feat: support arbitrary URL proxy via single token
Build and Push to GHCR / build-and-push (push) Has been cancelled

Allow proxying to any URL through the single-token auth path:
- /TOKEN/https://target.com/path
- /TOKEN/https:/target.com/path (browser-normalized)
- /TOKEN/target.com/path (auto-prefixed with https:// for known domains)

Also fix single-mode path handling that previously dropped
parts[2] when SplitN produced 3 parts.

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
This commit is contained in:
Agent
2026-05-24 16:22:02 +08:00
co-authored by HAPI
parent e8f760e510
commit fdbb824b7e
3 changed files with 126 additions and 1 deletions
+80
View File
@@ -16,6 +16,80 @@ import (
"mirror-proxy/internal/proxy"
)
import (
"net/url"
)
// extractTargetURL 从请求路径中提取目标 URL
// 支持格式: /https://target.com/path 或 /http://target.com/path 或 /target.com/path
// 如果匹配,修改 r.URL.Path 为目标路径并返回目标 URL
func extractTargetURL(r *http.Request) (string, bool) {
path := strings.TrimPrefix(r.URL.Path, "/")
// 完整 URL 格式: https://... 或 http://...
if strings.HasPrefix(path, "https://") {
u, err := url.Parse(path)
if err == nil {
r.URL.Path = u.Path
if u.RawQuery != "" {
r.URL.RawQuery = u.RawQuery
}
return path, true
}
}
if strings.HasPrefix(path, "http://") {
u, err := url.Parse(path)
if err == nil {
r.URL.Path = u.Path
if u.RawQuery != "" {
r.URL.RawQuery = u.RawQuery
}
return path, true
}
}
// 浏览器规范化后的格式: https:/... 或 http:/...
if strings.HasPrefix(path, "https:/") {
targetURL := "https://" + strings.TrimPrefix(path, "https:/")
u, err := url.Parse(targetURL)
if err == nil {
r.URL.Path = u.Path
if u.RawQuery != "" {
r.URL.RawQuery = u.RawQuery
}
return targetURL, true
}
}
if strings.HasPrefix(path, "http:/") {
targetURL := "http://" + strings.TrimPrefix(path, "http:/")
u, err := url.Parse(targetURL)
if err == nil {
r.URL.Path = u.Path
if u.RawQuery != "" {
r.URL.RawQuery = u.RawQuery
}
return targetURL, true
}
}
// 无协议前缀的域名
if strings.HasPrefix(path, "github.com/") ||
strings.HasPrefix(path, "raw.githubusercontent.com/") ||
strings.HasPrefix(path, "api.github.com/") {
targetURL := "https://" + path
u, err := url.Parse(targetURL)
if err == nil {
r.URL.Path = u.Path
if u.RawQuery != "" {
r.URL.RawQuery = u.RawQuery
}
return targetURL, true
}
}
return "", false
}
func buildHandler(cfg *config.Config) (*admin.Handler, http.Handler) {
rl := auth.NewRateLimiter()
adminHandler := admin.NewHandler(cfg)
@@ -78,6 +152,12 @@ func buildHandler(cfg *config.Config) (*admin.Handler, http.Handler) {
return
}
// URL 代理模式: /https://target.com/path 或 /target.com/path
if targetURL, isURL := extractTargetURL(r); isURL {
proxy.DynamicProxy(targetURL).ServeHTTP(w, r)
return
}
switch link.Type {
case "docker":
dockerProxy.ServeHTTP(w, r)
+1 -1
View File
@@ -152,7 +152,7 @@ func ProxyAuthMiddleware(rl *RateLimiter) func(http.Handler) http.Handler {
if len(parts) == 1 {
newPath = "/"
} else {
newPath = "/" + parts[1]
newPath = "/" + strings.Join(parts[1:], "/")
}
}
}
+45
View File
@@ -0,0 +1,45 @@
package proxy
import (
"fmt"
"net/http"
"net/http/httputil"
"net/url"
"time"
)
// DynamicProxy 创建指向任意目标 URL 的反向代理
func DynamicProxy(targetURL string) http.Handler {
target, err := url.Parse(targetURL)
if err != nil {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
http.Error(w, "Invalid target URL", http.StatusBadRequest)
})
}
p := &httputil.ReverseProxy{
Director: func(req *http.Request) {
req.URL.Scheme = target.Scheme
req.URL.Host = target.Host
req.Host = target.Host
req.Header.Set("Host", target.Host)
if req.Header.Get("User-Agent") == "" {
req.Header.Set("User-Agent", "MirrorProxy/1.0")
}
req.Header.Del("X-Forwarded-For")
},
ErrorHandler: func(w http.ResponseWriter, r *http.Request, err error) {
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
w.WriteHeader(http.StatusBadGateway)
fmt.Fprintf(w, "Proxy error: %s", err.Error())
},
Transport: &http.Transport{
MaxIdleConns: 100,
MaxIdleConnsPerHost: 20,
IdleConnTimeout: 90 * time.Second,
TLSHandshakeTimeout: 10 * time.Second,
},
}
return p
}