customHeaders.html 29 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642
  1. <!DOCTYPE html>
  2. <html>
  3. <head>
  4. <!-- Notes: This should be open in its original path-->
  5. <meta charset="utf-8">
  6. <meta name="zoraxy.csrf.Token" content="{{.csrfToken}}">
  7. <link rel="stylesheet" href="../script/semantic/semantic.min.css">
  8. <script src="../script/jquery-3.6.0.min.js"></script>
  9. <script src="../script/semantic/semantic.min.js"></script>
  10. <script src="../script/utils.js"></script>
  11. <style>
  12. .ui.tabular.menu .item.narrowpadding{
  13. padding: 0.6em !important;
  14. margin: 0.15em !important;
  15. }
  16. #permissionPolicyEditor.disabled{
  17. opacity: 0.4;
  18. pointer-events: none;
  19. user-select: none;
  20. }
  21. #permissionPolicyEditor .experimental{
  22. background-color: rgb(241, 241, 241);
  23. }
  24. </style>
  25. </head>
  26. <body>
  27. <br>
  28. <div class="ui container">
  29. <div class="ui header">
  30. <div class="content">
  31. Custom Headers
  32. <div class="sub header" id="epname"></div>
  33. </div>
  34. </div>
  35. <div class="ui divider"></div>
  36. <div class="ui small pointing secondary menu">
  37. <a class="item active narrowpadding" data-tab="customheaders">Custom Headers</a>
  38. <a class="item narrowpadding" data-tab="security">Security Headers</a>
  39. </div>
  40. <div class="ui tab basic segment active" data-tab="customheaders">
  41. <table class="ui very basic compacted unstackable celled table">
  42. <thead>
  43. <tr>
  44. <th>Key</th>
  45. <th>Value</th>
  46. <th>Remove</th>
  47. </tr></thead>
  48. <tbody id="headerTable">
  49. <tr>
  50. <td colspan="3"><i class="ui green circle check icon"></i> No Additonal Header</td>
  51. </tr>
  52. </tbody>
  53. </table>
  54. <p>
  55. <i class="angle double right blue icon"></i> Add or remove headers before sending to origin server <br>
  56. <i class="angle double left orange icon"></i> Modify headers from origin server responses before sending to client
  57. </p>
  58. <div class="ui divider"></div>
  59. <h4>Edit Custom Header</h4>
  60. <p>Add or remove custom header(s) over this proxy target</p>
  61. <div class="scrolling content ui form">
  62. <div class="five small fields credentialEntry">
  63. <div class="field" align="center">
  64. <button id="toOriginButton" style="margin-top: 0.6em;" title="Downstream to Upstream" class="ui circular basic active button">Zoraxy <i class="angle double right blue icon" style="margin-right: 0.4em;"></i> Origin</button>
  65. <button id="toClientButton" style="margin-top: 0.6em;" title="Upstream to Downstream" class="ui circular basic button">Client <i class="angle double left orange icon" style="margin-left: 0.4em;"></i> Zoraxy</button>
  66. </div>
  67. <div class="field" align="center">
  68. <button id="headerModeAdd" style="margin-top: 0.6em;" class="ui circular basic active button"><i class="ui green circle add icon"></i> Add Header</button>
  69. <button id="headerModeRemove" style="margin-top: 0.6em;" class="ui circular basic button"><i class="ui red circle times icon"></i> Remove Header</button>
  70. </div>
  71. <div class="field">
  72. <label>Header Key</label>
  73. <input id="headerName" type="text" placeholder="X-Custom-Header" autocomplete="off">
  74. <small>The header key is <b>NOT</b> case sensitive</small>
  75. </div>
  76. <div class="field">
  77. <label>Header Value</label>
  78. <input id="headerValue" type="text" placeholder="value1,value2,value3" autocomplete="off">
  79. </div>
  80. <div class="field" >
  81. <button class="ui basic button" onclick="addCustomHeader();"><i class="green add icon"></i> Add Header Rewrite Rule</button>
  82. </div>
  83. <div class="ui divider"></div>
  84. </div>
  85. </div>
  86. <div class="ui divider"></div>
  87. <div class="ui basic segment advanceoptions">
  88. <div class="ui fluid accordion">
  89. <div class="title">
  90. <i class="dropdown icon" tabindex="0"><div class="menu" tabindex="-1"></div></i>
  91. Advance Settings
  92. </div>
  93. <div class="content">
