Merge pull request 'feat: 管理后台一键从 Caddy 获取证书 + TLS 证书热加载' (#4) from dsh/mailgo:caddy-cert-hot-reload into main
Reviewed-on: #4
This commit was merged in pull request #4.
This commit is contained in:
@@ -108,6 +108,11 @@ ldap_use_tls = false
|
|||||||
max_fail_attempts = 5 # 登录失败次数阈值
|
max_fail_attempts = 5 # 登录失败次数阈值
|
||||||
ban_duration_min = 30 # 封禁时长(分钟)
|
ban_duration_min = 30 # 封禁时长(分钟)
|
||||||
|
|
||||||
|
[caddy]
|
||||||
|
data_dir = "" # Caddy 数据目录(含 certificates/ 的那个),
|
||||||
|
# 供后台一键导入证书;留空自动探测
|
||||||
|
# /var/lib/caddy/.local/share/caddy 等常见位置
|
||||||
|
|
||||||
[outbound]
|
[outbound]
|
||||||
hostname = "" # EHLO 主机名,留空使用 [smtp] domain
|
hostname = "" # EHLO 主机名,留空使用 [smtp] domain
|
||||||
poll_interval = 15 # 外发队列扫描间隔(秒)
|
poll_interval = 15 # 外发队列扫描间隔(秒)
|
||||||
@@ -207,6 +212,32 @@ tls_key = "/etc/mail_go/certs/server.key"
|
|||||||
> # 私钥路径: /etc/letsencrypt/live/mail.example.com/privkey.pem
|
> # 私钥路径: /etc/letsencrypt/live/mail.example.com/privkey.pem
|
||||||
> ```
|
> ```
|
||||||
|
|
||||||
|
#### 从 Caddy 一键导入证书
|
||||||
|
|
||||||
|
如果本机已用 [Caddy](https://caddyserver.com/) 托管该域名 HTTPS(Caddy 会自动签发并续期证书),
|
||||||
|
可在管理后台 **域名管理 → 编辑域名** 页面点击 **“从 Caddy 获取证书”** 按钮,
|
||||||
|
一键把 Caddy 存储中的证书与私钥导入邮件服务(自动启用该域名的 TLS),无需手动复制 PEM 文件。
|
||||||
|
支持通配符证书(如 `*.example.com` 可匹配 `mail.example.com`)。
|
||||||
|
证书支持**热加载**:导入(或手动上传)后立即生效,无需重启服务——SMTP/IMAP/POP3
|
||||||
|
每次 TLS 握手会自动检查并重载变化的证书文件。
|
||||||
|
|
||||||
|
由于 Caddy 的证书目录仅 `caddy` 用户可读,install.sh 会安装一个 root 权限的证书同步任务
|
||||||
|
(`mailgo-caddy-sync.{path,timer}`),把 Caddy 证书树镜像到 `/srv/mail_go/tls/caddy`,
|
||||||
|
证书续期后自动同步,mail_go 始终可读;另外还会授予 ACL 权限作为直接读取的兜底。
|
||||||
|
安装时自动配置,也可手动执行:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo ./install.sh setup-caddy-cert # 自动探测 Caddy 数据目录并配置同步 + ACL
|
||||||
|
sudo ./install.sh setup-caddy-cert /path/to/caddy/data # 或手动指定数据目录
|
||||||
|
```
|
||||||
|
|
||||||
|
若 Caddy 数据目录不在常见位置,可在配置文件中显式指定:
|
||||||
|
|
||||||
|
```toml
|
||||||
|
[caddy]
|
||||||
|
data_dir = "/var/lib/caddy/.local/share/caddy"
|
||||||
|
```
|
||||||
|
|
||||||
### 4. 启用 OAuth2 登录(Google 示例)
|
### 4. 启用 OAuth2 登录(Google 示例)
|
||||||
|
|
||||||
```toml
|
```toml
|
||||||
|
|||||||
@@ -79,6 +79,15 @@ type BanConfig struct {
|
|||||||
BanDurationMin int `toml:"ban_duration_min"` // Default: 30 (minutes)
|
BanDurationMin int `toml:"ban_duration_min"` // Default: 30 (minutes)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// CaddyConfig holds settings for importing TLS certificates from a local Caddy.
|
||||||
|
type CaddyConfig struct {
|
||||||
|
// DataDir is the Caddy data directory (the one containing the
|
||||||
|
// "certificates/" subdirectory), used by the one-click certificate
|
||||||
|
// import in the admin panel. Leave empty to auto-detect common
|
||||||
|
// locations such as /var/lib/caddy/.local/share/caddy.
|
||||||
|
DataDir string `toml:"data_dir"`
|
||||||
|
}
|
||||||
|
|
||||||
// OutboundConfig holds outbound (external) mail delivery settings.
|
// OutboundConfig holds outbound (external) mail delivery settings.
|
||||||
type OutboundConfig struct {
|
type OutboundConfig struct {
|
||||||
Hostname string `toml:"hostname"` // EHLO 主机名,留空使用 [smtp] domain
|
Hostname string `toml:"hostname"` // EHLO 主机名,留空使用 [smtp] domain
|
||||||
@@ -114,6 +123,7 @@ type Config struct {
|
|||||||
POP3 POP3Config `toml:"pop3"`
|
POP3 POP3Config `toml:"pop3"`
|
||||||
Auth AuthConfig `toml:"auth"`
|
Auth AuthConfig `toml:"auth"`
|
||||||
Ban BanConfig `toml:"ban"`
|
Ban BanConfig `toml:"ban"`
|
||||||
|
Caddy CaddyConfig `toml:"caddy"`
|
||||||
Outbound OutboundConfig `toml:"outbound"`
|
Outbound OutboundConfig `toml:"outbound"`
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -184,6 +194,8 @@ func defaultConfig() *Config {
|
|||||||
MaxFailAttempts: 5,
|
MaxFailAttempts: 5,
|
||||||
BanDurationMin: 30,
|
BanDurationMin: 30,
|
||||||
},
|
},
|
||||||
|
// Caddy: 留空则自动探测常见数据目录,无需配置
|
||||||
|
Caddy: CaddyConfig{},
|
||||||
Outbound: OutboundConfig{
|
Outbound: OutboundConfig{
|
||||||
PollInterval: 15, // 15 秒扫描一次队列
|
PollInterval: 15, // 15 秒扫描一次队列
|
||||||
MaxAttempts: 12, // 最多尝试 12 次
|
MaxAttempts: 12, // 最多尝试 12 次
|
||||||
|
|||||||
+165
-1
@@ -214,6 +214,20 @@ do_install() {
|
|||||||
# 4. 拉取代码并编译
|
# 4. 拉取代码并编译
|
||||||
build_binary
|
build_binary
|
||||||
|
|
||||||
|
# 4.5 配置 Caddy 证书同步(若检测到 Caddy),供后台一键导入使用
|
||||||
|
local caddy_data
|
||||||
|
caddy_data="$(find_caddy_data_dir 2>/dev/null || true)"
|
||||||
|
if [[ -n "${caddy_data}" ]]; then
|
||||||
|
info "检测到 Caddy(${caddy_data}),配置证书同步任务 ..."
|
||||||
|
if install_caddy_sync "${caddy_data}"; then
|
||||||
|
ok "Caddy 证书同步已配置(后台可一键导入证书)"
|
||||||
|
else
|
||||||
|
warn "Caddy 证书同步配置失败,可稍后手动执行: sudo $0 setup-caddy-cert"
|
||||||
|
fi
|
||||||
|
# ACL 兜底(失败不影响使用)
|
||||||
|
command -v setfacl &>/dev/null && setup_caddy_acls "${caddy_data}" || true
|
||||||
|
fi
|
||||||
|
|
||||||
# 5. 部署文件
|
# 5. 部署文件
|
||||||
deploy_files
|
deploy_files
|
||||||
|
|
||||||
@@ -250,6 +264,153 @@ do_install() {
|
|||||||
warn "⚠ 请登录后立即修改默认密码!"
