Some checks are pending
Build / Calculate version (push) Waiting to run
Build / Build binary (push) Blocked by required conditions
Build / Build Darwin binaries (push) Blocked by required conditions
Build / Build Windows binaries (push) Blocked by required conditions
Build / Build Android (push) Blocked by required conditions
Build / Publish Android (push) Blocked by required conditions
Build / Build Apple clients (push) Blocked by required conditions
Build / Upload builds (push) Blocked by required conditions
- New UserManager service with HTTPS auth, credential sync, traffic tracking, and kick API - Integrates into all 10 protocol inbounds (hysteria2, tuic, vless, vmess, trojan, shadowsocks, http, socks, mixed, naive) - Each inbound auto-detects user_manager from service context, falls back to static config - Auth server contract: POST /api/auth, GET /api/credentials, POST /api/traffic
153 lines
4.9 KiB
Go
153 lines
4.9 KiB
Go
package socks
|
|
|
|
import (
|
|
std_bufio "bufio"
|
|
"context"
|
|
"net"
|
|
"time"
|
|
|
|
"github.com/sagernet/sing-box/adapter"
|
|
"github.com/sagernet/sing-box/adapter/inbound"
|
|
"github.com/sagernet/sing-box/common/listener"
|
|
"github.com/sagernet/sing-box/common/uot"
|
|
C "github.com/sagernet/sing-box/constant"
|
|
"github.com/sagernet/sing-box/log"
|
|
"github.com/sagernet/sing-box/option"
|
|
"github.com/sagernet/sing/common/auth"
|
|
E "github.com/sagernet/sing/common/exceptions"
|
|
"github.com/sagernet/sing/common/logger"
|
|
N "github.com/sagernet/sing/common/network"
|
|
"github.com/sagernet/sing/protocol/socks"
|
|
"github.com/sagernet/sing/service"
|
|
)
|
|
|
|
func RegisterInbound(registry *inbound.Registry) {
|
|
inbound.Register[option.SocksInboundOptions](registry, C.TypeSOCKS, NewInbound)
|
|
}
|
|
|
|
var _ adapter.TCPInjectableInbound = (*Inbound)(nil)
|
|
|
|
type Inbound struct {
|
|
inbound.Adapter
|
|
router adapter.ConnectionRouterEx
|
|
logger logger.ContextLogger
|
|
listener *listener.Listener
|
|
authenticator *auth.Authenticator
|
|
udpTimeout time.Duration
|
|
userManager adapter.UserManager
|
|
}
|
|
|
|
func NewInbound(ctx context.Context, router adapter.Router, logger log.ContextLogger, tag string, options option.SocksInboundOptions) (adapter.Inbound, error) {
|
|
var udpTimeout time.Duration
|
|
if options.UDPTimeout != 0 {
|
|
udpTimeout = time.Duration(options.UDPTimeout)
|
|
} else {
|
|
udpTimeout = C.UDPTimeout
|
|
}
|
|
authenticator := auth.NewAuthenticator(options.Users)
|
|
userManager := service.FromContext[adapter.UserManager](ctx)
|
|
if userManager != nil {
|
|
creds, err := userManager.GetCredentials(C.TypeSOCKS)
|
|
if err == nil && len(creds) > 0 {
|
|
users := make([]auth.User, len(creds))
|
|
for i, c := range creds {
|
|
users[i] = auth.User{Username: c.Username, Password: c.Credential}
|
|
}
|
|
authenticator = auth.NewAuthenticator(users)
|
|
}
|
|
}
|
|
inbound := &Inbound{
|
|
Adapter: inbound.NewAdapter(C.TypeSOCKS, tag),
|
|
router: uot.NewRouter(router, logger),
|
|
logger: logger,
|
|
authenticator: authenticator,
|
|
udpTimeout: udpTimeout,
|
|
userManager: userManager,
|
|
}
|
|
inbound.listener = listener.New(listener.Options{