  94. <br>
  95. <div class="ui container">
  96. <h4>Overwrite Host Header</h4>
  97. <p>Manual override the automatic "Host" header rewrite logic. Leave empty for automatic.</p>
  98. <div class="ui fluid action input">
  99. <input type="text" id="manualHostOverwrite" placeholder="Overwrite Host name">
  100. <button onclick="updateManualHostOverwrite();" class="ui basic icon button" title="Update"><i class="ui green save icon"></i></button>
  101. <button onclick="clearManualHostOverwrite();" class="ui basic icon button" title="Clear"><i class="ui grey remove icon"></i></button>
  102. </div>
  103. <div class="ui divider"></div>
  104. <h4>Remove Hop-by-hop Headers</h4>
  105. <p>Remove headers like "Connection" and "Keep-Alive" from both upstream and downstream requests. Set to ON by default.</p>
  106. <div class="ui toggle checkbox">
  107. <input type="checkbox" id="removeHopByHop" name="">
  108. <label>Remove Hop-by-hop Header<br>
  109. <small>This should be ON by default</small></label>
  110. </div>
  111. <div class="ui yellow message">
  112. <p><i class="exclamation triangle icon"></i>Settings in this section are for advanced users. Invalid settings might cause werid, unexpected behavior.</p>
  113. </div>
  114. </div>
  115. </div>
  116. </div>
  117. </div>
  118. </div>
  119. <div class="ui tab basic segment" data-tab="security">
  120. <h4>HTTP Strict Transport Security</h4>
  121. <p>Force future attempts to access this site to only use HTTPS</p>
  122. <div class="ui toggle checkbox">
  123. <input type="checkbox" id="enableHSTS" name="enableHSTS">
  124. <label>Enable HSTS<br>
  125. <small>HSTS header will be automatically ignored if the site is accessed using HTTP</small></label>
  126. </div>
  127. <div class="ui divider"></div>
  128. <h4>Permission Policy</h4>
  129. <p>Explicitly declare what functionality can and cannot be used on this website. </p>
  130. <div class="ui toggle checkbox" style="margin-top: 0.6em;">
  131. <input type="checkbox" id="enablePP" name="enablePP">
  132. <label>Enable Permission Policy<br>
  133. <small>Enable Permission-Policy header with all allowed state.</small></label>
  134. </div>
  135. <div style="margin-top: 1em;" id="permissionPolicyEditor">
  136. <table class="ui celled unstackable very compact table">
  137. <thead>
  138. <tr><th>Feature</th>
  139. <th>Enabled</th>
  140. <th>Allow All (*)</th>
  141. <th>Self Only (self)</th>
  142. </tr></thead>
  143. <tbody id="permissionPolicyEditTable">
  144. <tr>
  145. <td colspan="4"><i class="ui loading spinner icon"></i> Generating</td>
  146. </tr>
  147. </tbody>
  148. </table>
  149. </div>
  150. <small><i class="ui yellow exclamation triangle icon"></i> Grey out fields are non-standard permission policies</small>
  151. <br><br>
  152. <button class="ui basic button" onclick="savePermissionPolicy();"><i class="green save icon"></i> Save</button>
  153. </div>
  154. <div class="field" >
  155. <button class="ui basic button" style="float: right;" onclick="closeThisWrapper();">Close</button>
  156. </div>
  157. </div>
  158. <br><br><br><br>
  159. <script>
  160. $('.menu .item').tab();
  161. $(".accordion").accordion();
  162. let permissionPolicyKeys = [];
  163. let editingEndpoint = {};
  164. if (window.location.hash.length > 1){
  165. let payloadHash = window.location.hash.substr(1);
  166. try{
  167. payloadHash = JSON.parse(decodeURIComponent(payloadHash));
  168. $("#epname").text(payloadHash.ep);
  169. editingEndpoint = payloadHash;
  170. }catch(ex){
  171. console.log("Unable to load endpoint data from hash")
  172. }
  173. }
  174. function closeThisWrapper(){
  175. parent.hideSideWrapper(true);
  176. }
  177. //Bind events to header mod mode
  178. $("#headerModeAdd").on("click", function(){
  179. $("#headerModeAdd").addClass("active");
  180. $("#headerModeRemove").removeClass("active");
  181. $("#headerValue").parent().show();
  182. });
  183. $("#headerModeRemove").on("click", function(){
  184. $("#headerModeAdd").removeClass("active");
  185. $("#headerModeRemove").addClass("active");