|
warn "⚠ 请登录后立即修改默认密码!"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# ======================== Caddy 证书同步 ========================
|
||||||
|
# mail_go 后台有一键“从 Caddy 获取证书”功能:从 Caddy 的证书存储读取
|
||||||
|
# 域名证书与私钥并导入邮件服务。Caddy 证书目录默认仅 caddy 用户可读
|
||||||
|
# (0700/0600),且证书续期后文件会被替换(权限重置),因此安装一个
|
||||||
|
# root 权限的 systemd path/timer 同步任务,把 Caddy 证书树镜像到
|
||||||
|
# mail_go 可读的 <storage>/tls/caddy 目录,续期后自动更新;
|
||||||
|
# 同时授予 ACL 作为直接读取的兜底。用法: sudo ./install.sh setup-caddy-cert [caddy数据目录]
|
||||||
|
|
||||||
|
# 探测 Caddy 数据目录(包含 certificates/ 子目录的那个目录)
|
||||||
|
find_caddy_data_dir() {
|
||||||
|
local candidates=(
|
||||||
|
"/var/lib/caddy/.local/share/caddy"
|
||||||
|
"/root/.local/share/caddy"
|
||||||
|
"/home/caddy/.local/share/caddy"
|
||||||
|
)
|
||||||
|
local d
|
||||||
|
for d in "${candidates[@]}"; do
|
||||||
|
if [[ -d "${d}/certificates" ]]; then
|
||||||
|
echo "${d}"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
# systemd 服务可能配置了自定义 HOME
|
||||||
|
local home
|
||||||
|
home=$(systemctl show caddy -p Environment --value 2>/dev/null | grep -oP '(?<=HOME=)[^ ]+' || true)
|
||||||
|
if [[ -n "${home}" && -d "${home}/.local/share/caddy/certificates" ]]; then
|
||||||
|
echo "${home}/.local/share/caddy"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# 用 ACL 授予 mail_go 用户读取 Caddy 证书的权限(幂等,兜底用:
|
||||||
|
# 续期后 caddy 以 0600 重建文件,ACL 可能失效,靠同步任务保障)
|
||||||
|
setup_caddy_acls() {
|
||||||
|
local data_dir="${1:-$(find_caddy_data_dir 2>/dev/null || true)}"
|
||||||
|
[[ -n "${data_dir}" ]] || return 1
|
||||||
|
local certs_dir="${data_dir}/certificates"
|
||||||
|
[[ -d "${certs_dir}" ]] || return 1
|
||||||
|
|
||||||
|
command -v setfacl &>/dev/null || return 1
|
||||||
|
|
||||||
|
# 各级父目录需要 x(遍历)权限
|
||||||
|
local p="${data_dir}"
|
||||||
|
while [[ "${p}" != "/" ]]; do
|
||||||
|
setfacl -m "u:${SERVICE_USER}:x" "${p}" 2>/dev/null
|
||||||
|
p="$(dirname "${p}")"
|
||||||
|
done
|
||||||
|
setfacl -R -m "u:${SERVICE_USER}:rX" "${certs_dir}" 2>/dev/null
|
||||||
|
setfacl -R -m "d:u:${SERVICE_USER}:rX" "${certs_dir}" 2>/dev/null
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
# 安装证书同步脚本 + systemd path/timer 单元,并立即同步一次
|
||||||
|
install_caddy_sync() {
|
||||||
|
local data_dir="$1"
|
||||||
|
local sync_script="/usr/local/sbin/mailgo-caddy-cert-sync.sh"
|
||||||
|
local sync_dir="${DATA_DIR}/tls/caddy"
|
||||||
|
local certs_dir="${data_dir}/certificates"
|
||||||
|
|
||||||
|
# 同步脚本(把数据目录固化进去)
|
||||||
|
cat > "${sync_script}" <<EOF
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
# MailGo - 将 Caddy 证书存储镜像到 mail_go 可读目录(root 运行,
|
||||||
|
# 由 mailgo-caddy-sync.{path,timer} 触发),供后台一键导入使用。
|
||||||
|
set -euo pipefail
|
||||||
|
SRC="${certs_dir}"
|
||||||
|
SYNC="${sync_dir}"
|
||||||
|
[[ -d "\${SRC}" ]] || exit 0
|
||||||
|
mkdir -p "\${SYNC}"
|
||||||
|
rm -rf "\${SYNC}/.certs.tmp"
|
||||||
|
cp -a "\${SRC}" "\${SYNC}/.certs.tmp"
|
||||||
|
chown -R "${SERVICE_USER}:${SERVICE_USER}" "\${SYNC}/.certs.tmp"
|
||||||
|
chmod -R u+rwX,go-rwx "\${SYNC}/.certs.tmp"
|
||||||
|
rm -rf "\${SYNC}/certificates"
|
||||||
|
mv "\${SYNC}/.certs.tmp" "\${SYNC}/certificates"
|
||||||
|
EOF
|
||||||
|
chmod 700 "${sync_script}"
|
||||||
|
|
||||||
|
cat > /etc/systemd/system/mailgo-caddy-sync.service <<EOF
|
||||||
|
[Unit]
|
||||||
|
Description=MailGo - 同步 Caddy 证书到 mail_go TLS 目录
|
||||||
|
After=network.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
ExecStart=${sync_script}
|
||||||
|
EOF
|
||||||
|
|
||||||
|
cat > /etc/systemd/system/mailgo-caddy-sync.path <<EOF
|
||||||
|
[Unit]
|
||||||
|
Description=MailGo - 监视 Caddy 证书目录变化并触发同步
|
||||||
|
|
||||||
|
[Path]
|
||||||
|
PathChanged=${certs_dir}
|
||||||
|
PathChanged=${certs_dir}/*/*
|
||||||
|
Unit=mailgo-caddy-sync.service
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
|
EOF
|
||||||
|
|
||||||
|
cat > /etc/systemd/system/mailgo-caddy-sync.timer <<EOF
|
||||||
|
[Unit]
|
||||||
|
Description=MailGo - 定期同步 Caddy 证书(开机 + 每日兜底)
|
||||||
|
|
||||||
|
[Timer]
|
||||||
|
OnBootSec=1min
|
||||||
|
OnUnitActiveSec=1d
|
||||||
|
Unit=mailgo-caddy-sync.service
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=timers.target
|
||||||
|
EOF
|
||||||
|
|
||||||
|
systemctl daemon-reload
|
||||||
|
systemctl enable --now mailgo-caddy-sync.path mailgo-caddy-sync.timer >/dev/null
|
||||||
|
systemctl start mailgo-caddy-sync.service
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
do_setup_caddy_cert() {
|
||||||
|
check_root
|
||||||
|
local data_dir="${2:-}"
|
||||||
|
if [[ -z "${data_dir}" ]]; then
|
||||||
|
data_dir="$(find_caddy_data_dir || true)"
|
||||||
|
if [[ -z "${data_dir}" ]]; then
|
||||||
|
error "未检测到 Caddy 数据目录(/var/lib/caddy 等),请手动指定: sudo $0 setup-caddy-cert <caddy数据目录>"
|
||||||
|
fi
|
||||||
|
info "检测到 Caddy 数据目录: ${data_dir}"
|
||||||
|
elif [[ ! -d "${data_dir}/certificates" ]]; then
|
||||||
|
error "目录 ${data_dir} 下未找到 certificates/ 子目录,请确认传入的是 Caddy 数据目录"
|
||||||
|
fi
|
||||||
|
|
||||||
|
info "安装证书同步任务(systemd path + timer,续期后自动同步)..."
|
||||||
|
install_caddy_sync "${data_dir}"
|
||||||
|
ok "证书同步任务已安装并完成首次同步"
|
||||||
|
|
||||||
|
if command -v setfacl &>/dev/null && setup_caddy_acls "${data_dir}"; then
|
||||||
|
ok "已授予 ${SERVICE_USER} 用户直接读取 Caddy 证书的 ACL 权限(兜底)"
|
||||||
|
else
|
||||||
|
warn "未配置 ACL 兜底(不影响使用,同步镜像始终可读)"
|
||||||
|
fi
|
||||||
|
|
||||||
|
ok "现在可在管理后台“编辑域名”页点击“从 Caddy 获取证书”一键导入"
|
||||||
|
}
|
||||||
|
|
||||||
# ======================== 卸载 ========================
|
# ======================== 卸载 ========================
|
||||||
do_uninstall() {
|
do_uninstall() {
|
||||||
info "========== 卸载 ${SERVICE_NAME} =========="
|
info "========== 卸载 ${SERVICE_NAME} =========="
|
||||||
@@ -358,8 +519,9 @@ case "${1:-}" in
|
|||||||
stop) do_stop ;;
|
stop) do_stop ;;
|
||||||
restart) do_restart ;;
|
restart) do_restart ;;
|
||||||
status) do_status ;;
|
status) do_status ;;
|
||||||
|
setup-caddy-cert) do_setup_caddy_cert ;;
|
||||||
*)
|
*)
|
||||||
echo "用法: sudo $0 {install|uninstall|start|stop|restart|status}"
|
echo "用法: sudo $0 {install|uninstall|start|stop|restart|status|setup-caddy-cert}"
|
||||||
echo ""
|
echo ""
|
||||||
echo " install — 完整安装/更新(拉代码+编译+部署+启动+开机自启)"
|
echo " install — 完整安装/更新(拉代码+编译+部署+启动+开机自启)"
|
||||||
echo " uninstall — 卸载服务(可选保留数据)"
|
echo " uninstall — 卸载服务(可选保留数据)"
|
||||||
@@ -367,6 +529,8 @@ case "${1:-}" in
|
|||||||
echo " stop — 停止服务"
|
echo " stop — 停止服务"
|
||||||
echo " restart — 重启服务"
|
echo " restart — 重启服务"
|
||||||
echo " status — 查看服务状态"
|
echo " status — 查看服务状态"
|
||||||
|
echo " setup-caddy-cert — 授予 mail_go 读取本机 Caddy 证书的 ACL 权限"
|
||||||
|
echo " (后台“从 Caddy 获取证书”按钮的前置条件)"
|
||||||
exit 1
|
exit 1
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
@@ -0,0 +1,243 @@
|
|||||||
|
// Package caddycert 从本机 Caddy 的证书存储中查找并读取某个域名
|
||||||
|
// 的 TLS 证书与私钥,供 MailGo 一键导入使用。
|
||||||
|
//
|
||||||
|
// Caddy(certmagic)将 ACME 证书保存在其数据目录下的
|
||||||
|
//
|
||||||
|
// <data>/certificates/<CA 目录>/<域名>/<域名>.crt
|
||||||
|
// <data>/certificates/<CA 目录>/<域名>/<域名>.key
|
||||||
|
//
|
||||||
|
// 数据目录默认是 $HOME/.local/share/caddy(systemd 服务通常是
|
||||||
|
// /var/lib/caddy/.local/share/caddy),可通过配置 caddy.data_dir 覆盖。
|
||||||
|
package caddycert
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/tls"
|
||||||
|
"crypto/x509"
|
||||||
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"os/user"
|
||||||
|
"path/filepath"
|
||||||
|
"sort"
|
||||||
|
"strings"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// DefaultDataDirs 是未显式配置时依次探测的 Caddy 数据目录。
|
||||||
|
var DefaultDataDirs = []string{
|
||||||
|
"/var/lib/caddy/.local/share/caddy", // Debian/Ubuntu 软件包的 systemd 服务默认 HOME
|
||||||
|
"/root/.local/share/caddy", // 直接以 root 运行的 caddy
|
||||||
|
"/home/caddy/.local/share/caddy",
|
||||||
|
}
|
||||||
|
|
||||||
|
// Cert 是从 Caddy 存储中找到的一对证书与私钥(PEM 编码)。
|
||||||
|
type Cert struct {
|
||||||
|
CertPEM []byte // 证书链(含叶子证书)
|
||||||
|
KeyPEM []byte // 私钥
|
||||||
|
Source string // 来源 .crt 文件的绝对路径
|
||||||
|
}
|
||||||
|
|
||||||
|
// Fetch 在给定的 Caddy 证书数据目录中查找 domain 的证书与私钥。
|
||||||
|
//
|
||||||
|
// dataDirs 按优先级从高到低排列,每个目录都是包含 certificates/ 子目录的
|
||||||
|
// Caddy 数据目录(如 /var/lib/caddy/.local/share/caddy,或 mail_go 的同步
|
||||||
|
// 镜像目录 /srv/mail_go/tls/caddy);空字符串项被忽略。dataDirs 为空时仅
|
||||||
|
// 探测 DefaultDataDirs 及当前进程用户的数据目录。
|
||||||
|
//
|
||||||
|
// 返回的证书保证:能组成有效的密钥对、尚未过期、且证书 SAN 覆盖 domain
|
||||||
|
// (支持通配符证书,例如 *.example.com 的证书可匹配 mail.example.com)。
|
||||||
|
func Fetch(domain string, dataDirs []string) (*Cert, error) {
|
||||||
|
domain = strings.ToLower(strings.TrimSpace(domain))
|
||||||
|
if domain == "" {
|
||||||
|
return nil, fmt.Errorf("域名为空")
|
||||||
|
}
|
||||||
|
|
||||||
|
roots := dataRoots(dataDirs)
|
||||||
|
|
||||||
|
var (
|
||||||
|
permDenied []string
|
||||||
|
seen []string // 找到同名/相关文件但证书无效的来源
|
||||||
|
)
|
||||||
|
for _, root := range roots {
|
||||||
|
cert, found, invalid, err := searchRoot(domain, root)
|
||||||
|
if err != nil {
|
||||||
|
if os.IsPermission(err) {
|
||||||
|
permDenied = append(permDenied, root)
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if found {
|
||||||
|
return cert, nil
|
||||||
|
}
|
||||||
|
seen = append(seen, invalid...)
