Merge remote-tracking branch 'origin/caddy2' into v2multiauth
This commit is contained in:
commit
397bfdf7c1
7 changed files with 338 additions and 542 deletions
2
.github/workflows/golangci-lint.yml
vendored
2
.github/workflows/golangci-lint.yml
vendored
|
|
@ -22,4 +22,4 @@ jobs:
|
|||
- name: Run golangci-lint
|
||||
uses: reviewdog/action-golangci-lint@v2
|
||||
with:
|
||||
golangci_lint_flags: "--tests=false"
|
||||
golangci_lint_flags: "--tests=false --timeout=5m"
|
||||
|
|
|
|||
5
.github/workflows/tests.yml
vendored
5
.github/workflows/tests.yml
vendored
|
|
@ -18,6 +18,7 @@ jobs:
|
|||
strategy:
|
||||
matrix:
|
||||
go-version:
|
||||
- oldstable
|
||||
- stable
|
||||
platform:
|
||||
- ubuntu-latest
|
||||
|
|
@ -30,6 +31,4 @@ jobs:
|
|||
with:
|
||||
go-version: '${{ matrix.go-version }}'
|
||||
- name: Run test
|
||||
run: go test -v ./...
|
||||
- name: Run test -race
|
||||
run: go test -v -race ./...
|
||||
run: go test -v -race ./...
|
||||
|
|
|
|||
|
|
@ -368,6 +368,9 @@ func TestMain(m *testing.M) {
|
|||
panic(err)
|
||||
}
|
||||
|
||||
// wait server ready for tls dial
|
||||
time.Sleep(500 * time.Millisecond)
|
||||
|
||||
retCode := m.Run()
|
||||
|
||||
caddy.Stop()
|
||||
|
|
|
|||
|
|
@ -356,7 +356,7 @@ func (h *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request, next caddyht
|
|||
}
|
||||
r.Body, _ = r.GetBody()
|
||||
}
|
||||
response, _ = h.httpTransport.RoundTrip(r)
|
||||
response, err = h.httpTransport.RoundTrip(r)
|
||||
} else {
|
||||
// Upstream requests don't interact well with Transport: connections could always be
|
||||
// reused, but Transport thinks they go to different Hosts, so it spawns tons of
|
||||
|
|
@ -385,7 +385,10 @@ func (h *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request, next caddyht
|
|||
fmt.Errorf("failed to read upstream response: %v", err))
|
||||
}
|
||||
}
|
||||
err = r.Body.Close()
|
||||
if err := r.Body.Close(); err != nil {
|
||||
return caddyhttp.Error(http.StatusBadGateway,
|
||||
fmt.Errorf("failed to close response body: %v", err))
|
||||
}
|
||||
|
||||
if response != nil {
|
||||
defer response.Body.Close()
|
||||
|
|
|
|||
123
go.mod
123
go.mod
|
|
@ -1,29 +1,29 @@
|
|||
module github.com/caddyserver/forwardproxy
|
||||
|
||||
go 1.20
|
||||
go 1.21
|
||||
|
||||
require (
|
||||
github.com/caddyserver/caddy/v2 v2.6.4
|
||||
go.uber.org/zap v1.24.0
|
||||
golang.org/x/net v0.11.0
|
||||
github.com/caddyserver/caddy/v2 v2.7.4
|
||||
go.uber.org/zap v1.26.0
|
||||
golang.org/x/net v0.17.0
|
||||
)
|
||||
|
||||
require (
|
||||
filippo.io/edwards25519 v1.0.0 // indirect
|
||||
github.com/AndreasBriese/bbloom v0.0.0-20190825152654-46b345b51c96 // indirect
|
||||
github.com/BurntSushi/toml v1.2.1 // indirect
|
||||
github.com/BurntSushi/toml v1.3.2 // indirect
|
||||
github.com/Masterminds/goutils v1.1.1 // indirect
|
||||
github.com/Masterminds/semver/v3 v3.2.0 // indirect
|
||||
github.com/Masterminds/sprig/v3 v3.2.3 // indirect
|
||||
github.com/Microsoft/go-winio v0.6.0 // indirect
|
||||
github.com/alecthomas/chroma/v2 v2.5.0 // indirect
|
||||
github.com/antlr/antlr4/runtime/Go/antlr v1.4.10 // indirect
|
||||
github.com/alecthomas/chroma/v2 v2.7.0 // indirect
|
||||
github.com/antlr/antlr4/runtime/Go/antlr/v4 v4.0.0-20230305170008-8188dc5388df // indirect
