From 9e9254983030a298df9e9b32a75b33311bf7508b Mon Sep 17 00:00:00 2001 From: Sergey Frolov Date: Mon, 24 Jul 2017 12:05:47 -0400 Subject: [PATCH] Initial commit --- .travis.yml | 11 + CONTRIBUTING.md | 23 ++ LICENSE | 202 ++++++++++++ README.md | 54 ++++ common_test.go | 277 ++++++++++++++++ docker-build/Dockerfile | 16 + docker-build/README.md | 7 + docker-build/gen_caddyfile_and_start.sh | 32 ++ docker-build/run.sh | 39 +++ forwardproxy.go | 389 ++++++++++++++++++++++ forwardproxy_test.go | 321 +++++++++++++++++++ probe_resist_test.go | 410 ++++++++++++++++++++++++ setup.go | 151 +++++++++ setup_test.go | 105 ++++++ test/forwardproxy/index.html | 1 + test/forwardproxy/pic.png | Bin 0 -> 21754 bytes test/index/index.html | 1 + test/index/pic.png | Bin 0 -> 26732 bytes 18 files changed, 2039 insertions(+) create mode 100644 .travis.yml create mode 100644 CONTRIBUTING.md create mode 100644 LICENSE create mode 100644 README.md create mode 100644 common_test.go create mode 100644 docker-build/Dockerfile create mode 100644 docker-build/README.md create mode 100755 docker-build/gen_caddyfile_and_start.sh create mode 100755 docker-build/run.sh create mode 100644 forwardproxy.go create mode 100644 forwardproxy_test.go create mode 100644 probe_resist_test.go create mode 100644 setup.go create mode 100644 setup_test.go create mode 100644 test/forwardproxy/index.html create mode 100644 test/forwardproxy/pic.png create mode 100644 test/index/index.html create mode 100644 test/index/pic.png diff --git a/.travis.yml b/.travis.yml new file mode 100644 index 0000000..bdf56ac --- /dev/null +++ b/.travis.yml @@ -0,0 +1,11 @@ +language: go + +go: + - 1.8.x +# - 1.9.x + +dist: trusty + +script: + - go test . + - unformatted="$(gofmt -l .)"; ! [ -z "${unformatted}" ] && echo "${unformatted}" && exit 1 diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..6d364e1 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,23 @@ +# How to Contribute + +We'd love to accept your patches and contributions to this project. There are +just a few small guidelines you need to follow. + +## Contributor License Agreement + +Contributions to this project must be accompanied by a Contributor License +Agreement. You (or your employer) retain the copyright to your contribution, +this simply gives us permission to use and redistribute your contributions as +part of the project. Head over to to see +your current agreements on file or to sign a new one. + +You generally only need to submit a CLA once, so if you've already submitted one +(even if it was for a different project), you probably don't need to do it +again. + +## Code reviews + +All submissions, including submissions by project members, require review. We +use GitHub pull requests for this purpose. Consult +[GitHub Help](https://help.github.com/articles/about-pull-requests/) for more +information on using pull requests. \ No newline at end of file diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..d645695 --- /dev/null +++ b/LICENSE @@ -0,0 +1,202 @@ + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. diff --git a/README.md b/README.md new file mode 100644 index 0000000..5640c28 --- /dev/null +++ b/README.md @@ -0,0 +1,54 @@ +# ForwardProxy plugin for Caddy webserver + +This plugin enables Caddy webserver to act as a ForwardProxy for http/2.0 and http/1.1 requests +(http/1.0 might work, but is untested). + +## ForwardProxy Caddyfile directives +To simply enable forward proxy without authentication just include the ```forwardproxy``` directive in your Caddyfile. + +To do more advanced things, you may use expanded syntax: +``` +forwardproxy { + basicauth caddyuser1 0NtCL2JPJBgPPMmlPcJ + basicauth caddyuser2 秘密 + ports 80 443 + hide_ip + experimental_probe_resist secretlink-7qS4+3dqm.localhost + response_timeout 30 + dial_timeout 30 +} +``` +Warning: all directives are subject to changes! +* basicauth user password +Sets basic HTTP auth credentials. This directive may be repeated multiple times. +Default: no auth required. +* ports integer integer... +Whitelists