|
||||||
|
}
|
||||||
|
|
||||||
|
msg := fmt.Sprintf("在 Caddy 证书存储中未找到域名 %q 的证书(请确认 Caddy 已为该域名签发证书)", domain)
|
||||||
|
if len(seen) > 0 {
|
||||||
|
msg += fmt.Sprintf(";发现相关文件但证书无效/已过期/不匹配域名: %s", strings.Join(seen, "、"))
|
||||||
|
}
|
||||||
|
if len(permDenied) > 0 {
|
||||||
|
msg += fmt.Sprintf(";另有目录因权限不足未能检查: %s,可运行 install.sh 的 setup-caddy-cert 授予 %s 用户读取权限",
|
||||||
|
strings.Join(permDenied, "、"), currentUsername())
|
||||||
|
}
|
||||||
|
return nil, fmt.Errorf("%s", msg)
|
||||||
|
}
|
||||||
|
|
||||||
|
// dataRoots 返回要探测的候选数据目录列表(去重,保留优先级顺序)。
|
||||||
|
func dataRoots(dataDirs []string) []string {
|
||||||
|
var roots []string
|
||||||
|
seen := map[string]bool{}
|
||||||
|
add := func(p string) {
|
||||||
|
p = strings.TrimRight(filepath.Clean(p), string(filepath.Separator))
|
||||||
|
if p == "" || seen[p] {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
seen[p] = true
|
||||||
|
roots = append(roots, p)
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, d := range dataDirs {
|
||||||
|
add(d)
|
||||||
|
}
|
||||||
|
for _, d := range DefaultDataDirs {
|
||||||
|
add(d)
|
||||||
|
}
|
||||||
|
if home, err := os.UserHomeDir(); err == nil && home != "" {
|
||||||
|
add(filepath.Join(home, ".local", "share", "caddy"))
|
||||||
|
}
|
||||||
|
return roots
|
||||||
|
}
|
||||||
|
|
||||||
|
// searchRoot 在单个数据目录中查找 domain 的证书。
|
||||||
|
// 返回 (证书, 是否找到, 找到但无效的来源列表, 错误)。
|
||||||
|
func searchRoot(domain, root string) (*Cert, bool, []string, error) {
|
||||||
|
// 允许把 certificates/ 目录本身当作 data_dir 传入
|
||||||
|
certsDir := root
|
||||||
|
if filepath.Base(certsDir) != "certificates" {
|
||||||
|
certsDir = filepath.Join(root, "certificates")
|
||||||
|
}
|
||||||
|
|
||||||
|
info, err := os.Stat(certsDir)
|
||||||
|
if err != nil {
|
||||||
|
if os.IsNotExist(err) {
|
||||||
|
return nil, false, nil, nil
|
||||||
|
}
|
||||||
|
return nil, false, nil, err
|
||||||
|
}
|
||||||
|
if !info.IsDir() {
|
||||||
|
return nil, false, nil, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
caDirs, err := os.ReadDir(certsDir)
|
||||||
|
if err != nil {
|
||||||
|
return nil, false, nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
var invalid []string
|
||||||
|
|
||||||
|
// 1) 直接路径: certificates/<CA>/<domain>/<domain>.crt|.key
|
||||||
|
for _, ca := range caDirs {
|
||||||
|
if !ca.IsDir() {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
cert, found, bad, err := readDomainDir(filepath.Join(certsDir, ca.Name(), domain), domain)
|
||||||
|
if err != nil {
|
||||||
|
return nil, false, nil, err
|
||||||
|
}
|
||||||
|
if found {
|
||||||
|
return cert, true, nil, nil
|
||||||
|
}
|
||||||
|
invalid = append(invalid, bad...)
|
||||||
|
}
|
||||||
|
|
||||||
|
// 2) 全量扫描,处理通配符证书(如 *.example.com 目录)等情况
|
||||||
|
for _, ca := range caDirs {
|
||||||
|
if !ca.IsDir() {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
caPath := filepath.Join(certsDir, ca.Name())
|
||||||
|
domDirs, err := os.ReadDir(caPath)
|
||||||
|
if err != nil {
|
||||||
|
return nil, false, nil, err
|
||||||
|
}
|
||||||
|
for _, d := range domDirs {
|
||||||
|
if !d.IsDir() {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
cert, found, bad, err := readDomainDir(filepath.Join(caPath, d.Name()), domain)
|
||||||
|
if err != nil {
|
||||||
|
return nil, false, nil, err
|
||||||
|
}
|
||||||
|
if found {
|
||||||
|
return cert, true, nil, nil
|
||||||
|
}
|
||||||
|
invalid = append(invalid, bad...)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
sort.Strings(invalid)
|
||||||
|
return nil, false, invalid, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// readDomainDir 读取 Caddy 某个域名目录下的 <name>.crt 与 <name>.key,
|
||||||
|
// 校验其是否为 domain 的有效证书。bad 返回“存在但无效”的来源路径。
|
||||||
|
func readDomainDir(dirPath, domain string) (*Cert, bool, []string, error) {
|
||||||
|
name := filepath.Base(dirPath)
|
||||||
|
certPath := filepath.Join(dirPath, name+".crt")
|
||||||
|
keyPath := filepath.Join(dirPath, name+".key")
|
||||||
|
|
||||||
|
certPEM, err := os.ReadFile(certPath)
|
||||||
|
if err != nil {
|
||||||
|
if os.IsNotExist(err) {
|
||||||
|
return nil, false, nil, nil
|
||||||
|
}
|
||||||
|
return nil, false, nil, err
|
||||||
|
}
|
||||||
|
keyPEM, err := os.ReadFile(keyPath)
|
||||||
|
if err != nil {
|
||||||
|
if os.IsNotExist(err) {
|
||||||
|
return nil, false, nil, nil
|
||||||
|
}
|
||||||
|
return nil, false, nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
// 只有与目标域名相关的目录才值得报“无效”,否则静默跳过
|
||||||
|
related := strings.TrimSuffix(name, "."+domain) == domain ||
|
||||||
|
name == domain || strings.HasPrefix(name, "*.") && strings.HasSuffix(domain, name[1:])
|
||||||
|
|
||||||
|
if !validPair(certPEM, keyPEM, domain) {
|
||||||
|
if related {
|
||||||
|
return nil, false, []string{certPath}, nil
|
||||||
|
}
|
||||||
|
return nil, false, nil, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
return &Cert{CertPEM: certPEM, KeyPEM: keyPEM, Source: certPath}, true, nil, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// validPair 校验证书/私钥是否组成有效密钥对、未过期且 SAN 覆盖 domain。
|
||||||
|
func validPair(certPEM, keyPEM []byte, domain string) bool {
|
||||||
|
pair, err := tls.X509KeyPair(certPEM, keyPEM)
|
||||||
|
if err != nil {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
if len(pair.Certificate) == 0 {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
leaf, err := x509.ParseCertificate(pair.Certificate[0])
|
||||||
|
if err != nil {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
if time.Now().After(leaf.NotAfter) {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
return leaf.VerifyHostname(domain) == nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// currentUsername 返回当前进程的运行用户(错误提示用)。
|
||||||
|
func currentUsername() string {
|
||||||
|
if u, err := user.Current(); err == nil && u.Username != "" {
|
||||||
|
return u.Username
|
||||||
|
}
|
||||||
|
return os.Getenv("USER")
|
||||||
|
}
|
||||||
@@ -0,0 +1,176 @@
|
|||||||
|
package caddycert
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/rand"
|
||||||
|
"crypto/rsa"
|
||||||
|
"crypto/x509"
|
||||||
|
"crypto/x509/pkix"
|
||||||
|
"encoding/pem"
|
||||||
|
"math/big"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// makeCert 生成一份自签名证书(含指定 SAN),返回 PEM 编码的证书与私钥。
|
||||||
|
func makeCert(t *testing.T, dnsNames []string, notBefore, notAfter time.Time) (certPEM, keyPEM []byte) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
key, err := rsa.GenerateKey(rand.Reader, 2048)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("生成私钥失败: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
tmpl := &x509.Certificate{
|
||||||
|
SerialNumber: big.NewInt(1),
|
||||||
|
Subject: pkix.Name{CommonName: dnsNames[0]},
|
||||||
|
DNSNames: dnsNames,
|
||||||
|
NotBefore: notBefore,
|
||||||
|
NotAfter: notAfter,
|
||||||
|
KeyUsage: x509.KeyUsageDigitalSignature | x509.KeyUsageKeyEncipherment,
|
||||||
|
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth},
|
||||||
|
}
|
||||||
|
der, err := x509.CreateCertificate(rand.Reader, tmpl, tmpl, &key.PublicKey, key)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("生成证书失败: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
certPEM = pem.EncodeToMemory(&pem.Block{Type: "CERTIFICATE", Bytes: der})
|
||||||
|
keyPEM = pem.EncodeToMemory(&pem.Block{Type: "RSA PRIVATE KEY", Bytes: x509.MarshalPKCS1PrivateKey(key)})
|
||||||
|
return certPEM, keyPEM
|
||||||
|
}
|
||||||
|
|
||||||
|
// writeSite 在 Caddy 风格目录结构中写入某个域名的证书。
|
||||||
|
func writeSite(t *testing.T, dataDir, domain string, certPEM, keyPEM []byte) {
|
||||||
|
t.Helper()
|
||||||
|
dir := filepath.Join(dataDir, "certificates", "acme-v02.api.letsencrypt.org-directory", domain)
|
||||||
|
if err := os.MkdirAll(dir, 0700); err != nil {
|
||||||
|
t.Fatalf("创建目录失败: %v", err)
|
||||||
|
}
|
||||||
|
if err := os.WriteFile(filepath.Join(dir, domain+".crt"), certPEM, 0600); err != nil {
|
||||||
|
t.Fatalf("写入证书失败: %v", err)
|
||||||
|
}
|
||||||
|
if err := os.WriteFile(filepath.Join(dir, domain+".key"), keyPEM, 0600); err != nil {
|
||||||
|
t.Fatalf("写入私钥失败: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFetchExactDomain(t *testing.T) {
|
||||||
|
dataDir := t.TempDir()
|
||||||
|
certPEM, keyPEM := makeCert(t, []string{"mail.example.com"}, time.Now().Add(-time.Hour), time.Now().Add(24*time.Hour))
|
||||||
|
writeSite(t, dataDir, "mail.example.com", certPEM, keyPEM)
|
||||||
|
|
||||||
|
got, err := Fetch("mail.example.com", []string{dataDir})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Fetch 失败: %v", err)
|
||||||
|
}
|
||||||
|
if string(got.CertPEM) != string(certPEM) {
|
||||||
|
t.Error("返回的证书与写入的不一致")
|
||||||
|
}
|
||||||
|
if string(got.KeyPEM) != string(keyPEM) {