|
||||
github.com/aryann/difflib v0.0.0-20210328193216-ff5ff6dc229b // indirect
|
||||
github.com/beorn7/perks v1.0.1 // indirect
|
||||
github.com/caddyserver/certmagic v0.17.2 // indirect
|
||||
github.com/caddyserver/certmagic v0.19.2 // indirect
|
||||
github.com/cespare/xxhash v1.1.0 // indirect
|
||||
github.com/cespare/xxhash/v2 v2.1.2 // indirect
|
||||
github.com/chzyer/readline v0.0.0-20180603132655-2972be24d48e // indirect
|
||||
github.com/cespare/xxhash/v2 v2.2.0 // indirect
|
||||
github.com/chzyer/readline v1.5.1 // indirect
|
||||
github.com/cpuguy83/go-md2man/v2 v2.0.2 // indirect
|
||||
github.com/dgraph-io/badger v1.6.2 // indirect
|
||||
github.com/dgraph-io/badger/v2 v2.2007.4 // indirect
|
||||
|
|
@ -33,83 +33,82 @@ require (
|
|||
github.com/dustin/go-humanize v1.0.1 // indirect
|
||||
github.com/go-kit/kit v0.10.0 // indirect
|
||||
github.com/go-logfmt/logfmt v0.5.1 // indirect
|
||||
github.com/go-sql-driver/mysql v1.6.0 // indirect
|
||||
github.com/go-task/slim-sprig v0.0.0-20210107165309-348f09dbbbc0 // indirect
|
||||
github.com/golang/glog v1.0.0 // indirect
|
||||
github.com/golang/mock v1.6.0 // indirect
|
||||
github.com/golang/protobuf v1.5.2 // indirect
|
||||
github.com/go-sql-driver/mysql v1.7.0 // indirect
|
||||
github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572 // indirect
|
||||
github.com/golang/glog v1.1.0 // indirect
|
||||
github.com/golang/protobuf v1.5.3 // indirect
|
||||
github.com/golang/snappy v0.0.4 // indirect
|
||||
github.com/google/cel-go v0.13.0 // indirect
|
||||
github.com/google/pprof v0.0.0-20210407192527-94a9f03dee38 // indirect
|
||||
github.com/google/uuid v1.3.0 // indirect
|
||||
github.com/google/cel-go v0.15.1 // indirect
|
||||
github.com/google/pprof v0.0.0-20230912144702-c363fe2c2ed8 // indirect
|
||||
github.com/google/uuid v1.3.1 // indirect
|
||||
github.com/huandu/xstrings v1.3.3 // indirect
|
||||
github.com/imdario/mergo v0.3.12 // indirect
|
||||
github.com/inconshreveable/mousetrap v1.0.1 // indirect
|
||||
github.com/inconshreveable/mousetrap v1.1.0 // indirect
|
||||
github.com/jackc/chunkreader/v2 v2.0.1 // indirect
|
||||
github.com/jackc/pgconn v1.13.0 // indirect
|
||||
github.com/jackc/pgconn v1.14.0 // indirect
|
||||
github.com/jackc/pgio v1.0.0 // indirect
|
||||
github.com/jackc/pgpassfile v1.0.0 // indirect
|
||||
github.com/jackc/pgproto3/v2 v2.3.1 // indirect
|
||||
github.com/jackc/pgservicefile v0.0.0-20200714003250-2b9c44734f2b // indirect
|
||||
github.com/jackc/pgtype v1.12.0 // indirect
|
||||
github.com/jackc/pgx/v4 v4.17.2 // indirect
|
||||
github.com/klauspost/compress v1.15.15 // indirect
|
||||
github.com/klauspost/cpuid/v2 v2.2.3 // indirect
|
||||
github.com/jackc/pgproto3/v2 v2.3.2 // indirect
|
||||
github.com/jackc/pgservicefile v0.0.0-20221227161230-091c0ba34f0a // indirect
|
||||
github.com/jackc/pgtype v1.14.0 // indirect
|
||||
github.com/jackc/pgx/v4 v4.18.0 // indirect
|
||||
github.com/klauspost/compress v1.16.7 // indirect
|
||||
github.com/klauspost/cpuid/v2 v2.2.5 // indirect
|
||||
github.com/libdns/libdns v0.2.1 // indirect
|
||||
github.com/manifoldco/promptui v0.9.0 // indirect
|
||||
github.com/mattn/go-colorable v0.1.8 // indirect
|
||||