  186. $("#headerValue").parent().hide();
  187. $("#headerValue").val("");
  188. });
  189. //Bind events to header directions option
  190. $("#toOriginButton").on("click", function(){
  191. $("#toOriginButton").addClass("active");
  192. $("#toClientButton").removeClass("active");
  193. });
  194. $("#toClientButton").on("click", function(){
  195. $("#toOriginButton").removeClass("active");
  196. $("#toClientButton").addClass("active");
  197. });
  198. //Return "add" or "remove" depending on mode user selected
  199. function getHeaderEditMode(){
  200. if ($("#headerModeAdd").hasClass("active")){
  201. return "add";
  202. }
  203. return "remove";
  204. }
  205. //Return "toOrigin" or "toClient"
  206. function getHeaderDirection(){
  207. if ($("#toOriginButton").hasClass("active")){
  208. return "toOrigin";
  209. }
  210. return "toClient";
  211. }
  212. //$("#debug").text(JSON.stringify(editingEndpoint));
  213. function addCustomHeader(){
  214. let name = $("#headerName").val().trim();
  215. let value = $("#headerValue").val().trim();
  216. if (name == ""){
  217. $("#headerName").parent().addClass("error");
  218. return
  219. }else{
  220. $("#headerName").parent().removeClass("error");
  221. }
  222. if (getHeaderEditMode() == "add"){
  223. if (value == ""){
  224. $("#headerValue").parent().addClass("error");
  225. return
  226. }else{
  227. $("#headerValue").parent().removeClass("error");
  228. }
  229. }
  230. $.cjax({
  231. url: "/api/proxy/header/add",
  232. method: "POST",
  233. data: {
  234. "type": getHeaderEditMode(),
  235. "domain": editingEndpoint.ep,
  236. "direction":getHeaderDirection(),
  237. "name": name,
  238. "value": value
  239. },
  240. success: function(data){
  241. if (data.error != undefined){
  242. if (parent != undefined && parent.msgbox != undefined){
  243. parent.msgbox(data.error,false);
  244. }else{
  245. alert(data.error);
  246. }
  247. }else{
  248. listCustomHeaders();
  249. if (parent != undefined && parent.msgbox != undefined){
  250. parent.msgbox("Custom header added",true);
  251. }
  252. //Clear the form
  253. $("#headerName").val("");
  254. $("#headerValue").val("");
  255. }
  256. }
  257. });
  258. }
  259. function deleteCustomHeader(name){
  260. $.cjax({
  261. url: "/api/proxy/header/remove",
  262. method: "POST",
  263. data: {
  264. "domain": editingEndpoint.ep,
  265. "name": name,
  266. },
  267. success: function(data){
  268. listCustomHeaders();
  269. if (parent != undefined && parent.msgbox != undefined){
  270. parent.msgbox("Custom header removed",true);
  271. }
  272. }
  273. });
  274. }
  275. function listCustomHeaders(){
  276. $("#headerTable").html(`<tr><td colspan="3"><i class="ui loading spinner icon"></i> Loading</td></tr>`);
  277. $.ajax({
  278. url: "/api/proxy/header/list",
  279. method: "GET",
  280. data: {
  281. "type": editingEndpoint.ept,
  282. "domain": editingEndpoint.ep,
  283. },
  284. success: function(data){
  285. if (data.error != undefined){
  286. alert(data.error);
  287. }else{
  288. $("#headerTable").html("");
  289. data.forEach(header => {
  290. let editModeIcon = header.IsRemove?`<i class="ui red times circle icon"></i>`:`<i class="ui green add circle icon"></i>`;
  291. let direction = (header.Direction==0)?`<i class="angle double right blue icon"></i>`:`<i class="angle double left orange icon"></i>`;
  292. let valueField = header.Value;
  293. if (header.IsRemove){
  294. valueField = "<small style='color: grey;'>(Field Removed)</small>";
  295. }
  296. $("#headerTable").append(`
  297. <tr>
  298. <td>${direction} ${header.Key}</td>
  299. <td>${editModeIcon} ${valueField}</td>
  300. <td><button class="ui basic circular mini red icon button" onclick="deleteCustomHeader('${header.Key}');"><i class="ui trash icon"></i></button></td>
  301. </tr>
  302. `);
  303. });
  304. if (data.length == 0){
  305. $("#headerTable").html(`<tr>
  306. <td colspan="3"><i class="ui green circle check icon"></i> No Additonal Header</td>
  307. </tr>`);
