UNPKG

@stacksjs/rpx

Version:

A modern and smart reverse proxy.

88 lines (87 loc) 3.99 kB
import { config } from './config'; import { MACOS_CA_TRUST_FLAGS, MACOS_SYSTEM_KEYCHAIN, getMacosLoginKeychainPath, isRootCaFingerprintInKeychains, isRootCaTrustedForSsl, pruneStaleRootCas, trustRootCaForBrowsers } from './macos-trust'; import { readCertCommonName, readCertSha256Fingerprint } from './cert-inspect'; import type { ProxyConfigs, ProxyOption, ProxyOptions, SSLConfig, TlsConfig } from './types'; /** * Bun needs one `tls[]` entry per SNI name even when a single PEM covers every SAN. * Without this, :443 serves the default cert (wrong CN → ERR_CERT_COMMON_NAME_INVALID). */ export declare function devSslToSniEntries(hosts: string[], ssl: SSLConfig): Array<{ serverName: string, cert: string, key: string }>; /** ProxyOptions for the shared multi-app dev certificate (all registry hosts as SANs). */ export declare function buildRegistryTlsProxyOptions(registryHosts: string[], primary: string, verbose?: boolean): ProxyOptions; /** * Returns the canonical Root CA cert + key paths inside `basePath`. */ export declare function getRootCAPaths(basePath: string): RootCAPaths; /** Paths for the shared multi-host daemon cert under `~/.stacks/ssl`. */ export declare function getSharedDaemonCertPaths(sslDir: string): { certPath: string keyPath: string caCertPath: string rootCA: RootCAPaths }; /** * Resolves SSL paths based on configuration */ export declare function resolveSSLPaths(options: ProxyConfigs, defaultConfig: typeof config): TlsConfig; // Generate wildcard patterns for a domain export declare function generateWildcardPatterns(domain: string): string[]; /** * Generates SSL file paths based on domain */ export declare function generateSSLPaths(options?: ProxyOptions): { caCertPath: string certPath: string keyPath: string }; export declare function getAllDomains(options: ProxyOption | ProxyOptions): Set<string>; /** * Load SSL certificates from files or use provided strings */ export declare function loadSSLConfig(options: ProxyOption): Promise<SSLConfig | null>; /** * Force trust a certificate - exposing for direct use */ export declare function forceTrustCertificate(certPath: string, options?: { serverName?: string, verbose?: boolean }): Promise<boolean>; export declare function generateCertificate(options: ProxyOptions): Promise<void>; export declare function getSSLConfig(): { key: string, cert: string, ca?: string } | null; /** Clear in-process TLS cache so the next generate/load picks up new files on disk. */ export declare function clearSslConfigCache(): void; // needs to accept the options export declare function checkExistingCertificates(options?: ProxyOptions): Promise<SSLConfig | null>; export declare function httpsConfig(options: ProxyOption | ProxyOptions, verbose?: boolean): TlsConfig; /** * Clean up SSL certificates for a specific domain */ export declare function cleanupCertificates(domain: string, verbose?: boolean): Promise<void>; /** * Checks if a certificate is trusted by the system (macOS only for now) * If options.regenerateUntrustedCerts is false, always returns true (skips trust check) */ export declare function isCertTrusted(certPath: string, options?: { verbose?: boolean, regenerateUntrustedCerts?: boolean, serverName?: string }): Promise<boolean>; /** Shared dev host cert path used by the rpx daemon and `./buddy dev`. */ export declare const SHARED_DEV_HOST_CERT_PATH: string; export declare interface RootCAPaths { caCertPath: string caKeyPath: string } export { MACOS_CA_TRUST_FLAGS, MACOS_SYSTEM_KEYCHAIN, RPX_ROOT_CA_COMMON_NAME, getMacosLoginKeychainPath, getMacosTrustKeychains, isRootCaFingerprintInKeychains, isRootCaTrustedForSsl, listCertSha256HashesByCommonName, pruneStaleRootCas, trustRootCaForBrowsers, } from './macos-trust'; export { certIncludesSanHostnames, normalizeSha256Fingerprint, parseSha256HashesFromSecurityListing, readCertCommonName, readCertSha256Fingerprint, verifyHttpsChain, } from './cert-inspect';