github.com/mattn/go-isatty v0.0.13 // indirect
|
||||
github.com/matttproud/golang_protobuf_extensions v1.0.1 // indirect
|
||||
github.com/mattn/go-isatty v0.0.16 // indirect
|
||||
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
|
||||
github.com/mgutz/ansi v0.0.0-20200706080929-d51e80ef957d // indirect
|
||||
github.com/mholt/acmez v1.1.0 // indirect
|
||||
github.com/mholt/acmez v1.2.0 // indirect
|
||||
github.com/micromdm/scep/v2 v2.1.0 // indirect
|
||||
github.com/miekg/dns v1.1.50 // indirect
|
||||
github.com/miekg/dns v1.1.56 // indirect
|
||||
github.com/mitchellh/copystructure v1.2.0 // indirect
|
||||
github.com/mitchellh/go-ps v1.0.0 // indirect
|
||||
github.com/mitchellh/reflectwalk v1.0.2 // indirect
|
||||
github.com/onsi/ginkgo/v2 v2.2.0 // indirect
|
||||
github.com/onsi/ginkgo/v2 v2.12.1 // indirect
|
||||
github.com/pkg/errors v0.9.1 // indirect
|
||||
github.com/prometheus/client_golang v1.14.0 // indirect
|
||||
github.com/prometheus/client_model v0.3.0 // indirect
|
||||
github.com/prometheus/common v0.37.0 // indirect
|
||||
github.com/prometheus/procfs v0.8.0 // indirect
|
||||
github.com/prometheus/client_golang v1.16.0 // indirect
|
||||
github.com/prometheus/client_model v0.4.0 // indirect
|
||||
github.com/prometheus/common v0.44.0 // indirect
|
||||
github.com/prometheus/procfs v0.12.0 // indirect
|
||||
github.com/quic-go/qpack v0.4.0 // indirect
|
||||
github.com/quic-go/qtls-go1-18 v0.2.0 // indirect
|
||||
github.com/quic-go/qtls-go1-19 v0.2.0 // indirect
|
||||
github.com/quic-go/qtls-go1-20 v0.1.0 // indirect
|
||||
github.com/quic-go/quic-go v0.32.0 // indirect
|
||||
github.com/quic-go/qtls-go1-20 v0.3.4 // indirect
|
||||
github.com/quic-go/quic-go v0.39.0 // indirect
|
||||
github.com/russross/blackfriday/v2 v2.1.0 // indirect
|
||||
github.com/shopspring/decimal v1.2.0 // indirect
|
||||
github.com/shurcooL/sanitized_anchor_name v1.0.0 // indirect
|
||||
github.com/slackhq/nebula v1.6.1 // indirect
|
||||
github.com/smallstep/certificates v0.23.2 // indirect
|
||||
github.com/smallstep/nosql v0.5.0 // indirect
|
||||
github.com/smallstep/certificates v0.24.3-rc.5 // indirect
|
||||
github.com/smallstep/nosql v0.6.0 // indirect
|
||||
github.com/smallstep/truststore v0.12.1 // indirect
|
||||
github.com/spf13/cast v1.4.1 // indirect
|
||||
github.com/spf13/cobra v1.6.1 // indirect
|
||||
github.com/spf13/cobra v1.7.0 // indirect
|
||||
github.com/spf13/pflag v1.0.5 // indirect
|
||||
github.com/stoewer/go-strcase v1.2.0 // indirect
|
||||
github.com/tailscale/tscert v0.0.0-20230124224810-c6dc1f4049b2 // indirect
|
||||
github.com/urfave/cli v1.22.12 // indirect
|
||||
github.com/yuin/goldmark v1.5.4 // indirect
|
||||
github.com/yuin/goldmark-highlighting/v2 v2.0.0-20220924101305-151362477c87 // indirect
|
||||
go.etcd.io/bbolt v1.3.6 // indirect
|
||||
github.com/tailscale/tscert v0.0.0-20230509043813-4e9cb4f2b4ad // indirect
|
||||
github.com/urfave/cli v1.22.14 // indirect
|
||||
github.com/yuin/goldmark v1.5.5 // indirect
|
||||
github.com/yuin/goldmark-highlighting/v2 v2.0.0-20230729083705-37449abec8cc // indirect
|
||||
github.com/zeebo/blake3 v0.2.3 // indirect
|
||||
go.etcd.io/bbolt v1.3.7 // indirect
|
||||
go.mozilla.org/pkcs7 v0.0.0-20210826202110-33d05740a352 // indirect