  308. }
  309. }
  310. },
  311. });
  312. }
  313. listCustomHeaders();
  314. //Start HSTS state
  315. function initHSTSState(){
  316. $.get("/api/proxy/header/handleHSTS?domain=" + editingEndpoint.ep, function(data){
  317. if (data == 0){
  318. //HSTS disabled
  319. $("#enableHSTS").parent().checkbox("set unchecked");
  320. }else{
  321. //HSTS enabled
  322. $("#enableHSTS").parent().checkbox("set checked");
  323. }
  324. /* Bind events to toggles */
  325. $("#enableHSTS").on("change", function(){
  326. let HSTSEnabled = $("#enableHSTS")[0].checked;
  327. $.cjax({
  328. url: "/api/proxy/header/handleHSTS",
  329. method: "POST",
  330. data: {
  331. "domain": editingEndpoint.ep,
  332. "maxage": 31536000
  333. },
  334. success: function(data){
  335. if (data.error != undefined){
  336. parent.msgbox(data.error, false);
  337. }else{
  338. parent.msgbox(`HSTS ${HSTSEnabled?"Enabled":"Disabled"}`);
  339. }
  340. }
  341. })
  342. });
  343. });
  344. }
  345. initHSTSState();
  346. //Return true if this is an proposed permission policy feature
  347. function isExperimentalFeature(header) {
  348. // List of experimental features
  349. const experimentalFeatures = [
  350. "clipboard-read",
  351. "clipboard-write",
  352. "gamepad",
  353. "speaker-selection",
  354. "conversion-measurement",
  355. "focus-without-user-activation",
  356. "hid",
  357. "idle-detection",
  358. "interest-cohort",
  359. "serial",
  360. "sync-script",
  361. "trust-token-redemption",
  362. "unload",
  363. "window-placement",
  364. "vertical-scroll"
  365. ];
  366. header = header.replaceAll("_","-");
  367. // Check if the header is in the list of experimental features
  368. return experimentalFeatures.includes(header);
  369. }
  370. /* List permission policy header from server */
  371. function initPermissionPolicy(){
  372. $.get("/api/proxy/header/handlePermissionPolicy?domain=" + editingEndpoint.ep, function(data){
  373. if (data.error != undefined){
  374. console.log(data.error);
  375. $("#enablePP").parent().addClass('disabled');
  376. return;
  377. }
  378. //Set checkbox initial state
  379. if (data.PPEnabled){
  380. $("#enablePP").parent().checkbox("set checked");
  381. $("#permissionPolicyEditor").removeClass("disabled");
  382. }else{
  383. $("#enablePP").parent().checkbox("set unchecked");
  384. $("#permissionPolicyEditor").addClass("disabled");
  385. }
  386. //Bind toggle change events
  387. $("#enablePP").on("change", function(evt){
  388. //Set checkbox state
  389. let ppEnabled = $("#enablePP")[0].checked;
  390. if (ppEnabled){
  391. $("#permissionPolicyEditor").removeClass("disabled");
  392. }else{
  393. $("#permissionPolicyEditor").addClass("disabled");
  394. }
  395. $.cjax({
  396. url: "/api/proxy/header/handlePermissionPolicy",
  397. method: "POST",
  398. data: {
  399. enable: ppEnabled,
  400. domain: editingEndpoint.ep
  401. },
  402. success: function(data){
  403. if (data.error != undefined){
  404. parent.msgbox(data.error, false);
  405. }else{
  406. parent.msgbox(`Permission Policy ${ppEnabled?"Enabled":"Disabled"}`)
  407. }
  408. }
  409. })
  410. });
  411. //Render the table to list
  412. $("#permissionPolicyEditTable").html("");
  413. for (const [key, value] of Object.entries(data.CurrentPolicy)) {
  414. let allowall = "";
  415. let allowself = "";
  416. let enabled = "checked";
  417. if (value.length == 1 && value[0] == "*"){
  418. allowall = "checked";
  419. }else if (value.length == 1 && value[0] == "self"){
  420. allowself = "checked";
  421. }
  422. if (value.length == 0){
  423. enabled = ""
  424. allowall = "checked"; //default state
  425. }
  426. let isExperimental = isExperimentalFeature(key);
  427. $("#permissionPolicyEditTable").append(`<tr class="${isExperimental?"experimental":""}">
  428. <td>${key.replaceAll("_","-")}</td>
  429. <td>
  430. <div class="ui checkbox">
  431. <input class="enabled" type="checkbox" name="${key}" ${enabled}>
  432. <label></label>
  433. </div>
  434. </td>
  435. <td>