|
||||||
|
t.Error("返回的私钥与写入的不一致")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFetchWildcardCoversSubdomain(t *testing.T) {
|
||||||
|
dataDir := t.TempDir()
|
||||||
|
certPEM, keyPEM := makeCert(t, []string{"*.example.com", "example.com"}, time.Now().Add(-time.Hour), time.Now().Add(24*time.Hour))
|
||||||
|
writeSite(t, dataDir, "*.example.com", certPEM, keyPEM)
|
||||||
|
|
||||||
|
got, err := Fetch("mail.example.com", []string{dataDir})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("通配符证书应覆盖子域名,Fetch 失败: %v", err)
|
||||||
|
}
|
||||||
|
if got.Source == "" {
|
||||||
|
t.Error("Source 不应为空")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFetchSkipsExpiredCert(t *testing.T) {
|
||||||
|
dataDir := t.TempDir()
|
||||||
|
certPEM, keyPEM := makeCert(t, []string{"mail.example.com"}, time.Now().Add(-48*time.Hour), time.Now().Add(-24*time.Hour))
|
||||||
|
writeSite(t, dataDir, "mail.example.com", certPEM, keyPEM)
|
||||||
|
|
||||||
|
_, err := Fetch("mail.example.com", []string{dataDir})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("过期证书不应被返回")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "无效") {
|
||||||
|
t.Errorf("错误信息应说明证书无效,实际: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFetchNotExist(t *testing.T) {
|
||||||
|
dataDir := t.TempDir()
|
||||||
|
|
||||||
|
_, err := Fetch("nobody.example.com", []string{dataDir})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("不存在的域名应返回错误")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "未找到") {
|
||||||
|
t.Errorf("错误信息应包含“未找到”,实际: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFetchUppercaseDomainIsLowercased(t *testing.T) {
|
||||||
|
dataDir := t.TempDir()
|
||||||
|
certPEM, keyPEM := makeCert(t, []string{"mail.example.com"}, time.Now().Add(-time.Hour), time.Now().Add(24*time.Hour))
|
||||||
|
writeSite(t, dataDir, "mail.example.com", certPEM, keyPEM)
|
||||||
|
|
||||||
|
if _, err := Fetch("MAIL.Example.COM", []string{dataDir}); err != nil {
|
||||||
|
t.Fatalf("域名大小写应被归一化,Fetch 失败: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFetchCertificatesDirAsDataDir(t *testing.T) {
|
||||||
|
dataDir := t.TempDir()
|
||||||
|
certPEM, keyPEM := makeCert(t, []string{"mail.example.com"}, time.Now().Add(-time.Hour), time.Now().Add(24*time.Hour))
|
||||||
|
writeSite(t, dataDir, "mail.example.com", certPEM, keyPEM)
|
||||||
|
|
||||||
|
// 把 certificates 目录本身当作 data_dir 传入
|
||||||
|
certsDir := filepath.Join(dataDir, "certificates")
|
||||||
|
if _, err := Fetch("mail.example.com", []string{certsDir}); err != nil {
|
||||||
|
t.Fatalf("data_dir 直接指向 certificates 目录时应可用: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFetchPrefersFirstDataDir(t *testing.T) {
|
||||||
|
// 模拟“同步镜像目录优先”:两个目录都有该域名证书时,应返回第一个的
|
||||||
|
dirA := t.TempDir()
|
||||||
|
dirB := t.TempDir()
|
||||||
|
certA, keyA := makeCert(t, []string{"mail.example.com"}, time.Now().Add(-time.Hour), time.Now().Add(48*time.Hour))
|
||||||
|
certB, keyB := makeCert(t, []string{"mail.example.com"}, time.Now().Add(-time.Hour), time.Now().Add(24*time.Hour))
|
||||||
|
writeSite(t, dirA, "mail.example.com", certA, keyA)
|
||||||
|
writeSite(t, dirB, "mail.example.com", certB, keyB)
|
||||||
|
|
||||||
|
got, err := Fetch("mail.example.com", []string{dirA, dirB})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Fetch 失败: %v", err)
|
||||||
|
}
|
||||||
|
if string(got.CertPEM) != string(certA) {
|
||||||
|
t.Error("应按优先级返回第一个目录中的证书")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFetchPermissionDeniedHint(t *testing.T) {
|
||||||
|
if os.Geteuid() == 0 {
|
||||||
|
t.Skip("root 用户不受文件权限限制,跳过")
|
||||||
|
}
|
||||||
|
dataDir := t.TempDir()
|
||||||
|
certPEM, keyPEM := makeCert(t, []string{"mail.example.com"}, time.Now().Add(-time.Hour), time.Now().Add(24*time.Hour))
|
||||||
|
writeSite(t, dataDir, "mail.example.com", certPEM, keyPEM)
|
||||||
|
if err := os.Chmod(dataDir, 0000); err != nil {
|
||||||
|
t.Fatalf("chmod 失败: %v", err)
|
||||||
|
}
|
||||||
|
defer os.Chmod(dataDir, 0700)
|
||||||
|
|
||||||
|
_, err := Fetch("mail.example.com", []string{dataDir})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("无权限时应返回错误")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "权限不足") {
|
||||||
|
t.Errorf("错误信息应提示权限不足,实际: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -7,6 +7,7 @@ import (
|
|||||||
|
|
||||||
"mail_go/config"
|
"mail_go/config"
|
||||||
"mail_go/internal/store"
|
"mail_go/internal/store"
|
||||||
|
"mail_go/internal/tlsutil"
|
||||||
|
|
||||||
"github.com/emersion/go-imap/backend"
|
"github.com/emersion/go-imap/backend"
|
||||||
imapserver "github.com/emersion/go-imap/server"
|
imapserver "github.com/emersion/go-imap/server"
|
||||||
@@ -16,25 +17,25 @@ import (
|
|||||||
type IMAPServer struct {
|
type IMAPServer struct {
|
||||||
stores *store.Stores
|
stores *store.Stores
|
||||||
cfg config.IMAPConfig
|
cfg config.IMAPConfig
|
||||||
|
tlsLoader *tlsutil.Loader
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewIMAPServer creates a new IMAP server instance.
|
// NewIMAPServer creates a new IMAP server instance. tlsLoader may be nil
|
||||||
func NewIMAPServer(cfg config.IMAPConfig, stores *store.Stores) *IMAPServer {
|
// when TLS is not configured.
|
||||||
|
func NewIMAPServer(cfg config.IMAPConfig, stores *store.Stores, tlsLoader *tlsutil.Loader) *IMAPServer {
|
||||||
return &IMAPServer{
|
return &IMAPServer{
|
||||||
stores: stores,
|
stores: stores,
|
||||||
cfg: cfg,
|
cfg: cfg,
|
||||||
|
tlsLoader: tlsLoader,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *IMAPServer) tlsConfig() (*tls.Config, error) {
|
func (s *IMAPServer) tlsConfig() (*tls.Config, error) {
|
||||||
if s.cfg.TLSCert == "" || s.cfg.TLSKey == "" {
|
if s.tlsLoader == nil {
|
||||||
return nil, fmt.Errorf("IMAP TLS certificate or key not configured")
|
return nil, fmt.Errorf("IMAP TLS certificate or key not configured")
|
||||||
}
|
}
|
||||||
cert, err := tls.LoadX509KeyPair(s.cfg.TLSCert, s.cfg.TLSKey)
|
// GetCertificate 每次握手按需重载证书,证书更新后无需重启服务
|
||||||
if err != nil {
|
return &tls.Config{GetCertificate: s.tlsLoader.GetCertificate}, nil
|
||||||
return nil, fmt.Errorf("failed to load IMAP TLS certificate: %w", err)
|
|
||||||
}
|
|
||||||
return &tls.Config{Certificates: []tls.Certificate{cert}}, nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// newServer creates a configured imapserver.Server with the given address.
|
// newServer creates a configured imapserver.Server with the given address.
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ import (
|
|||||||
"mail_go/config"
|
"mail_go/config"
|
||||||
"mail_go/internal/db"
|
"mail_go/internal/db"
|
||||||
"mail_go/internal/store"
|
"mail_go/internal/store"
|
||||||
|
"mail_go/internal/tlsutil"
|
||||||
)
|
)
|
||||||
|
|
||||||
// POP3Server implements a simple POP3 mail server over TCP.
|
// POP3Server implements a simple POP3 mail server over TCP.
|
||||||
@@ -21,23 +22,22 @@ type POP3Server struct {
|
|||||||
listener net.Listener
|
listener net.Listener
|
||||||
stores *store.Stores
|
stores *store.Stores
|
||||||
cfg config.POP3Config
|
cfg config.POP3Config
|
||||||
|
tlsLoader *tlsutil.Loader
|
||||||
wg sync.WaitGroup
|
wg sync.WaitGroup
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewPOP3Server creates a new POP3 server instance.
|
// NewPOP3Server creates a new POP3 server instance. tlsLoader may be nil
|
||||||
func NewPOP3Server(cfg config.POP3Config, stores *store.Stores) *POP3Server {
|
// when TLS is not configured.
|
||||||
return &POP3Server{stores: stores, cfg: cfg}
|
func NewPOP3Server(cfg config.POP3Config, stores *store.Stores, tlsLoader *tlsutil.Loader) *POP3Server {
|
||||||
|
return &POP3Server{stores: stores, cfg: cfg, tlsLoader: tlsLoader}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *POP3Server) tlsConfig() (*tls.Config, error) {
|
func (s *POP3Server) tlsConfig() (*tls.Config, error) {
|
||||||
if s.cfg.TLSCert == "" || s.cfg.TLSKey == "" {
|
if s.tlsLoader == nil {
|
||||||
return nil, fmt.Errorf("POP3 TLS certificate or key not configured")
|
return nil, fmt.Errorf("POP3 TLS certificate or key not configured")
|
||||||
}
|
}
|
||||||
cert, err := tls.LoadX509KeyPair(s.cfg.TLSCert, s.cfg.TLSKey)
|
// GetCertificate 每次握手按需重载证书,证书更新后无需重启服务
|
||||||
if err != nil {
|
return &tls.Config{GetCertificate: s.tlsLoader.GetCertificate}, nil
|
||||||
return nil, fmt.Errorf("load POP3 TLS certificate failed: %w", err)
|
|
||||||
}
|
|
||||||
return &tls.Config{Certificates: []tls.Certificate{cert}}, nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Start starts the POP3 server on the configured plain-text port.
|
// Start starts the POP3 server on the configured plain-text port.
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ import (
|
|||||||
"mail_go/internal/outbound"
|
"mail_go/internal/outbound"
|
||||||
"mail_go/internal/storage"
|
"mail_go/internal/storage"
|
||||||
"mail_go/internal/store"
|
"mail_go/internal/store"
|
||||||
|
"mail_go/internal/tlsutil"
|
||||||
|
|
||||||
"github.com/emersion/go-message/mail"
|
"github.com/emersion/go-message/mail"
|
||||||
"github.com/emersion/go-sasl"
|
"github.com/emersion/go-sasl"
|
||||||
@@ -35,23 +36,21 @@ type SMTPServer struct {
|
|||||||
storage *storage.AttachmentStorage
|
storage *storage.AttachmentStorage
|
||||||
outbound *outbound.Manager
|
outbound *outbound.Manager
|
||||||
cfg config.SMTPConfig
|
cfg config.SMTPConfig
|
||||||
|
tlsLoader *tlsutil.Loader
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewSMTPServer creates a new SMTP server instance.
|
// NewSMTPServer creates a new SMTP server instance. tlsLoader may be nil
|
||||||
func NewSMTPServer(cfg config.SMTPConfig, stores *store.Stores, attStorage *storage.AttachmentStorage, ob *outbound.Manager) *SMTPServer {
|
// when TLS is not configured.
|
||||||
return &SMTPServer{stores: stores, storage: attStorage, outbound: ob, cfg: cfg}
|
func NewSMTPServer(cfg config.SMTPConfig, stores *store.Stores, attStorage *storage.AttachmentStorage, ob *outbound.Manager, tlsLoader *tlsutil.Loader) *SMTPServer {
|
||||||
|
return &SMTPServer{stores: stores, storage: attStorage, outbound: ob, cfg: cfg, tlsLoader: tlsLoader}
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *SMTPServer) tlsConfig() (*tls.Config, error) {
|
func (s *SMTPServer) tlsConfig() (*tls.Config, error) {
|
||||||
if s.cfg.TLSCert == "" || s.cfg.TLSKey == "" {
|
if s.tlsLoader == nil {
|
||||||
return nil, fmt.Errorf("SMTP TLS certificate or key not configured")
|
return nil, fmt.Errorf("SMTP TLS certificate or key not configured")
|
||||||
}
|
}
|
||||||
|
// GetCertificate 每次握手按需重载证书,证书更新后无需重启服务
|
||||||
cert, err := tls.LoadX509KeyPair(s.cfg.TLSCert, s.cfg.TLSKey)
|
return &tls.Config{GetCertificate: s.tlsLoader.GetCertificate}, nil
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("failed to load SMTP TLS certificate: %w", err)
|
|
||||||
}
|
|
||||||
return &tls.Config{Certificates: []tls.Certificate{cert}}, nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s *SMTPServer) newServer(addr string, mode smtpMode, tlsConfig *tls.Config) *smtp.Server {
|
func (s *SMTPServer) newServer(addr string, mode smtpMode, tlsConfig *tls.Config) *smtp.Server {
|
||||||
|
|||||||
@@ -0,0 +1,127 @@
|
|||||||
|
// Package tlsutil 提供 TLS 证书热加载:每次 TLS 握手时按需检查
|
||||||
|
// 证书路径与文件内容是否变化,变化则自动重载,证书更新后无需重启
|
||||||
|
// 服务即可生效。
|
||||||
|
package tlsutil
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/tls"
|
||||||
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"sync"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// retryInterval 是重载失败后的最小重试间隔,避免证书文件损坏时
|
||||||
|
// 每个握手都重复做无意义的磁盘读取。
|
||||||
|
const retryInterval = 5 * time.Second
|
||||||
|
|
||||||
|
// Source 返回当前应使用的证书路径。路径可能随时间变化(例如管理后台
|
||||||
|
// 一键导入证书后切换到新的域名证书);返回空路径表示暂无可用证书。
|
||||||
|
type Source func() (certPath, keyPath string)
|
||||||
|
|
||||||
|
// Loader 管理一对可热加载的证书。所有方法均并发安全。
|
||||||
|
type Loader struct {
|
||||||
|
mu sync.Mutex
|
||||||
|
source Source
|
||||||
|
certPath string
|
||||||
|
keyPath string
|
||||||
|
cert *tls.Certificate
|
||||||
|
certMod time.Time
|
||||||
|
keyMod time.Time
|
||||||
|
lastTry time.Time
|
||||||
|
logf func(format string, args ...interface{})
|
||||||
|
}
|
||||||
|
|
||||||
|
// NewLoader 立即加载并校验证书,失败返回错误(保持启动时 fail-fast)。
|
||||||
|
// source 为 nil 时证书路径固定不变,仅检测文件内容变化。
|
||||||
|
func NewLoader(certPath, keyPath string, source Source, logf func(string, ...interface{})) (*Loader, error) {
|
||||||
|
if certPath == "" || keyPath == "" {
|
||||||
|
return nil, fmt.Errorf("TLS 证书路径为空")
|
||||||
|
}
|
||||||
|
l := &Loader{
|
||||||
|
source: source,
|
||||||
|
certPath: certPath,
|
||||||
|
keyPath: keyPath,
|
||||||
|
logf: logf,
|
||||||
|
}
|
||||||
|
if err := l.load(); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return l, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// GetCertificate 实现 tls.Config.GetCertificate:
|
||||||
|
// 每次 TLS 握手时检查证书路径与文件是否有变化,有则自动重载;
|
||||||
|
// 重载失败时继续使用上一次成功加载的证书,避免中断现有服务。
|
||||||
|
func (l *Loader) GetCertificate(_ *tls.ClientHelloInfo) (*tls.Certificate, error) {
|
||||||
|
l.mu.Lock()
|
||||||
|
defer l.mu.Unlock()
|
||||||
|
|
||||||
|
certPath, keyPath := l.certPath, l.keyPath
|
||||||
|
if l.source != nil {
|
||||||
|
certPath, keyPath = l.source()
|
||||||
|
}
|
||||||
|
if certPath == "" || keyPath == "" {
|
||||||
|
// 暂无证书可用:继续使用旧证书(若有)
|
||||||
|
return l.current()
|
||||||
|
}
|
||||||
|
|
||||||
|
changed := certPath != l.certPath || keyPath != l.keyPath
|
||||||
|
if !changed {
|
||||||
|
changed = l.filesChanged(certPath, keyPath)
|
||||||
|
}
|
||||||
|
|
||||||
|
// 仅在重载失败后节流(避免证书文件损坏时每个握手都重复读盘);
|
||||||
|
// 成功后清零节流,保证正常的连续更新立即生效。
|
||||||
|
if changed && time.Since(l.lastTry) >= retryInterval {
|
||||||
|
l.lastTry = time.Now()
|
||||||
|
l.certPath, l.keyPath = certPath, keyPath
|
||||||
|
if err := l.load(); err != nil {
|
||||||
|
if l.logf != nil {
|
||||||
|
l.logf("TLS 证书重载失败 (%s, %s): %v,继续使用旧证书", certPath, keyPath, err)
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
l.lastTry = time.Time{}
|
||||||
|
if l.logf != nil {
|
||||||
|
l.logf("TLS 证书已热加载: %s", certPath)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return l.current()
|
||||||
|
}
|
||||||
|
|
||||||
|
// current 返回当前已加载的证书。
|
||||||
|
func (l *Loader) current() (*tls.Certificate, error) {
|
||||||
|
if l.cert == nil {
|
||||||
|
return nil, fmt.Errorf("TLS 证书不可用")
|
||||||
|
}
|
||||||
|
return l.cert, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// filesChanged 判断证书/私钥文件自上次加载后是否被修改。
|
||||||
|
// 文件暂时不可读(如正在原子替换)时视为已变化,触发重载尝试。
|
||||||
|
func (l *Loader) filesChanged(certPath, keyPath string) bool {
|
||||||
|
stC, errC := os.Stat(certPath)
|
||||||
|
stK, errK := os.Stat(keyPath)
|
||||||
|
if errC != nil || errK != nil {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
return !stC.ModTime().Equal(l.certMod) || !stK.ModTime().Equal(l.keyMod)
|
||||||
|
}
|
||||||
|
|
||||||
|
// load 从当前路径加载证书对并记录文件修改时间。
|
||||||
|
func (l *Loader) load() error {
|
||||||
|
cert, err := tls.LoadX509KeyPair(l.certPath, l.keyPath)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
if stC, err := os.Stat(l.certPath); err == nil {
|
||||||
|
l.certMod = stC.ModTime()
|
||||||
|
}
|
||||||
|
if stK, err := os.Stat(l.keyPath); err == nil {
|
||||||
|
l.keyMod = stK.ModTime()
|
||||||
|
}
|
||||||
|
l.cert = &cert
|
||||||
|
return nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,241 @@
|
|||||||
|
package tlsutil
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/rand"
|
||||||
|
"crypto/rsa"
|
||||||
|
"crypto/x509"
|
||||||
|
"crypto/x509/pkix"
|
||||||
|
"encoding/pem"
|
||||||
|
"math/big"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"sync"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// writeCertPair 生成一对自签名证书并写入文件,返回叶子证书序列号。
|
||||||
|
func writeCertPair(t *testing.T, certPath, keyPath string, serial int64) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
key, err := rsa.GenerateKey(rand.Reader, 2048)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("生成私钥失败: %v", err)
|
||||||
|
}
|
||||||
|
tmpl := &x509.Certificate{
|
||||||
|
SerialNumber: big.NewInt(serial),
|
||||||
|
Subject: pkix.Name{CommonName: "test"},
|
||||||
|
NotBefore: time.Now().Add(-time.Hour),
|
||||||
|
NotAfter: time.Now().Add(24 * time.Hour),
|
||||||
|
DNSNames: []string{"localhost"},
|
||||||
|
KeyUsage: x509.KeyUsageDigitalSignature | x509.KeyUsageKeyEncipherment,
|
||||||
|
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth},
|
||||||
|
}
|
||||||
|
der, err := x509.CreateCertificate(rand.Reader, tmpl, tmpl, &key.PublicKey, key)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("生成证书失败: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
certPEM := pem.EncodeToMemory(&pem.Block{Type: "CERTIFICATE", Bytes: der})
|
||||||
|
keyPEM := pem.EncodeToMemory(&pem.Block{Type: "RSA PRIVATE KEY", Bytes: x509.MarshalPKCS1PrivateKey(key)})
|
||||||
|
|
||||||
|
if err := os.MkdirAll(filepath.Dir(certPath), 0700); err != nil {
|
||||||
|
t.Fatalf("创建目录失败: %v", err)
|
||||||
|
}
|
||||||
|
if err := os.WriteFile(certPath, certPEM, 0600); err != nil {
|
||||||
|
t.Fatalf("写入证书失败: %v", err)
|
||||||
|
}
|
||||||
|
if err := os.WriteFile(keyPath, keyPEM, 0600); err != nil {
|
||||||
|
t.Fatalf("写入私钥失败: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func leafSerial(t *testing.T, cert *x509.Certificate) *big.Int {
|
||||||
|
t.Helper()
|
||||||
|
return cert.SerialNumber
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewLoaderFailsFast(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
certPath := filepath.Join(dir, "cert.pem")
|
||||||
|
keyPath := filepath.Join(dir, "key.pem")
|
||||||
|
os.WriteFile(certPath, []byte("garbage"), 0600)
|
||||||
|
os.WriteFile(keyPath, []byte("garbage"), 0600)
|
||||||
|
|
||||||
|
if _, err := NewLoader(certPath, keyPath, nil, nil); err == nil {
|
||||||
|
t.Fatal("无效证书应返回错误")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestReloadOnFileChange(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
certPath := filepath.Join(dir, "cert.pem")
|
||||||
|
keyPath := filepath.Join(dir, "key.pem")
|
||||||
|
|
||||||
|
writeCertPair(t, certPath, keyPath, 1)
|
||||||
|
l, err := NewLoader(certPath, keyPath, nil, nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("NewLoader 失败: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
c1, err := l.GetCertificate(nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GetCertificate 失败: %v", err)
|
||||||
|
}
|
||||||
|
if c1.Leaf == nil {
|
||||||
|
if parsed, err := x509.ParseCertificate(c1.Certificate[0]); err == nil {
|
||||||
|
c1.Leaf = parsed
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if leafSerial(t, c1.Leaf).Int64() != 1 {
|
||||||
|
t.Fatalf("初始证书序列号应为 1")
|
||||||
|
}
|
||||||
|
|
||||||
|
// 替换文件内容(模拟证书更新),无需重启
|
||||||
|
time.Sleep(10 * time.Millisecond) // 确保 mtime 变化
|
||||||
|
writeCertPair(t, certPath, keyPath, 2)
|
||||||
|
|
||||||
|
c2, err := l.GetCertificate(nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("更新后 GetCertificate 失败: %v", err)
|
||||||
|
}
|
||||||
|
if parsed, err := x509.ParseCertificate(c2.Certificate[0]); err == nil {
|
||||||
|
c2.Leaf = parsed
|
||||||
|
}
|
||||||
|
if leafSerial(t, c2.Leaf).Int64() != 2 {
|
||||||
|
t.Fatal("文件更新后应自动加载新证书(序列号 2)")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStaleCertOnInvalidReload(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
certPath := filepath.Join(dir, "cert.pem")
|
||||||
|
keyPath := filepath.Join(dir, "key.pem")
|
||||||
|
|
||||||
|
writeCertPair(t, certPath, keyPath, 1)
|
||||||
|
l, err := NewLoader(certPath, keyPath, nil, nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("NewLoader 失败: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// 写入损坏的证书:重载失败时应继续使用旧证书
|
||||||
|
time.Sleep(10 * time.Millisecond)
|
||||||
|
os.WriteFile(certPath, []byte("broken"), 0600)
|
||||||
|
|
||||||
|
c, err := l.GetCertificate(nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("重载失败时不应返回错误: %v", err)
|
||||||
|
}
|
||||||
|
if parsed, err := x509.ParseCertificate(c.Certificate[0]); err == nil {
|
||||||
|
c.Leaf = parsed
|
||||||
|
}
|
||||||
|
if leafSerial(t, c.Leaf).Int64() != 1 {
|
||||||
|
t.Fatal("重载失败时应继续使用旧证书")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSourcePathSwitch(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
certA := filepath.Join(dir, "a", "cert.pem")
|
||||||
|
keyA := filepath.Join(dir, "a", "key.pem")
|
||||||
|
certB := filepath.Join(dir, "b", "cert.pem")
|
||||||
|
keyB := filepath.Join(dir, "b", "key.pem")
|
||||||
|
writeCertPair(t, certA, keyA, 1)
|
||||||
|
writeCertPair(t, certB, keyB, 2)
|
||||||
|
|
||||||
|
// 初始用 A,source 后续切换到 B(模拟后台导入新域名证书)
|
||||||
|
source := func() (string, string) { return certB, keyB }
|
||||||
|
l, err := NewLoader(certA, keyA, source, nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("NewLoader 失败: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
c, err := l.GetCertificate(nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GetCertificate 失败: %v", err)
|
||||||
|
}
|
||||||
|
if parsed, err := x509.ParseCertificate(c.Certificate[0]); err == nil {
|
||||||
|
c.Leaf = parsed
|
||||||
|
}
|
||||||
|
if leafSerial(t, c.Leaf).Int64() != 2 {
|
||||||
|
t.Fatal("source 切换路径后应自动加载新证书")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRapidSuccessiveChanges(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
certPath := filepath.Join(dir, "cert.pem")
|
||||||
|
keyPath := filepath.Join(dir, "key.pem")
|
||||||
|
|
||||||
|
writeCertPair(t, certPath, keyPath, 1)
|
||||||
|
l, err := NewLoader(certPath, keyPath, nil, nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("NewLoader 失败: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
serialOf := func() int64 {
|
||||||
|
t.Helper()
|
||||||
|
c, err := l.GetCertificate(nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GetCertificate 失败: %v", err)
|
||||||
|
}
|
||||||
|
parsed, err := x509.ParseCertificate(c.Certificate[0])
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("解析证书失败: %v", err)
|
||||||
|
}
|
||||||
|
return parsed.SerialNumber.Int64()
|
||||||
|
}
|
||||||
|
|
||||||
|
// 5 秒内连续两次更新,两次都应立即生效(节流只针对失败重载)
|
||||||
|
time.Sleep(10 * time.Millisecond)
|
||||||
|
writeCertPair(t, certPath, keyPath, 2)
|
||||||
|
if got := serialOf(); got != 2 {
|
||||||
|
t.Fatalf("第一次更新后应加载序列号 2,实际 %d", got)
|
||||||
|
}
|
||||||
|
|
||||||
|
time.Sleep(10 * time.Millisecond)
|
||||||
|
writeCertPair(t, certPath, keyPath, 3)
|
||||||
|
if got := serialOf(); got != 3 {
|
||||||
|
t.Fatalf("第二次快速更新后应立即加载序列号 3,实际 %d", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestConcurrentGetCertificate(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
certPath := filepath.Join(dir, "cert.pem")
|
||||||
|
keyPath := filepath.Join(dir, "key.pem")
|
||||||
|
writeCertPair(t, certPath, keyPath, 1)
|
||||||
|
|
||||||
|
l, err := NewLoader(certPath, keyPath, nil, nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("NewLoader 失败: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
var wg sync.WaitGroup
|
||||||
|
stop := make(chan struct{})
|
||||||
|
// 并发读
|
||||||
|
for i := 0; i < 8; i++ {
|
||||||
|
wg.Add(1)
|
||||||
|
go func() {
|
||||||
|
defer wg.Done()
|
||||||
|
for {
|
||||||
|
select {
|
||||||
|
case <-stop:
|
||||||
|
return
|
||||||
|
default:
|
||||||
|
if _, err := l.GetCertificate(nil); err != nil {
|
||||||
|
t.Errorf("并发 GetCertificate 失败: %v", err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
}
|
||||||
|
// 同时反复替换证书文件(模拟续期)
|
||||||
|
for i := int64(2); i < 6; i++ {
|
||||||
|
writeCertPair(t, certPath, keyPath, i)
|
||||||
|
time.Sleep(20 * time.Millisecond)
|
||||||
|
}
|
||||||
|
close(stop)
|
||||||
|
wg.Wait()
|
||||||
|
}
|
||||||
@@ -5,12 +5,14 @@ import (
|
|||||||
"fmt"
|
"fmt"
|
||||||
"log"
|
"log"
|
||||||
"net/http"
|
"net/http"
|
||||||
|
"net/url"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"strconv"
|
"strconv"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
|
"mail_go/internal/caddycert"
|
||||||
"mail_go/internal/db"
|
"mail_go/internal/db"
|
||||||
"mail_go/internal/dkim"
|
"mail_go/internal/dkim"
|
||||||
"mail_go/internal/outbound"
|
"mail_go/internal/outbound"
|
||||||
@@ -26,13 +28,14 @@ type AdminHandler struct {
|
|||||||
stores *store.Stores
|
stores *store.Stores
|
||||||
storage *storage.AttachmentStorage
|
storage *storage.AttachmentStorage
|
||||||
tlsDir string
|
tlsDir string
|
||||||
|
caddyDataDir string
|
||||||
outbound *outbound.Manager
|
outbound *outbound.Manager
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewAdminHandler creates a new AdminHandler with the given stores, attachment
|
// NewAdminHandler creates a new AdminHandler with the given stores, attachment
|
||||||
// storage, TLS directory and outbound delivery manager.
|
// storage, TLS directory, Caddy data directory and outbound delivery manager.
|
||||||
func NewAdminHandler(stores *store.Stores, attStorage *storage.AttachmentStorage, tlsDir string, ob *outbound.Manager) *AdminHandler {
|
func NewAdminHandler(stores *store.Stores, attStorage *storage.AttachmentStorage, tlsDir string, caddyDataDir string, ob *outbound.Manager) *AdminHandler {
|
||||||
return &AdminHandler{stores: stores, storage: attStorage, tlsDir: tlsDir, outbound: ob}
|
return &AdminHandler{stores: stores, storage: attStorage, tlsDir: tlsDir, caddyDataDir: caddyDataDir, outbound: ob}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Dashboard renders the admin dashboard with summary statistics.
|
// Dashboard renders the admin dashboard with summary statistics.
|
||||||
@@ -209,6 +212,16 @@ func (h *AdminHandler) EditDomain(c *gin.Context) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
currentUser, _ := c.Get("currentUser")
|
currentUser, _ := c.Get("currentUser")
|
||||||
|
|
||||||
|
caddyMsg, caddyMsgType := "", ""
|
||||||
|
if c.Query("caddy_err") != "" {
|
||||||
|
caddyMsg = c.Query("caddy_err")
|
||||||
|
caddyMsgType = "error"
|
||||||
|
} else if c.Query("caddy_ok") == "1" {
|
||||||
|
caddyMsg = "✅ 已从 Caddy 获取证书并保存到域名 TLS 目录,同时已启用该域名的 TLS;证书已热加载,无需重启服务。"
|
||||||
|
caddyMsgType = "success"
|
||||||
|
}
|
||||||
|
|
||||||
c.HTML(200, "admin_domain_form", gin.H{
|
c.HTML(200, "admin_domain_form", gin.H{
|
||||||
"currentUser": currentUser,
|
"currentUser": currentUser,
|
||||||
"activeFolder": "domains",
|
"activeFolder": "domains",
|
||||||
@@ -217,6 +230,8 @@ func (h *AdminHandler) EditDomain(c *gin.Context) {
|
|||||||
"domain": domain,
|
"domain": domain,
|
||||||
"tlsPublicCert": readTLSCert(domain.TlsCertPath),
|
"tlsPublicCert": readTLSCert(domain.TlsCertPath),
|
||||||
"tlsCertConfigured": domain.TlsCertPath != "" && domain.TlsKeyPath != "",
|
"tlsCertConfigured": domain.TlsCertPath != "" && domain.TlsKeyPath != "",
|
||||||
|
"caddyMsg": caddyMsg,
|
||||||
|
"caddyMsgType": caddyMsgType,
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -264,6 +279,78 @@ func (h *AdminHandler) UpdateDomain(c *gin.Context) {
|
|||||||
c.Redirect(http.StatusFound, "/admin/domains")
|
c.Redirect(http.StatusFound, "/admin/domains")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// FetchCaddyCert 尝试从本机 Caddy 的证书存储中获取该域名的证书与私钥,
|
||||||
|
// 保存到 MailGo 的域名 TLS 目录并更新数据库记录。结果通过查询参数回显到
|
||||||
|
// 编辑页面(caddy_ok=1 成功 / caddy_err=<消息> 失败)。
|
||||||
|
func (h *AdminHandler) FetchCaddyCert(c *gin.Context) {
|
||||||
|
id, err := strconv.ParseUint(c.Param("id"), 10, 64)
|
||||||
|
if err != nil {
|
||||||
|
c.String(http.StatusBadRequest, "无效的域名ID")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
domain, err := h.stores.Domains.GetByID(uint(id))
|
||||||
|
if err != nil {
|
||||||
|
c.String(http.StatusNotFound, "域名不存在")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
editURL := fmt.Sprintf("/admin/domains/%d/edit", domain.ID)
|
||||||
|
fail := func(msg string) {
|
||||||
|
log.Printf("从 Caddy 获取证书失败 domain=%s: %s", domain.Name, msg)
|
||||||
|
c.Redirect(http.StatusFound, editURL+"?caddy_err="+url.QueryEscape(msg))
|
||||||
|
}
|
||||||
|
|
||||||
|
cert, err := caddycert.Fetch(domain.Name, h.caddyCertRoots())
|
||||||
|
if err != nil {
|
||||||
|
fail(fmt.Sprintf("从 Caddy 获取证书失败: %v", err))
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// 保存到域名 TLS 目录(与手动上传证书的位置一致)
|
||||||
|
domainTLSDir := filepath.Join(h.tlsDir, strconv.FormatUint(uint64(domain.ID), 10))
|
||||||
|
if err := os.MkdirAll(domainTLSDir, 0700); err != nil {
|
||||||
|
fail(fmt.Sprintf("创建 TLS 证书目录失败: %v", err))
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
certPath := filepath.Join(domainTLSDir, "cert.pem")
|
||||||
|
keyPath := filepath.Join(domainTLSDir, "key.pem")
|
||||||
|
if err := os.WriteFile(certPath, cert.CertPEM, 0644); err != nil {
|
||||||
|
fail(fmt.Sprintf("保存 TLS 公钥证书失败: %v", err))
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if err := os.WriteFile(keyPath, cert.KeyPEM, 0600); err != nil {
|
||||||
|
fail(fmt.Sprintf("保存 TLS 私钥失败: %v", err))
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
domain.TlsCertPath = certPath
|
||||||
|
domain.TlsKeyPath = keyPath
|
||||||
|
domain.TlsEnabled = true
|
||||||
|
if err := h.stores.Domains.Update(domain); err != nil {
|
||||||
|
fail(fmt.Sprintf("更新域名记录失败: %v", err))
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
log.Printf("已从 Caddy 导入域名 %s 的证书 (%s),热加载生效", domain.Name, cert.Source)
|
||||||
|
c.Redirect(http.StatusFound, editURL+"?caddy_ok=1")
|
||||||
|
}
|
||||||
|
|
||||||
|
// caddyCertRoots 返回按优先级排列的证书来源目录:
|
||||||
|
// 1. MailGo 的同步镜像目录 <storage>/tls/caddy —— 由 install.sh 安装的
|
||||||
|
// systemd path 同步任务以 root 权限从 Caddy 证书存储镜像而来,
|
||||||
|
// mail_go 始终可读,证书续期后自动更新;
|
||||||
|
// 2. 配置文件 caddy.data_dir 指定的目录(可选);
|
||||||
|
//
|
||||||
|
// 其余默认位置由 caddycert.Fetch 自行探测。
|
||||||
|
func (h *AdminHandler) caddyCertRoots() []string {
|
||||||
|
return []string{
|
||||||
|
filepath.Join(filepath.Dir(h.tlsDir), "caddy"),
|
||||||
|
h.caddyDataDir,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func readTLSCert(path string) string {
|
func readTLSCert(path string) string {
|
||||||
if path == "" {
|
if path == "" {
|
||||||
return ""
|
return ""
|
||||||
|
|||||||
@@ -45,6 +45,7 @@ type WebServer struct {
|
|||||||
storageCfg config.StorageConfig
|
storageCfg config.StorageConfig
|
||||||
authCfg config.AuthConfig
|
authCfg config.AuthConfig
|
||||||
banCfg config.BanConfig
|
banCfg config.BanConfig
|
||||||
|
caddyDataDir string
|
||||||
outbound *outbound.Manager
|
outbound *outbound.Manager
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -84,7 +85,7 @@ func templateFuncs() template.FuncMap {
|
|||||||
|
|
||||||
// NewWebServer creates a new WebServer, initializes the Gin engine,
|
// NewWebServer creates a new WebServer, initializes the Gin engine,
|
||||||
// configures sessions, middleware, and registers all routes.
|
// configures sessions, middleware, and registers all routes.
|
||||||
func NewWebServer(cfg config.WebConfig, stores *store.Stores, attStorage *storage.AttachmentStorage, storageCfg config.StorageConfig, authCfg config.AuthConfig, banCfg config.BanConfig, ob *outbound.Manager) *WebServer {
|
func NewWebServer(cfg config.WebConfig, stores *store.Stores, attStorage *storage.AttachmentStorage, storageCfg config.StorageConfig, authCfg config.AuthConfig, banCfg config.BanConfig, caddyCfg config.CaddyConfig, ob *outbound.Manager) *WebServer {
|
||||||
gin.SetMode(gin.ReleaseMode)
|
gin.SetMode(gin.ReleaseMode)
|
||||||
engine := gin.New()
|
engine := gin.New()
|
||||||
engine.Use(gin.Logger())
|
engine.Use(gin.Logger())
|
||||||
@@ -114,6 +115,7 @@ func NewWebServer(cfg config.WebConfig, stores *store.Stores, attStorage *storag
|
|||||||
storageCfg: storageCfg,
|
storageCfg: storageCfg,
|
||||||
authCfg: authCfg,
|
authCfg: authCfg,
|
||||||
banCfg: banCfg,
|
banCfg: banCfg,
|
||||||
|
caddyDataDir: caddyCfg.DataDir,
|
||||||
outbound: ob,
|
outbound: ob,
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -125,7 +127,7 @@ func NewWebServer(cfg config.WebConfig, stores *store.Stores, attStorage *storag
|
|||||||
func (ws *WebServer) registerRoutes() {
|
func (ws *WebServer) registerRoutes() {
|
||||||
authHandler := handlers.NewAuthHandler(ws.stores, ws.authCfg, ws.banCfg)
|
authHandler := handlers.NewAuthHandler(ws.stores, ws.authCfg, ws.banCfg)
|
||||||
mailHandler := handlers.NewMailHandler(ws.stores, ws.storage, ws.outbound)
|
mailHandler := handlers.NewMailHandler(ws.stores, ws.storage, ws.outbound)
|
||||||
adminHandler := handlers.NewAdminHandler(ws.stores, ws.storage, filepath.Join(ws.storageCfg.BaseDir, "tls", "domains"), ws.outbound)
|
adminHandler := handlers.NewAdminHandler(ws.stores, ws.storage, filepath.Join(ws.storageCfg.BaseDir, "tls", "domains"), ws.caddyDataDir, ws.outbound)
|
||||||
|
|
||||||
// Apply BanMiddleware globally before public routes
|
// Apply BanMiddleware globally before public routes
|
||||||
ws.engine.Use(middleware.BanMiddleware(ws.stores))
|
ws.engine.Use(middleware.BanMiddleware(ws.stores))
|
||||||
@@ -175,6 +177,7 @@ func (ws *WebServer) registerRoutes() {
|
|||||||
admin.GET("/domains/:id/edit", adminHandler.EditDomain)
|
admin.GET("/domains/:id/edit", adminHandler.EditDomain)
|
||||||
admin.POST("/domains/:id", adminHandler.UpdateDomain)
|
admin.POST("/domains/:id", adminHandler.UpdateDomain)
|
||||||
admin.POST("/domains/:id/delete", adminHandler.DeleteDomain)
|
admin.POST("/domains/:id/delete", adminHandler.DeleteDomain)
|
||||||
|
admin.POST("/domains/:id/fetch-caddy-cert", adminHandler.FetchCaddyCert)
|
||||||
admin.GET("/domains/:id/dns", adminHandler.DNSHint)
|
admin.GET("/domains/:id/dns", adminHandler.DNSHint)
|
||||||
admin.GET("/users", adminHandler.ListUsers)
|
admin.GET("/users", adminHandler.ListUsers)
|
||||||
admin.GET("/users/new", adminHandler.NewUser)
|
admin.GET("/users/new", adminHandler.NewUser)
|
||||||
|
|||||||
@@ -24,6 +24,7 @@
|
|||||||
<div class="card">
|
<div class="card">
|
||||||
<h2 style="margin-bottom:16px;">{{if .isEdit}}编辑域名{{else}}新增域名{{end}}</h2>
|
<h2 style="margin-bottom:16px;">{{if .isEdit}}编辑域名{{else}}新增域名{{end}}</h2>
|
||||||
{{if .error}}<div class="alert alert-error">{{.error}}</div>{{end}}
|
{{if .error}}<div class="alert alert-error">{{.error}}</div>{{end}}
|
||||||
|
{{if .caddyMsg}}<div class="alert {{if eq .caddyMsgType "success"}}alert-success{{else}}alert-error{{end}}">{{.caddyMsg}}</div>{{end}}
|
||||||
<form method="POST" action="{{if .isEdit}}/admin/domains/{{.domain.ID}}{{else}}/admin/domains{{end}}">
|
<form method="POST" action="{{if .isEdit}}/admin/domains/{{.domain.ID}}{{else}}/admin/domains{{end}}">
|
||||||
<div class="form-group">
|
<div class="form-group">
|
||||||
<label>域名</label>
|
<label>域名</label>
|
||||||
@@ -63,12 +64,40 @@
|
|||||||
<label>TLS 公钥证书 PEM</label>
|
<label>TLS 公钥证书 PEM</label>
|
||||||
<textarea name="tls_public_cert" rows="8" placeholder="-----BEGIN CERTIFICATE----- ... -----END CERTIFICATE-----" style="font-family:monospace;">{{.tlsPublicCert}}</textarea>
|