|
||||
go.step.sm/cli-utils v0.7.5 // indirect
|
||||
go.step.sm/crypto v0.23.2 // indirect
|
||||
go.step.sm/linkedca v0.19.0 // indirect
|
||||
go.uber.org/atomic v1.9.0 // indirect
|
||||
go.uber.org/multierr v1.6.0 // indirect
|
||||
golang.org/x/crypto v0.10.0 // indirect
|
||||
golang.org/x/exp v0.0.0-20221205204356-47842c84f3db // indirect
|
||||
golang.org/x/mod v0.8.0 // indirect
|
||||
golang.org/x/sys v0.9.0 // indirect
|
||||
golang.org/x/term v0.9.0 // indirect
|
||||
golang.org/x/text v0.10.0 // indirect
|
||||
golang.org/x/tools v0.6.0 // indirect
|
||||
google.golang.org/genproto v0.0.0-20230202175211-008b39050e57 // indirect
|
||||
google.golang.org/grpc v1.52.3 // indirect
|
||||
google.golang.org/protobuf v1.28.1 // indirect
|
||||
go.step.sm/cli-utils v0.8.0 // indirect
|
||||
go.step.sm/crypto v0.33.0 // indirect
|
||||
go.step.sm/linkedca v0.20.0 // indirect
|
||||
go.uber.org/mock v0.3.0 // indirect
|
||||
go.uber.org/multierr v1.11.0 // indirect
|
||||
golang.org/x/crypto v0.14.0 // indirect
|
||||
golang.org/x/exp v0.0.0-20230905200255-921286631fa9 // indirect
|
||||
golang.org/x/mod v0.12.0 // indirect
|
||||
golang.org/x/sys v0.13.0 // indirect
|
||||
golang.org/x/term v0.13.0 // indirect
|
||||
golang.org/x/text v0.13.0 // indirect
|
||||
golang.org/x/tools v0.13.0 // indirect
|
||||
google.golang.org/genproto/googleapis/api v0.0.0-20230706204954-ccb25ca9f130 // indirect
|
||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20230711160842-782d3b101e98 // indirect
|
||||
google.golang.org/grpc v1.56.2 // indirect
|
||||
google.golang.org/protobuf v1.31.0 // indirect
|
||||
gopkg.in/square/go-jose.v2 v2.6.0 // indirect
|
||||
gopkg.in/yaml.v3 v3.0.1 // indirect
|
||||
howett.net/plist v1.0.0 // indirect
|
||||
|
|
|
|||
|
|
@ -50,7 +50,13 @@ func TestGETAuthWrongProbeResist(t *testing.T) {
|
|||
responseReference.StatusCode, responseProbeResist.StatusCode)
|
||||
}
|
||||
if err = responsesAreEqual(responseProbeResist, responseReference); err != nil {
|
||||
t.Fatal(err)
|
||||
var e errorHeaderAlternativeServiceNotEqual
|
||||
if !errors.As(err, &e) {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err = e.CheckAlternativeServiceError(caddyForwardProxyProbeResist.addr, caddyDummyProbeResist.addr); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
if err = responsesAreEqual(responseProbeResist, responseForwardProxy); err == nil {
|
||||
t.Fatalf("Responses from servers with and without Probe Resistance are expected to be different."+
|
||||
|
|
@ -78,7 +84,13 @@ func TestGETAuthWrongProbeResist(t *testing.T) {
|
|||
responseProbeResist.StatusCode)
|
||||
}
|
||||
if err = responsesAreEqual(responseProbeResist, responseReference); err != nil {
|
||||
t.Fatal(err)
|
||||
var e errorHeaderAlternativeServiceNotEqual
|
||||
if !errors.As(err, &e) {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err = e.CheckAlternativeServiceError(caddyForwardProxyProbeResist.addr, caddyDummyProbeResist.addr); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
if err = responsesAreEqual(responseProbeResist, responseForwardProxy); err == nil {
|
||||
t.Fatalf("Responses from servers with and without Probe Resistance are expected to be different."+
|
||||
|
|
@ -174,7 +186,13 @@ func TestConnectAuthWrongProbeResist(t *testing.T) {