|
|
Context: ctx,
|
|
Logger: logger,
|
|
Network: []string{N.NetworkTCP},
|
|
Listen: options.ListenOptions,
|
|
ConnectionHandler: inbound,
|
|
})
|
|
return inbound, nil
|
|
}
|
|
|
|
func (h *Inbound) Start(stage adapter.StartStage) error {
|
|
if stage != adapter.StartStateStart {
|
|
return nil
|
|
}
|
|
if h.userManager != nil {
|
|
go h.credentialLoop()
|
|
}
|
|
return h.listener.Start()
|
|
}
|
|
|
|
func (h *Inbound) credentialLoop() {
|
|
ticker := time.NewTicker(30 * time.Second)
|
|
defer ticker.Stop()
|
|
for range ticker.C {
|
|
creds, err := h.userManager.GetCredentials(C.TypeSOCKS)
|
|
if err != nil || len(creds) == 0 {
|
|
continue
|
|
}
|
|
users := make([]auth.User, len(creds))
|
|
for i, c := range creds {
|
|
users[i] = auth.User{Username: c.Username, Password: c.Credential}
|
|
}
|
|
h.authenticator = auth.NewAuthenticator(users)
|
|
}
|
|
}
|
|
|
|
func (h *Inbound) Close() error {
|
|
return h.listener.Close()
|
|
}
|
|
|
|
func (h *Inbound) NewConnection(ctx context.Context, conn net.Conn, metadata adapter.InboundContext, onClose N.CloseHandlerFunc) {
|
|
err := socks.HandleConnectionEx(ctx, conn, std_bufio.NewReader(conn), h.authenticator, adapter.NewUpstreamHandler(metadata, h.newUserConnection, h.streamUserPacketConnection), h.listener, h.udpTimeout, metadata.Source, onClose)
|
|
N.CloseOnHandshakeFailure(conn, onClose, err)
|
|
if err != nil {
|
|
if E.IsClosedOrCanceled(err) {
|
|
h.logger.DebugContext(ctx, "connection closed: ", err)
|
|
} else {
|
|
h.logger.ErrorContext(ctx, E.Cause(err, "process connection from ", metadata.Source))
|
|
}
|
|
}
|
|
}
|
|
|
|
func (h *Inbound) newUserConnection(ctx context.Context, conn net.Conn, metadata adapter.InboundContext, onClose N.CloseHandlerFunc) {
|
|
metadata.Inbound = h.Tag()
|
|
metadata.InboundType = h.Type()
|
|
user, loaded := auth.UserFromContext[string](ctx)
|
|
if !loaded {
|
|
h.logger.InfoContext(ctx, "inbound connection to ", metadata.Destination)
|
|
h.router.RouteConnectionEx(ctx, conn, metadata, onClose)
|
|
return
|
|
}
|
|
metadata.User = user
|
|
h.logger.InfoContext(ctx, "[", user, "] inbound connection to ", metadata.Destination)
|
|
h.router.RouteConnectionEx(ctx, conn, metadata, onClose)
|
|
}
|
|
|
|
func (h *Inbound) streamUserPacketConnection(ctx context.Context, conn N.PacketConn, metadata adapter.InboundContext, onClose N.CloseHandlerFunc) {
|
|
metadata.Inbound = h.Tag()
|
|
metadata.InboundType = h.Type()
|
|
user, loaded := auth.UserFromContext[string](ctx)
|
|
if !loaded {
|
|
if !metadata.Destination.IsValid() {
|
|
h.logger.InfoContext(ctx, "inbound packet connection")
|
|
} else {
|
|
h.logger.InfoContext(ctx, "inbound packet connection to ", metadata.Destination)
|
|
}
|
|
h.router.RoutePacketConnectionEx(ctx, conn, metadata, onClose)
|
|
return
|
|
}
|
|
metadata.User = user
|
|
if !metadata.Destination.IsValid() {
|
|
h.logger.InfoContext(ctx, "[", user, "] inbound packet connection")
|
|
} else {
|
|
h.logger.InfoContext(ctx, "[", user, "] inbound packet connection to ", metadata.Destination)
|
|
}
|
|
h.router.RoutePacketConnectionEx(ctx, conn, metadata, onClose)
|
|
}
|