ports forwardproxy will HTTP CONNECT to. +Default: no restrictions. +* hide_ip +If set, forwardproxy will not add user's IP to "Forwarded:" header. +Default: no hiding, "_Forwarded: for="useraddress"_" will be sent out. +* experimental_probe_resist secretlink.tld +EXPERIMENTAL, HERE BE DRAGONS. +Attempts to hide the fact that the site is a forwardproxy. +Proxy will no longer respond with _"407 Proxy Authentication Required"_ if credentials are incorrect or absent, +and will attempt to mimic generic forwardproxy-less Caddy server in other regards. +Not all clients(browsers) are able to be configured to send credentials right away, +and only provide credentials after receiving 407. +To work around this, we will use a secret link - the only link that will trigger 407 response, +prompting browsers to request credentials from users and cache them for the rest of the session. +It is possible to use any top level domain, but for secrecy reasons it is highly recommended to use .localhost. +Probing resistance works(and makes sense) only if basicauth is set up. +Default: no probing resistance. +* response_timeout integer +Sets timeout (in seconds) for HTTP requests made by proxy on behalf of users (does not affect CONNECT requests) +Default: no timeout(other timeouts will eventually close the connection). +* dial_timeout integer +Sets timeout (in seconds) for establishing TCP connection to target website. Affects all requests. +Default: 20 seconds. + +### License +Licensed under the [Apache License](LICENSE) + +Initial version of this plugin was developed by Google. +Disclaimer: This is not an official Google product. diff --git a/common_test.go b/common_test.go new file mode 100644 index 0000000..a04f94f --- /dev/null +++ b/common_test.go @@ -0,0 +1,277 @@ +package forwardproxy + +import ( + "crypto/tls" + "encoding/hex" + "fmt" + "github.com/mholt/caddy" + "io" + "io/ioutil" + "net/http" + "net/http/httputil" + "os" + "strings" + "testing" + "time" +) + +var credentialsEmpty = "" +var credentialsCorrect = "Basic dGVzdDpwYXNz" // test:pass +var credentialsWrong = []string{ + "", + "\"\"", + "Basic dzp3", + "Basic \"\"", + "Foo bar", + "Tssssssss", + "Basic dpz3 asp", +} + +/* +Test naming: Test{httpVer}Proxy{Method}{Auth}{Credentials}{httpVer} +GET/CONNECT -- get gets, connect connects and gets +Auth/NoAuth +Empty/Correct/Wrong -- tries different credentials +*/ +var testResources = []string{"", "/pic.png"} +var testHttpVersions = []string{"HTTP/2.0", "HTTP/1.1"} + +type caddyTestServer struct { + *caddy.Instance + addr string // could be http or https + + HTTPRedirectPort string // used in probe-resist tests to simulate default Caddy's http->https redirect + root string // expected to have index.html and pic.png + directives []string + proxyEnabled bool + proxyDirectives []string + contents map[string][]byte +} + +var ( + caddyForwardProxy caddyTestServer + caddyForwardProxyAuth caddyTestServer // requires auth + caddyForwardProxyProbeResist caddyTestServer // requires auth, and has probing resistance on + caddyDummyProbeResist caddyTestServer // same as caddyForwardProxyProbeResist, but w/o forwardproxy + caddyTestTarget caddyTestServer +) + +func (c *caddyTestServer) marshal() []byte { + mainBlock := []string{c.addr + " {", + "root " + c.root} + mainBlock = append(mainBlock, c.directives...) + if c.proxyEnabled { + if len(c.proxyDirectives) == 0 { + mainBlock = append(mainBlock, "forwardproxy") + } else { + forwardProxyBlock := []string{"forwardproxy {"} + forwardProxyBlock = append(forwardProxyBlock, strings.Join(c.proxyDirectives, "\n")) + forwardProxyBlock = append(forwardProxyBlock, "}") + mainBlock = append(mainBlock, strings.Join(forwardProxyBlock, "\n")) + } + } + mainBlock = append(mainBlock, "}") + if len(c.HTTPRedirectPort) > 0 { + // TODO: this is not good enough, since `func redirPlaintextHost(cfg *SiteConfig) *SiteConfig` + // https://github.com/mholt/caddy/blob/master/caddyhttp/httpserver/https.go#L142 can change in future + // and we won't know. + redirectBlock := []string{"http://*:" + c.HTTPRedirectPort + " {", + "redir https://" + c.addr + "{uri}", + "header / Connection close", + "}"} + mainBlock = append(mainBlock, redirectBlock...) + } + // fmt.Println(strings.Join(mainBlock, "\n")) + return []byte(strings.Join(mainBlock, "\n")) +} + +func (c *caddyTestServer) StartTestServer() { + var err error + c.Instance, err = caddy.Start(caddy.CaddyfileInput{Contents: c.marshal(), ServerTypeName: "http"}) + if err != nil { + panic(err) + } + if c.contents == nil { + c.contents = make(map[string][]byte) + } + index, err := ioutil.ReadFile(c.root + "/index.html") + if err != nil { + panic(err) + } + c.contents[""] = index + c.contents["/"] = index + c.contents["/index.html"] = index + + c.contents["/pic.png"], err = ioutil.ReadFile(c.root + "/pic.png") + if err != nil { + panic(err) + } +} + +func TestMain(m *testing.M) { + caddyForwardProxy = caddyTestServer{addr: "127.0.0.1:1984", root: "./test/forwardproxy", + directives: []string{"tls self_signed"}, + proxyEnabled: true} + caddyForwardProxy.StartTestServer() + + caddyForwardProxyAuth = caddyTestServer{addr: "127.0.0.1:4891", root: "./test/forwardproxy", + directives: []string{"tls self_signed"}, + proxyEnabled: true, proxyDirectives: []string{"basicauth test pass"}} + caddyForwardProxyAuth.StartTestServer() + + caddyForwardProxyProbeResist = caddyTestServer{addr: "127.0.0.1:8888", root: "./test/forwardproxy", + directives: []string{"tls self_signed"}, HTTPRedirectPort: "8880", + proxyEnabled: true, proxyDirectives: []string{"basicauth test pass", "experimental_probe_resist test.localhost"}} + caddyForwardProxyProbeResist.StartTestServer() + + caddyDummyProbeResist = caddyTestServer{addr: "127.0.0.1:9999", root: "./test/forwardproxy", + directives: []string{"tls self_signed"}, HTTPRedirectPort: "9980", + proxyEnabled: false} + caddyDummyProbeResist.StartTestServer() + + // 127.0.0.1 and localhost are both used to avoid Caddy matching and routing proxy requests internally + caddyTestTarget = caddyTestServer{addr: "localhost:6451", root: "./test/index", + directives: []string{}, + proxyEnabled: false} + caddyTestTarget.StartTestServer() + + retCode := m.Run() + + caddyForwardProxy.Stop() + caddyForwardProxyAuth.Stop() + caddyForwardProxyProbeResist.Stop() + caddyDummyProbeResist.Stop() + caddyTestTarget.Stop() + + os.Exit(retCode) +} + +// This is a sanity check confirming that target servers actually directly serve what they are expected to. +// (And that they don't serve what they should not) +func TestTheTest(t *testing.T) { + tr := &http.Transport{ + TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, + ResponseHeaderTimeout: 2 * time.Second, + } + client := &http.Client{Transport: tr, Timeout: 2 * time.Second} + + // Request index + resp, err := client.Get("http://" + caddyTestTarget.addr) + if err != nil { + t.Fatal(err) + } else if err = responseExpected(resp, caddyTestTarget.contents[""]); err != nil { + t.Fatal(err) + } + + // Request pic + resp, err = client.Get("http://" + caddyTestTarget.addr + "/pic.png") + if err != nil { + t.Fatal(err) + } else if err = responseExpected(resp, caddyTestTarget.contents["/pic.png"]); err != nil { + t.Fatal(err) + } + + // Request pic, but expect index. Should fail + resp, err = client.Get("http://" + caddyTestTarget.addr + "/pic.png") + if err != nil { + t.Fatal(err) + } else if err = responseExpected(resp, caddyTestTarget.contents[""]); err == nil { + t.Fatal(err) + } + + // Request index, but expect pic. Should fail + resp, err = client.Get("http://" + caddyTestTarget.addr) + if err != nil { + t.Fatal(err) + } else if err = responseExpected(resp, caddyTestTarget.contents["/pic.png"]); err == nil { + t.Fatal(err) + } + + // Request non-existing resource + resp, err = client.Get("http://" + caddyTestTarget.addr + "/idontexist") + if err != nil { + t.Fatal(err) + } else if resp.StatusCode != http.StatusNotFound { + t.Fatalf("Expected: 404 StatusNotFound, got %s. Response: %#v\n", resp.StatusCode, resp) + } +} + +func TestIsSubdomain(t *testing.T) { + testSubDomain := func(s, domain