|
|||
responseReference.StatusCode, responseProbeResist.StatusCode)
|
||||
}
|
||||
if err = responsesAreEqual(responseProbeResist, responseReference); err != nil {
|
||||
t.Fatal(err)
|
||||
var e errorHeaderAlternativeServiceNotEqual
|
||||
if !errors.As(err, &e) {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err = e.CheckAlternativeServiceError(caddyForwardProxyProbeResist.addr, caddyDummyProbeResist.addr); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
if err = responsesAreEqual(responseProbeResist, responseForwardProxy); err == nil {
|
||||
t.Fatalf("Responses from servers with and without Probe Resistance are expected to be different."+
|
||||
|
|
@ -202,7 +220,13 @@ func TestConnectAuthWrongProbeResist(t *testing.T) {
|
|||
t.Fatal(err)
|
||||
}
|
||||
if err = responsesAreEqual(responseProbeResist, responseReference); err != nil {
|
||||
t.Fatal(err)
|
||||
var e errorHeaderAlternativeServiceNotEqual
|
||||
if !errors.As(err, &e) {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err = e.CheckAlternativeServiceError(caddyForwardProxyProbeResist.addr, caddyDummyProbeResist.addr); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
if err = responsesAreEqual(responseProbeResist, responseForwardProxy); err == nil {
|
||||
t.Fatalf("Responses from servers with and without Probe Resistance are expected to be different."+
|
||||
|
|
@ -263,6 +287,37 @@ func TestConnectAuthWrongProbeResistRedir(t *testing.T) {
|
|||
}
|
||||
}
|
||||
|
||||
type errorHeaderAlternativeServiceNotEqual struct {
|
||||
ValueA []string
|
||||
ValueB []string
|
||||
}
|
||||
|
||||
func (e errorHeaderAlternativeServiceNotEqual) Error() string {
|
||||
return fmt.Sprintf("header 'Alt-Svc' not equal: %v, %v\n", e.ValueA, e.ValueB)
|
||||
}
|
||||
|
||||
func (e errorHeaderAlternativeServiceNotEqual) CheckAlternativeServiceError(serverAddrA, serverAddrB string) error {
|
||||
if len(e.ValueA) == 0 || len(e.ValueB) == 0 {
|
||||
return fmt.Errorf("header 'Alt-Svc' is empty: %w", e)
|
||||
}
|
||||
_, port, err := net.SplitHostPort(serverAddrA)
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to split server address :%w", err)
|
||||
}
|
||||
if !strings.Contains(e.ValueA[0], port) {
|
||||
return fmt.Errorf("Alt-Svc address :%s does not contain the server port: %s", e.ValueA[0], port)
|
||||
}
|
||||
_, port, err = net.SplitHostPort(serverAddrB)
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to split server address :%w", err)
|
||||
}
|
||||
if !strings.Contains(e.ValueB[0], port) {
|
||||
return fmt.Errorf("Alt-Svc address :%s does not contain the server port: %s", e.ValueB[0], port)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// returns nil if are equal
|
||||
func responsesAreEqual(res1, res2 *http.Response) error {
|
||||
if res1 == nil {
|
||||
|
|
@ -343,6 +398,9 @@ func responsesAreEqual(res1, res2 *http.Response) error {
|
|||
return fmt.Errorf("header \"%s: %s\" is absent in res2", k1, v1)
|
||||
}
|
||||
if errStr = stringSlicesAreEqual(v1, v2); errStr != "" {
|
||||
if k1 == "Alt-Svc" {
|
||||
return errorHeaderAlternativeServiceNotEqual{v1, v2}
|
||||
}
|
||||
return fmt.Errorf("header \"%s\" is different: %s", k1, errStr)
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue