UNPKG

@push.rocks/smartproxy

Version:

A powerful proxy package with unified route-based configuration for high traffic management. Features include SSL/TLS support, flexible routing patterns, WebSocket handling, advanced security options, and automatic ACME certificate management.

276 lines 22.1 kB
import * as plugins from '../../plugins.js'; import { ForwardingHandler } from './base-handler.js'; import { ForwardingHandlerEvents } from '../config/forwarding-types.js'; import { setupSocketHandlers, createSocketWithErrorHandler, setupBidirectionalForwarding } from '../../core/utils/socket-utils.js'; /** * Handler for HTTPS termination with HTTP backend */ export class HttpsTerminateToHttpHandler extends ForwardingHandler { /** * Create a new HTTPS termination with HTTP backend handler * @param config The forwarding configuration */ constructor(config) { super(config); this.tlsServer = null; this.secureContext = null; // Validate that this is an HTTPS terminate to HTTP configuration if (config.type !== 'https-terminate-to-http') { throw new Error(`Invalid configuration type for HttpsTerminateToHttpHandler: ${config.type}`); } } /** * Initialize the handler, setting up TLS context */ async initialize() { // We need to load or create TLS certificates if (this.config.https?.customCert) { // Use custom certificate from configuration this.secureContext = plugins.tls.createSecureContext({ key: this.config.https.customCert.key, cert: this.config.https.customCert.cert }); this.emit(ForwardingHandlerEvents.CERTIFICATE_LOADED, { source: 'config', domain: this.config.target.host }); } else if (this.config.acme?.enabled) { // Request certificate through ACME if needed this.emit(ForwardingHandlerEvents.CERTIFICATE_NEEDED, { domain: Array.isArray(this.config.target.host) ? this.config.target.host[0] : this.config.target.host, useProduction: this.config.acme.production || false }); // In a real implementation, we would wait for the certificate to be issued // For now, we'll use a dummy context this.secureContext = plugins.tls.createSecureContext({ key: '-----BEGIN PRIVATE KEY-----\nDummy key\n-----END PRIVATE KEY-----', cert: '-----BEGIN CERTIFICATE-----\nDummy cert\n-----END CERTIFICATE-----' }); } else { throw new Error('HTTPS termination requires either a custom certificate or ACME enabled'); } } /** * Set the secure context for TLS termination * Called when a certificate is available * @param context The secure context */ setSecureContext(context) { this.secureContext = context; } /** * Handle a TLS/SSL socket connection by terminating TLS and forwarding to HTTP backend * @param clientSocket The incoming socket from the client */ handleConnection(clientSocket) { // Make sure we have a secure context if (!this.secureContext) { clientSocket.destroy(new Error('TLS secure context not initialized')); return; } const remoteAddress = clientSocket.remoteAddress || 'unknown'; const remotePort = clientSocket.remotePort || 0; // Create a TLS socket using our secure context const tlsSocket = new plugins.tls.TLSSocket(clientSocket, { secureContext: this.secureContext, isServer: true, server: this.tlsServer || undefined }); this.emit(ForwardingHandlerEvents.CONNECTED, { remoteAddress, remotePort, tls: true }); // Variables to track connections let backendSocket = null; let dataBuffer = Buffer.alloc(0); let connectionEstablished = false; let forwardingSetup = false; // Set up initial error handling for TLS socket const tlsCleanupHandler = (reason) => { if (!forwardingSetup) { // If forwarding not set up yet, emit disconnected and cleanup this.emit(ForwardingHandlerEvents.DISCONNECTED, { remoteAddress, reason }); dataBuffer = Buffer.alloc(0); connectionEstablished = false; if (!tlsSocket.destroyed) { tlsSocket.destroy(); } if (backendSocket && !backendSocket.destroyed) { backendSocket.destroy(); } } // If forwarding is setup, setupBidirectionalForwarding will handle cleanup }; setupSocketHandlers(tlsSocket, tlsCleanupHandler, undefined, 'tls'); // Set timeout const timeout = this.getTimeout(); tlsSocket.setTimeout(timeout); tlsSocket.on('timeout', () => { this.emit(ForwardingHandlerEvents.ERROR, { remoteAddress, error: 'TLS connection timeout' }); tlsCleanupHandler('timeout'); }); // Handle TLS data tlsSocket.on('data', (data) => { // If backend connection already established, just forward the data if (connectionEstablished && backendSocket && !backendSocket.destroyed) { backendSocket.write(data); return; } // Append to buffer dataBuffer = Buffer.concat([dataBuffer, data]); // Very basic HTTP parsing - in a real implementation, use http-parser if (dataBuffer.includes(Buffer.from('\r\n\r\n')) && !connectionEstablished) { const target = this.getTargetFromConfig(); // Create backend connection with immediate error handling backendSocket = createSocketWithErrorHandler({ port: target.port, host: target.host, onError: (error) => { this.emit(ForwardingHandlerEvents.ERROR, { error: error.message, code: error.code || 'UNKNOWN', remoteAddress, target: `${target.host}:${target.port}` }); // Clean up the TLS socket since we can't forward if (!tlsSocket.destroyed) { tlsSocket.destroy(); } this.emit(ForwardingHandlerEvents.DISCONNECTED, { remoteAddress, reason: `backend_connection_failed: ${error.message}` }); }, onConnect: () => { connectionEstablished = true; // Send buffered data if (dataBuffer.length > 0) { backendSocket.write(dataBuffer); dataBuffer = Buffer.alloc(0); } // Now set up bidirectional forwarding with proper cleanup forwardingSetup = true; setupBidirectionalForwarding(tlsSocket, backendSocket, { onCleanup: (reason) => { this.emit(ForwardingHandlerEvents.DISCONNECTED, { remoteAddress, reason }); dataBuffer = Buffer.alloc(0); connectionEstablished = false; forwardingSetup = false; }, enableHalfOpen: false // Close both when one closes }); } }); // Additional error logging for backend socket backendSocket.on('error', (error) => { if (!connectionEstablished) { // Connection failed during setup this.emit(ForwardingHandlerEvents.ERROR, { remoteAddress, error: `Target connection error: ${error.message}` }); } // If connected, setupBidirectionalForwarding handles cleanup }); } }); } /** * Handle an HTTP request by forwarding to the HTTP backend * @param req The HTTP request * @param res The HTTP response */ handleHttpRequest(req, res) { // Check if we should redirect to HTTPS if (this.config.http?.redirectToHttps) { this.redirectToHttps(req, res); return; } // Get the target from configuration const target = this.getTargetFromConfig(); // Create custom headers with variable substitution const variables = { clientIp: req.socket.remoteAddress || 'unknown' }; // Prepare headers, merging with any custom headers from config const headers = this.applyCustomHeaders(req.headers, variables); // Create the proxy request options const options = { hostname: target.host, port: target.port, path: req.url, method: req.method, headers }; // Create the proxy request const proxyReq = plugins.http.request(options, (proxyRes) => { // Copy status code and headers from the proxied response res.writeHead(proxyRes.statusCode || 500, proxyRes.headers); // Pipe the proxy response to the client response proxyRes.pipe(res); // Track response size for logging let responseSize = 0; proxyRes.on('data', (chunk) => { responseSize += chunk.length; }); proxyRes.on('end', () => { this.emit(ForwardingHandlerEvents.HTTP_RESPONSE, { statusCode: proxyRes.statusCode, headers: proxyRes.headers, size: responseSize }); }); }); // Handle errors in the proxy request proxyReq.on('error', (error) => { this.emit(ForwardingHandlerEvents.ERROR, { remoteAddress: req.socket.remoteAddress, error: `Proxy request error: ${error.message}` }); // Send an error response if headers haven't been sent yet if (!res.headersSent) { res.writeHead(502, { 'Content-Type': 'text/plain' }); res.end(`Error forwarding request: ${error.message}`); } else { // Just end the response if headers have already been sent res.end(); } }); // Track request details for logging let requestSize = 0; req.on('data', (chunk) => { requestSize += chunk.length; }); // Log the request this.emit(ForwardingHandlerEvents.HTTP_REQUEST, { method: req.method, url: req.url, headers: req.headers, remoteAddress: req.socket.remoteAddress, target: `${target.host}:${target.port}` }); // Pipe the client request to the proxy request if (req.readable) { req.pipe(proxyReq); } else { proxyReq.end(); } } } //# sourceMappingURL=data:application/json;base64,