
||||
if strings.HasPrefix(path, "https:/") {
|
||||
targetURL := "https://" + strings.TrimPrefix(path, "https:/")
|
||||
u, err := url.Parse(targetURL)
|
||||
if err == nil {
|
||||
r.URL.Path = u.Path
|
||||
if u.RawQuery != "" {
|
||||
r.URL.RawQuery = u.RawQuery
|
||||
}
|
||||
return targetURL, true
|
||||
}
|
||||
}
|
||||
if strings.HasPrefix(path, "http:/") {
|
||||
targetURL := "http://" + strings.TrimPrefix(path, "http:/")
|
||||
u, err := url.Parse(targetURL)
|
||||
if err == nil {
|
||||
r.URL.Path = u.Path
|
||||
if u.RawQuery != "" {
|
||||
r.URL.RawQuery = u.RawQuery
|
||||
}
|
||||
return targetURL, true
|
||||
}
|
||||
}
|
||||
|
||||
// 无协议前缀的域名
|
||||
if strings.HasPrefix(path, "github.com/") ||
|
||||
strings.HasPrefix(path, "raw.githubusercontent.com/") ||
|
||||
strings.HasPrefix(path, "api.github.com/") {
|
||||
targetURL := "https://" + path
|
||||
u, err := url.Parse(targetURL)
|
||||
if err == nil {
|
||||
r.URL.Path = u.Path
|
||||
if u.RawQuery != "" {
|
||||
r.URL.RawQuery = u.RawQuery
|
||||
}
|
||||
return targetURL, true
|
||||
}
|
||||
}
|
||||
|
||||
return "", false
|
||||
}
|
||||
|
||||
func buildHandler(cfg *config.Config) (*admin.Handler, http.Handler) {
|
||||
rl := auth.NewRateLimiter()
|
||||
adminHandler := admin.NewHandler(cfg)
|
||||
@@ -78,6 +152,12 @@ func buildHandler(cfg *config.Config) (*admin.Handler, http.Handler) {
|
||||
return
|
||||
}
|
||||
|
||||
// URL 代理模式: /https://target.com/path 或 /target.com/path
|
||||
if targetURL, isURL := extractTargetURL(r); isURL {
|
||||
proxy.DynamicProxy(targetURL).ServeHTTP(w, r)
|
||||
return
|
||||
}
|
||||
|
||||
switch link.Type {
|
||||
case "docker":
|
||||
dockerProxy.ServeHTTP(w, r)
|
||||
|
||||
@@ -152,7 +152,7 @@ func ProxyAuthMiddleware(rl *RateLimiter) func(http.Handler) http.Handler {
|
||||
if len(parts) == 1 {
|
||||
newPath = "/"
|
||||
} else {
|
||||
newPath = "/" + parts[1]
|
||||
newPath = "/" + strings.Join(parts[1:], "/")
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,45 @@
|
||||
package proxy
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"net/http"
|
||||
"net/http/httputil"
|
||||
"net/url"
|
||||
"time"
|
||||
)
|
||||
|
||||
// DynamicProxy 创建指向任意目标 URL 的反向代理
|
||||
func DynamicProxy(targetURL string) http.Handler {
|
||||
target, err := url.Parse(targetURL)
|
||||
if err != nil {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
http.Error(w, "Invalid target URL", http.StatusBadRequest)
|
||||
})
|
||||
}
|
||||
|
||||
p := &httputil.ReverseProxy{
|
||||
Director: func(req *http.Request) {
|
||||
req.URL.Scheme = target.Scheme
|
||||
req.URL.Host = target.Host
|
||||
req.Host = target.Host
|
||||
req.Header.Set("Host", target.Host)
|
||||
if req.Header.Get("User-Agent") == "" {
|
||||
req.Header.Set("User-Agent", "MirrorProxy/1.0")
|
||||
}
|
||||
req.Header.Del("X-Forwarded-For")
|
||||
},
|
||||
ErrorHandler: func(w http.ResponseWriter, r *http.Request, err error) {
|
||||
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
|
||||
w.WriteHeader(http.StatusBadGateway)
|
||||
fmt.Fprintf(w, "Proxy error: %s", err.Error())
|
||||
},
|
||||
Transport: &http.Transport{
|
||||
MaxIdleConns: 100,
|
||||
MaxIdleConnsPerHost: 20,
|
||||
IdleConnTimeout: 90 * time.Second,
|
||||
TLSHandshakeTimeout: 10 * time.Second,
|
||||
},
|
||||
}
|
||||
|
||||
return p
|
||||
}
|
||||
Reference in New Issue
Block a user