<textarea name="tls_public_cert" rows="8" placeholder="-----BEGIN CERTIFICATE----- ... -----END CERTIFICATE-----" style="font-family:monospace;">{{.tlsPublicCert}}</textarea>
|
||||||
{{if .tlsCertConfigured}}
|
{{if .tlsCertConfigured}}
|
||||||
<p style="color:#27ae60;font-size:12px;margin-top:4px;">✅ TLS 证书已配置;上传新证书后需重启服务生效。</p>
|
<p style="color:#27ae60;font-size:12px;margin-top:4px;">✅ TLS 证书已配置;上传新证书后自动热加载生效。</p>
|
||||||
{{else}}
|
{{else}}
|
||||||
<p style="color:#e67e22;font-size:12px;margin-top:4px;">⚠️ TLS 证书未配置,启用 TLS 时必须同时填写私钥和证书。</p>
|
<p style="color:#e67e22;font-size:12px;margin-top:4px;">⚠️ TLS 证书未配置,启用 TLS 时必须同时填写私钥和证书。</p>
|
||||||
{{end}}
|
{{end}}
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
<div class="form-group" style="margin-top:4px;">
|
||||||
|
<label>从 Caddy 获取证书</label>
|
||||||
|
<p style="color:#7f8c8d;font-size:12px;margin-top:2px;margin-bottom:8px;">若该域名已由本机 Caddy 托管 HTTPS(自动签发证书),可一键导入其证书与私钥,并自动启用 TLS;证书热加载,无需重启服务。</p>
|
||||||
|
<button type="button" class="btn" id="btn_fetch_caddy" onclick="fetchCaddyCert()" style="background:#2e86de;color:#fff;">🔒 从 Caddy 获取证书</button>
|
||||||
|
<span id="caddy_fetch_msg" style="margin-left:10px;font-size:12px;color:#7f8c8d;"></span>
|
||||||
|
<script>
|
||||||
|
async function fetchCaddyCert() {
|
||||||
|
var btn = document.getElementById('btn_fetch_caddy');
|
||||||
|
var msg = document.getElementById('caddy_fetch_msg');
|
||||||
|
btn.disabled = true;
|
||||||
|
var oldText = btn.textContent;
|
||||||
|
btn.textContent = '获取中…';
|
||||||
|
msg.textContent = '';
|
||||||
|
try {
|
||||||
|
var resp = await fetch('/admin/domains/{{.domain.ID}}/fetch-caddy-cert', { method: 'POST' });
|
||||||
|
if (resp.redirected) {
|
||||||
|
window.location.href = resp.url;
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
msg.textContent = '获取失败: ' + await resp.text();
|
||||||
|
} catch (e) {
|
||||||
|
msg.textContent = '请求失败: ' + e;
|
||||||
|
}
|
||||||
|
btn.disabled = false;
|
||||||
|
btn.textContent = oldText;
|
||||||
|
}
|
||||||
|
</script>
|
||||||
|
</div>
|
||||||
{{end}}
|
{{end}}
|
||||||
<script>
|
<script>
|
||||||
function togglePorts() {
|
function togglePorts() {
|
||||||
|
|||||||
@@ -12,6 +12,7 @@ import (
|
|||||||
"net"
|
"net"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
|
"sync"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"mail_go/config"
|
"mail_go/config"
|
||||||
@@ -22,6 +23,7 @@ import (
|
|||||||
"mail_go/internal/smtp_server"
|
"mail_go/internal/smtp_server"
|
||||||
"mail_go/internal/storage"
|
"mail_go/internal/storage"
|
||||||
"mail_go/internal/store"
|
"mail_go/internal/store"
|
||||||
|
"mail_go/internal/tlsutil"
|
||||||
"mail_go/internal/web"
|
"mail_go/internal/web"
|
||||||
|
|
||||||
"golang.org/x/crypto/bcrypt"
|
"golang.org/x/crypto/bcrypt"
|
||||||
@@ -35,7 +37,7 @@ func applyDomainTLSConfig(stores *store.Stores, cfg *config.Config) {
|
|||||||
|
|
||||||
applied := applyTLSCertPaths(cfg, domain.TlsCertPath, domain.TlsKeyPath)
|
applied := applyTLSCertPaths(cfg, domain.TlsCertPath, domain.TlsKeyPath)
|
||||||
if applied {
|
if applied {
|
||||||
log.Printf("使用域名 %s 的 TLS 证书;更新证书后需重启服务生效", domain.Name)
|
log.Printf("使用域名 %s 的 TLS 证书;证书更新后自动热加载,无需重启服务", domain.Name)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -59,6 +61,49 @@ func applyTLSCertPaths(cfg *config.Config, certPath, keyPath string) bool {
|
|||||||
return applied
|
return applied
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// tlsSource 返回证书路径来源:协议在 toml 中显式配置的证书优先;
|
||||||
|
// 否则取第一个启用 TLS 且有证书的域名(管理后台一键导入证书后自动
|
||||||
|
// 切换,无需重启)。结果缓存 10 秒,避免每次握手都查询数据库。
|
||||||
|
func tlsSource(explicitCert, explicitKey string, stores *store.Stores) tlsutil.Source {
|
||||||
|
var (
|
||||||
|
mu sync.Mutex
|
||||||
|
lastCheck time.Time
|
||||||
|
cachedCert string
|
||||||
|
cachedKey string
|
||||||
|
)
|
||||||
|
return func() (string, string) {
|
||||||
|
mu.Lock()
|
||||||
|
defer mu.Unlock()
|
||||||
|
if time.Since(lastCheck) < 10*time.Second {
|
||||||
|
return cachedCert, cachedKey
|
||||||
|
}
|
||||||
|
lastCheck = time.Now()
|
||||||
|
if explicitCert != "" && explicitKey != "" {
|
||||||
|
cachedCert, cachedKey = explicitCert, explicitKey
|
||||||
|
} else if d, err := stores.Domains.GetFirstTLSEnabledWithCert(); err == nil {
|
||||||
|
cachedCert, cachedKey = d.TlsCertPath, d.TlsKeyPath
|
||||||
|
} else {
|
||||||
|
cachedCert, cachedKey = "", ""
|
||||||
|
}
|
||||||
|
return cachedCert, cachedKey
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// newTLSCertLoader 创建带热加载的 TLS 证书加载器(每次握手自动重载)。
|
||||||
|
// 初始路径取显式配置或启动时填充的路径;source 允许后续动态切换
|
||||||
|
// 证书来源。加载失败返回 nil,对应协议将不启用 TLS。
|
||||||
|
func newTLSCertLoader(explicitCert, explicitKey, initCert, initKey string, stores *store.Stores, proto string) *tlsutil.Loader {
|
||||||
|
if initCert == "" || initKey == "" {
|
||||||
|
initCert, initKey = explicitCert, explicitKey
|
||||||
|
}
|
||||||
|
loader, err := tlsutil.NewLoader(initCert, initKey, tlsSource(explicitCert, explicitKey, stores), log.Printf)
|
||||||
|
if err != nil {
|
||||||
|
log.Printf("%s TLS 证书初始化失败: %v(该协议将不启用 TLS)", proto, err)
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
return loader
|
||||||
|
}
|
||||||
|
|
||||||
func ensureSelfSignedTLSConfig(cfg *config.Config) {
|
func ensureSelfSignedTLSConfig(cfg *config.Config) {
|
||||||
if cfg.SMTP.TLSCert != "" && cfg.SMTP.TLSKey != "" && cfg.IMAP.TLSCert != "" && cfg.IMAP.TLSKey != "" && cfg.POP3.TLSCert != "" && cfg.POP3.TLSKey != "" {
|
if cfg.SMTP.TLSCert != "" && cfg.SMTP.TLSKey != "" && cfg.IMAP.TLSCert != "" && cfg.IMAP.TLSKey != "" && cfg.POP3.TLSCert != "" && cfg.POP3.TLSKey != "" {
|
||||||
return
|
return
|
||||||
@@ -168,9 +213,21 @@ func main() {
|
|||||||
|
|
||||||
// 5. Initialize attachment storage
|
// 5. Initialize attachment storage
|
||||||
attStorage := storage.NewAttachmentStorage(cfg.Storage.AttachDir)
|
attStorage := storage.NewAttachmentStorage(cfg.Storage.AttachDir)
|
||||||
|
|
||||||
|
// 记录 toml 中显式配置的证书路径;此后 applyDomainTLSConfig 会用
|
||||||
|
// 域名证书填充空值,需要原始值来判断“显式配置优先”。
|
||||||
|
explicitSMTPCert, explicitSMTPKey := cfg.SMTP.TLSCert, cfg.SMTP.TLSKey
|
||||||
|
explicitIMAPCert, explicitIMAPKey := cfg.IMAP.TLSCert, cfg.IMAP.TLSKey
|
||||||
|
explicitPOP3Cert, explicitPOP3Key := cfg.POP3.TLSCert, cfg.POP3.TLSKey
|
||||||
|
|
||||||
applyDomainTLSConfig(stores, cfg)
|
applyDomainTLSConfig(stores, cfg)
|
||||||
ensureSelfSignedTLSConfig(cfg)
|
ensureSelfSignedTLSConfig(cfg)
|
||||||
|
|
||||||
|
// 证书热加载器:每次 TLS 握手自动重载证书文件,证书更新后无需重启
|
||||||
|
smtpTLS := newTLSCertLoader(explicitSMTPCert, explicitSMTPKey, cfg.SMTP.TLSCert, cfg.SMTP.TLSKey, stores, "SMTP")
|
||||||
|
imapTLS := newTLSCertLoader(explicitIMAPCert, explicitIMAPKey, cfg.IMAP.TLSCert, cfg.IMAP.TLSKey, stores, "IMAP")
|
||||||
|
pop3TLS := newTLSCertLoader(explicitPOP3Cert, explicitPOP3Key, cfg.POP3.TLSCert, cfg.POP3.TLSKey, stores, "POP3")
|
||||||
|
|
||||||
// 6. Outbound delivery manager (external mail queue + worker)
|
// 6. Outbound delivery manager (external mail queue + worker)
|
||||||
outboundMgr := outbound.NewManager(cfg.Outbound, cfg.SMTP.Domain, stores)
|
outboundMgr := outbound.NewManager(cfg.Outbound, cfg.SMTP.Domain, stores)
|
||||||
if outboundMgr.Enabled() {
|
if outboundMgr.Enabled() {
|
||||||
@@ -181,7 +238,7 @@ func main() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// 7. Start SMTP server
|
// 7. Start SMTP server
|
||||||
smtpSrv := smtp_server.NewSMTPServer(cfg.SMTP, stores, attStorage, outboundMgr)
|
smtpSrv := smtp_server.NewSMTPServer(cfg.SMTP, stores, attStorage, outboundMgr, smtpTLS)
|
||||||
go func() {
|
go func() {
|
||||||
if err := smtpSrv.Start(); err != nil {
|
if err := smtpSrv.Start(); err != nil {
|
||||||
log.Printf("SMTP 服务启动失败: %v", err)
|
log.Printf("SMTP 服务启动失败: %v", err)
|
||||||
@@ -202,7 +259,7 @@ func main() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// 7. Start IMAP server
|
// 7. Start IMAP server
|
||||||
imapSrv := imap_server.NewIMAPServer(cfg.IMAP, stores)
|
imapSrv := imap_server.NewIMAPServer(cfg.IMAP, stores, imapTLS)
|
||||||
go func() {
|
go func() {
|
||||||
if err := imapSrv.Start(); err != nil {
|
if err := imapSrv.Start(); err != nil {
|
||||||
log.Printf("IMAP 服务启动失败: %v", err)
|
log.Printf("IMAP 服务启动失败: %v", err)
|
||||||
@@ -218,7 +275,7 @@ func main() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// 8. Start POP3 server
|
// 8. Start POP3 server
|
||||||
pop3Srv := pop3_server.NewPOP3Server(cfg.POP3, stores)
|
pop3Srv := pop3_server.NewPOP3Server(cfg.POP3, stores, pop3TLS)
|
||||||
go func() {
|
go func() {
|
||||||
if err := pop3Srv.Start(); err != nil {
|
if err := pop3Srv.Start(); err != nil {
|
||||||
log.Printf("POP3 服务启动失败: %v", err)
|
log.Printf("POP3 服务启动失败: %v", err)
|
||||||
@@ -234,7 +291,7 @@ func main() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// 10. Start Web server
|
// 10. Start Web server
|
||||||
webServer := web.NewWebServer(cfg.Web, stores, attStorage, cfg.Storage, cfg.Auth, cfg.Ban, outboundMgr)
|
webServer := web.NewWebServer(cfg.Web, stores, attStorage, cfg.Storage, cfg.Auth, cfg.Ban, cfg.Caddy, outboundMgr)
|
||||||
fmt.Printf("Web 服务启动在 %s\n", cfg.Web.Addr)
|
fmt.Printf("Web 服务启动在 %s\n", cfg.Web.Addr)
|
||||||
go func() {
|
go func() {
|
||||||
if err := webServer.Start(); err != nil {
|
if err := webServer.Start(); err != nil {
|
||||||
|
|||||||
Reference in New Issue
Block a user