路由模式与CIDR配置重构: - 路由模式从 full/split/custom 改为 full/proxy/bypass,移除 split 和 custom - CIDR 按 IPv4/IPv6 分开配置,支持静态 CIDR + URL 动态获取 - URL 支持"代理前获取"(直连)和"代理后获取"(走隧道)两种时机 - 数据库迁移 v5 自动转换旧数据(custom_cidrs 拆分为 cidr_v4/v6,custom->proxy,split->full) CIDR命中统计: - 状态栏显示当前路由模式及 IPv4/IPv6 CIDR 命中数 - 代理模式: 显示命中/总数; 绕过模式: 显示已配置数 + 未命中目的地址数 - cidrTracker 在 pumpPackets 中逐包检查出站目的IP 连接稳定性修复(多轮): - transport.Connect 添加 ctx 监听 goroutine,取消时关闭WS中断阻塞的ReadMessage - auth.Login 加 context.Context 参数,可被 cancel 中断 - Disconnect() 先删路由再关TUN,避免断网窗口 - startSession 在 Connect 前释放 d.mu,避免锁持有过久 - onConnect 移除 SendStop 消除竞态 - before-proxy CIDR 获取移到 run 循环前,并行获取+5s超时,重连复用 - cidrTracker 加 RWMutex 防数据竞争 UI修复: - CIDR URL 输入框改为水平滚动+纵向布局,防止撑宽窗口 - 路由模式为full时隐藏CIDR配置区域
134 lines
3.8 KiB
Go
134 lines
3.8 KiB
Go
// Package auth implements the HTTP login flow (POST /api/login) to
|
|
// obtain a JWT for WebSocket authentication.
|
|
//
|
|
// (server: internal/handler/auth.go:32-82, internal/router/router.go:17)
|
|
package auth
|
|
|
|
import (
|
|
"bytes"
|
|
"context"
|
|
"crypto/tls"
|
|
"encoding/json"
|
|
"fmt"
|
|
"io"
|
|
"net/http"
|
|
"strings"
|
|
"time"
|
|
)
|
|
|
|
// LoginResult holds the response from a successful /api/login call.
|
|
type LoginResult struct {
|
|
Token string `json:"token"`
|
|
User LoginUser `json:"user"`
|
|
}
|
|
|
|
// LoginUser is the user object embedded in the login response.
|
|
type LoginUser struct {
|
|
ID uint `json:"id"`
|
|
Username string `json:"username"`
|
|
Role string `json:"role"`
|
|
}
|
|
|
|
type loginRequest struct {
|
|
Username string `json:"username"`
|
|
Password string `json:"password"`
|
|
}
|
|
|
|
type errorResponse struct {
|
|
Error string `json:"error"`
|
|
}
|
|
|
|
// Login performs an HTTP POST to /api/login and returns the JWT.
|
|
//
|
|
// baseURL should be the HTTP(S) origin derived from the WebSocket URL
|
|
// (e.g. "http://localhost:8080" for ws://, "https://vpn.example.com"
|
|
// for wss://). See WSURLToHTTP.
|
|
//
|
|
// tlsCfg, if non-nil, is used as the TLS configuration for the HTTP
|
|
// client. This is essential when connecting via CDN edge IPs: the URL
|
|
// host will be an IP address, but the certificate must be verified
|
|
// against the real hostname (set tlsCfg.ServerName).
|
|
//
|
|
// ctx allows cancellation of the HTTP request (e.g. when the VPN
|
|
// session is disconnected while login is in flight).
|
|
func Login(ctx context.Context, baseURL, username, password string, tlsCfg *tls.Config) (*LoginResult, error) {
|
|
body, err := json.Marshal(loginRequest{Username: username, Password: password})
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
url := strings.TrimRight(baseURL, "/") + "/api/login"
|
|
client := &http.Client{Timeout: 15 * time.Second}
|
|
if tlsCfg != nil {
|
|
client.Transport = &http.Transport{TLSClientConfig: tlsCfg}
|
|
}
|
|
|
|
req, err := http.NewRequestWithContext(ctx, http.MethodPost, url, bytes.NewReader(body))
|
|
if err != nil {
|
|
return nil, fmt.Errorf("create login request: %w", err)
|
|
}
|
|
req.Header.Set("Content-Type", "application/json")
|
|
|
|
resp, err := client.Do(req)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("login request: %w", err)
|
|
}
|
|
defer resp.Body.Close()
|
|
|
|
raw, err := io.ReadAll(resp.Body)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("read login response: %w", err)
|
|
}
|
|
|
|
switch resp.StatusCode {
|
|
case http.StatusOK:
|
|
var result LoginResult
|
|
if err := json.Unmarshal(raw, &result); err != nil {
|
|
return nil, fmt.Errorf("parse login response: %w", err)
|
|
}
|
|
return &result, nil
|
|
case http.StatusBadRequest, http.StatusUnauthorized, http.StatusForbidden,
|
|
http.StatusTooManyRequests, http.StatusInternalServerError:
|
|
var e errorResponse
|
|
_ = json.Unmarshal(raw, &e)
|
|
return nil, &LoginError{Code: resp.StatusCode, Message: e.Error}
|
|
default:
|
|
return nil, &LoginError{Code: resp.StatusCode, Message: string(raw)}
|
|
}
|
|
}
|
|
|
|
// LoginError carries the HTTP status code and server error message.
|
|
type LoginError struct {
|
|
Code int
|
|
Message string
|
|
}
|
|
|
|
func (e *LoginError) Error() string {
|
|
return fmt.Sprintf("login failed (%d): %s", e.Code, e.Message)
|
|
}
|
|
|
|
// IsRateLimited reports whether the error is a 429 rate-limit response.
|
|
func (e *LoginError) IsRateLimited() bool { return e.Code == http.StatusTooManyRequests }
|
|
|
|
// WSURLToHTTP converts a WebSocket URL to its HTTP origin.
|
|
//
|
|
// ws://host:port/ws → http://host:port
|
|
// wss://host/ws → https://host
|
|
// ws://host:8080 → http://host:8080
|
|
func WSURLToHTTP(wsURL string) (string, error) {
|
|
u := wsURL
|
|
switch {
|
|
case strings.HasPrefix(u, "wss://"):
|
|
u = "https://" + u[len("wss://"):]
|
|
case strings.HasPrefix(u, "ws://"):
|
|
u = "http://" + u[len("ws://"):]
|
|
default:
|
|
return "", fmt.Errorf("invalid WebSocket URL: %s", wsURL)
|
|
}
|
|
// Strip the path (e.g. /ws) to get just the origin.
|
|
if idx := strings.IndexByte(u, '/'); idx > 8 { // keep "https://"
|
|
u = u[:idx]
|
|
}
|
|
return u, nil
|
|
}
|