feat: support arbitrary URL proxy via single token
Build and Push to GHCR / build-and-push (push) Has been cancelled
Build and Push to GHCR / build-and-push (push) Has been cancelled
Allow proxying to any URL through the single-token auth path: - /TOKEN/https://target.com/path - /TOKEN/https:/target.com/path (browser-normalized) - /TOKEN/target.com/path (auto-prefixed with https:// for known domains) Also fix single-mode path handling that previously dropped parts[2] when SplitN produced 3 parts. via [HAPI](https://hapi.run) Co-Authored-By: HAPI <[email protected]>
This commit is contained in:
+80
@@ -16,6 +16,80 @@ import (
|
|||||||
"mirror-proxy/internal/proxy"
|
"mirror-proxy/internal/proxy"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
import (
|
||||||
|
"net/url"
|
||||||
|
)
|
||||||
|
|
||||||
|
// extractTargetURL 从请求路径中提取目标 URL
|
||||||
|
// 支持格式: /https://target.com/path 或 /http://target.com/path 或 /target.com/path
|
||||||
|
// 如果匹配,修改 r.URL.Path 为目标路径并返回目标 URL
|
||||||
|
func extractTargetURL(r *http.Request) (string, bool) {
|
||||||
|
path := strings.TrimPrefix(r.URL.Path, "/")
|
||||||
|
|
||||||
|
// 完整 URL 格式: https://... 或 http://...
|
||||||
|
if strings.HasPrefix(path, "https://") {
|
||||||
|
u, err := url.Parse(path)
|
||||||
|
if err == nil {
|
||||||
|
r.URL.Path = u.Path
|
||||||
|
if u.RawQuery != "" {
|
||||||
|
r.URL.RawQuery = u.RawQuery
|
||||||
|
}
|
||||||
|
return path, true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if strings.HasPrefix(path, "http://") {
|
||||||
|
u, err := url.Parse(path)
|
||||||
|
if err == nil {
|
||||||
|
r.URL.Path = u.Path
|
||||||
|
if u.RawQuery != "" {
|
||||||
|
r.URL.RawQuery = u.RawQuery
|
||||||
|
}
|
||||||
|
return path, true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// 浏览器规范化后的格式: https:/... 或 http:/...
|
||||||
|
if strings.HasPrefix(path, "https:/") {
|
||||||
|
targetURL := "https://" + strings.TrimPrefix(path, "https:/")
|
||||||
|
u, err := url.Parse(targetURL)
|
||||||
|
if err == nil {
|
||||||
|
r.URL.Path = u.Path
|
||||||
|
if u.RawQuery != "" {
|
||||||
|
r.URL.RawQuery = u.RawQuery
|
||||||
|
}
|
||||||
|
return targetURL, true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if strings.HasPrefix(path, "http:/") {
|
||||||
|
targetURL := "http://" + strings.TrimPrefix(path, "http:/")
|
||||||
|
u, err := url.Parse(targetURL)
|
||||||
|
if err == nil {
|
||||||
|
r.URL.Path = u.Path
|
||||||
|
if u.RawQuery != "" {
|
||||||
|
r.URL.RawQuery = u.RawQuery
|
||||||
|
}
|
||||||
|
return targetURL, true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// 无协议前缀的域名
|
||||||
|
if strings.HasPrefix(path, "github.com/") ||
|
||||||
|
strings.HasPrefix(path, "raw.githubusercontent.com/") ||
|
||||||
|
strings.HasPrefix(path, "api.github.com/") {
|
||||||
|
targetURL := "https://" + path
|
||||||
|
u, err := url.Parse(targetURL)
|
||||||
|
if err == nil {
|
||||||
|
r.URL.Path = u.Path
|
||||||
|
if u.RawQuery != "" {
|
||||||
|
r.URL.RawQuery = u.RawQuery
|
||||||
|
}
|
||||||
|
return targetURL, true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return "", false
|
||||||
|
}
|
||||||
|
|
||||||
func buildHandler(cfg *config.Config) (*admin.Handler, http.Handler) {
|
func buildHandler(cfg *config.Config) (*admin.Handler, http.Handler) {
|
||||||
rl := auth.NewRateLimiter()
|
rl := auth.NewRateLimiter()
|
||||||
adminHandler := admin.NewHandler(cfg)
|
adminHandler := admin.NewHandler(cfg)
|
||||||
@@ -78,6 +152,12 @@ func buildHandler(cfg *config.Config) (*admin.Handler, http.Handler) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// URL 代理模式: /https://target.com/path 或 /target.com/path
|
||||||
|
if targetURL, isURL := extractTargetURL(r); isURL {
|
||||||
|
proxy.DynamicProxy(targetURL).ServeHTTP(w, r)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
switch link.Type {
|
switch link.Type {
|
||||||
case "docker":
|
case "docker":
|
||||||
dockerProxy.ServeHTTP(w, r)
|
dockerProxy.ServeHTTP(w, r)
|
||||||
|
|||||||
@@ -152,7 +152,7 @@ func ProxyAuthMiddleware(rl *RateLimiter) func(http.Handler) http.Handler {
|
|||||||
if len(parts) == 1 {
|
if len(parts) == 1 {
|
||||||
newPath = "/"
|
newPath = "/"
|
||||||
} else {
|
} else {
|
||||||
newPath = "/" + parts[1]
|
newPath = "/" + strings.Join(parts[1:], "/")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,45 @@
|
|||||||
|
package proxy
|
||||||
|
|
||||||
|
import (
|
||||||
|
"fmt"
|
||||||
|
"net/http"
|
||||||
|
"net/http/httputil"
|
||||||
|
"net/url"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// DynamicProxy 创建指向任意目标 URL 的反向代理
|
||||||
|
func DynamicProxy(targetURL string) http.Handler {
|
||||||
|
target, err := url.Parse(targetURL)
|
||||||
|
if err != nil {
|
||||||
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
http.Error(w, "Invalid target URL", http.StatusBadRequest)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
p := &httputil.ReverseProxy{
|
||||||
|
Director: func(req *http.Request) {
|
||||||
|
req.URL.Scheme = target.Scheme
|
||||||
|
req.URL.Host = target.Host
|
||||||
|
req.Host = target.Host
|
||||||
|
req.Header.Set("Host", target.Host)
|
||||||
|
if req.Header.Get("User-Agent") == "" {
|
||||||
|
req.Header.Set("User-Agent", "MirrorProxy/1.0")
|
||||||
|
}
|
||||||
|
req.Header.Del("X-Forwarded-For")
|
||||||
|
},
|
||||||
|
ErrorHandler: func(w http.ResponseWriter, r *http.Request, err error) {
|
||||||
|
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
|
||||||
|
w.WriteHeader(http.StatusBadGateway)
|
||||||
|
fmt.Fprintf(w, "Proxy error: %s", err.Error())
|
||||||
|
},
|
||||||
|
Transport: &http.Transport{
|
||||||
|
MaxIdleConns: 100,
|
||||||
|
MaxIdleConnsPerHost: 20,
|
||||||
|
IdleConnTimeout: 90 * time.Second,
|
||||||
|
TLSHandshakeTimeout: 10 * time.Second,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
return p
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user