string, expectedResult bool) { + result := isSubdomain(s, domain) + if result != expectedResult { + t.Fatalf("Expected: isSubdomain(%s, %s) is %b, Got: %b", s, domain, expectedResult, result) + } + } + testSubDomain("hoooli.abc", "hooya.ya", false) + testSubDomain("", "hooya.ya", false) + testSubDomain("hoooli.abc", "", false) + testSubDomain("hoooli.abc", "hiddenlink.localhost", false) + testSubDomain("www.hoooli.abc", "hoooli.abc", true) + testSubDomain("hoooli.abc", "hoooli.abc", true) + testSubDomain(".hoooli.abc", "hoooli.abc", true) + testSubDomain("sup.hoooli.abc", "hoooli.abc", true) + testSubDomain("qwe.qwe.qwe.hoooli.abc", "hoooli.abc", true) +} + +func debugIoCopy(dst io.Writer, src io.Reader, prefix string) (written int64, err error) { + buf := make([]byte, 32*1024) + flusher, ok := dst.(http.Flusher) + for { + nr, er := src.Read(buf) + fmt.Printf("[%s] Read err %#v\n%s", prefix, er, hex.Dump(buf[0:nr])) + if nr > 0 { + nw, ew := dst.Write(buf[0:nr]) + if ok { + flusher.Flush() + } + fmt.Printf("[%s] Wrote %v %v\n", prefix, nw, ew) + if nw > 0 { + written += int64(nw) + } + if ew != nil { + err = ew + break + } + if nr != nw { + err = io.ErrShortWrite + break + } + } + if er != nil { + if er != io.EOF { + err = er + } + break + } + } + fmt.Printf("[%s] Returning with %#v %#v\n", prefix, written, err) + return +} + +func httpdump(r interface{}) string { + switch v := r.(type) { + case *http.Request: + if v == nil { + return "httpdump: nil" + } + b, err := httputil.DumpRequest(v, false) + if err != nil { + return err.Error() + } else { + return string(b) + } + case *http.Response: + if v == nil { + return "httpdump: nil" + } + b, err := httputil.DumpResponse(v, false) + if err != nil { + return err.Error() + } else { + return string(b) + } + default: + return "httpdump: wrong type" + } +} diff --git a/docker-build/Dockerfile b/docker-build/Dockerfile new file mode 100644 index 0000000..5637e07 --- /dev/null +++ b/docker-build/Dockerfile @@ -0,0 +1,16 @@ +FROM alpine:3.6 + +LABEL description="Docker image for caddy+forwardproxy plugin." +LABEL maintainer="SergeyFrolov@colorado.edu" + +RUN apk add --no-cache ca-certificates bash curl + +RUN curl --fail https://getcaddy.com | bash -s http.forwardproxy + +COPY gen_caddyfile_and_start.sh /bin/ + +VOLUME /root/.caddy + +EXPOSE 80 443 2015 + +ENTRYPOINT /bin/gen_caddyfile_and_start.sh diff --git a/docker-build/README.md b/docker-build/README.md new file mode 100644 index 0000000..69d146c --- /dev/null +++ b/docker-build/README.md @@ -0,0 +1,7 @@ +# caddy-forwardproxy +A docker image for Caddy web server + forwardproxy plugin. +Allows to easily set up private web server with proxying. +### Build +```docker build -t caddy-forwardproxy .``` +### Usage +Please find latest usage instructions in [run.sh](./run.sh). diff --git a/docker-build/gen_caddyfile_and_start.sh b/docker-build/gen_caddyfile_and_start.sh new file mode 100755 index 0000000..885a707 --- /dev/null +++ b/docker-build/gen_caddyfile_and_start.sh @@ -0,0 +1,32 @@ +#!/usr/bin/env bash + +CADDYFILE="${CADDYFILE:-/etc/caddy/Caddyfile}" +ROOTDIR="${ROOTDIR:-/srv/index}" +SITE_ADDRESS="${SITE_ADDRESS:-localhost}" + +generate_caddyfile() { + mkdir -p "$(dirname "${CADDYFILE}")" + + echo "${SITE_ADDRESS} {" > ${CADDYFILE} + echo " root $ROOTDIR" >> ${CADDYFILE} + + echo " forwardproxy {" >> ${CADDYFILE} + if [[ ! -z ${PROXY_USERNAME} ]]; then + echo " basicauth ${PROXY_USERNAME} ${PROXY_PASSWORD}" >> ${CADDYFILE} + fi + if [[ "${PROBE_RESISTANT}" = true ]]; then + echo " experimental_probe_resist ${SECRET_LINK}" >> ${CADDYFILE} + fi + echo " }" >> ${CADDYFILE} + + echo "}" >> ${CADDYFILE} +} + +if [ -f "${CADDYFILE}" ]; then + echo "Using provided Caddyfile" +else + echo "Caddyfile is not provided: generating new one" + generate_caddyfile +fi + +caddy ${CADDY_OPTS} -conf ${CADDYFILE} diff --git a/docker-build/run.sh b/docker-build/run.sh new file mode 100755 index 0000000..532304f --- /dev/null +++ b/docker-build/run.sh @@ -0,0 +1,39 @@ +#!/usr/bin/env bash + +print_help() { + cat <