  436. <div class="ui radio checkbox targetinput ${!enabled?"disabled":""}">
  437. <input type="radio" value="all" name="${key}-target" ${allowall} ${!enabled?"disabled=\"\"":""}>
  438. <label></label>
  439. </div>
  440. </td>
  441. <td>
  442. <div class="ui radio checkbox targetinput ${!enabled?"disabled":""}">
  443. <input type="radio" value="self" name="${key}-target" ${allowself} ${!enabled?"disabled=\"\"":""}>
  444. <label></label>
  445. </div>
  446. </td>
  447. </tr>`);
  448. permissionPolicyKeys.push(key);
  449. }
  450. $("#permissionPolicyEditTable .enabled").on("change", function(){
  451. console.log($(this)[0].checked);
  452. let fieldGroup = $(this).parent().parent().parent();
  453. if ($(this)[0].checked){
  454. fieldGroup.find(".targetinput").removeClass("disabled");
  455. fieldGroup.find("input[type=radio]").prop('disabled', false);
  456. }else{
  457. fieldGroup.find(".targetinput").addClass("disabled");
  458. fieldGroup.find("input[type=radio]").prop('disabled', true);
  459. }
  460. })
  461. });
  462. }
  463. initPermissionPolicy();
  464. //Generate the permission policy object for sending to backend
  465. function generatePermissionPolicyObject(){
  466. function getStructuredFieldValueFromDOM(fieldKey){
  467. var policyTarget = $(`#permissionPolicyEditTable input[name="${fieldKey}-target"]:checked`).val();
  468. var isPolicyEnabled = $(`#permissionPolicyEditTable input[name="${fieldKey}"]`).is(':checked');
  469. if (!isPolicyEnabled){
  470. return [];
  471. }
  472. if (policyTarget == "all"){
  473. //Rewrite all to correct syntax
  474. policyTarget = "*";
  475. }
  476. return [policyTarget];
  477. }
  478. let newPermissionPolicyKeyValuePair = {};
  479. permissionPolicyKeys.forEach(policyKey => {
  480. newPermissionPolicyKeyValuePair[policyKey] = getStructuredFieldValueFromDOM(policyKey);
  481. });
  482. console.log(newPermissionPolicyKeyValuePair);
  483. return newPermissionPolicyKeyValuePair;
  484. }
  485. //Handle saving of permission policy
  486. function savePermissionPolicy(){
  487. let permissionPolicy = generatePermissionPolicyObject();
  488. let domain = editingEndpoint.ep;
  489. $.cjax({
  490. url: "/api/proxy/header/handlePermissionPolicy",
  491. method: "PUT",
  492. data: {
  493. "domain": domain,
  494. "pp": JSON.stringify(permissionPolicy),
  495. },
  496. success: function(data){
  497. if (data.error != undefined){
  498. parent.msgbox(data.error, false);
  499. }else{
  500. parent.msgbox("Permission Policy Updated");
  501. }
  502. }
  503. })
  504. }
  505. /* Manual HOST header overwrite */
  506. function updateManualHostOverwrite(){
  507. updateManualHostOverwriteVal(function(data){
  508. if (data.error != undefined){
  509. parent.msgbox(data.error, false);
  510. }else{
  511. parent.msgbox("Host field Overwrite Updated");
  512. initManualHostOverwriteValue();
  513. }
  514. });
  515. }
  516. function clearManualHostOverwrite(){
  517. $('#manualHostOverwrite').val('');
  518. updateManualHostOverwriteVal(function(data){
  519. if (data.error != undefined){
  520. parent.msgbox(data.error, false);
  521. }else{
  522. parent.msgbox("Host field Overwrite Cleared");
  523. initManualHostOverwriteValue();
  524. }
  525. })
  526. }
  527. function updateManualHostOverwriteVal(callback=undefined){
  528. let newHostname = $("#manualHostOverwrite").val().trim();
  529. $.cjax({
  530. url: "/api/proxy/header/handleHostOverwrite",
  531. method: "POST",
  532. data: {
  533. "domain": editingEndpoint.ep,
  534. "hostname": newHostname,
  535. },
  536. success: function(data){
  537. callback(data);
  538. }
  539. })
  540. }
  541. function initManualHostOverwriteValue(){
  542. $.get("/api/proxy/header/handleHostOverwrite?domain=" + editingEndpoint.ep, function(data){
  543. if (data.error != undefined){
  544. parent.msgbox(data.error, false);
  545. }else{
  546. $("#manualHostOverwrite").val(data);
  547. }
  548. });
  549. }
  550. initManualHostOverwriteValue();
  551. /* Hop-by-hop headers */
  552. function initHopByHopRemoverState(){
  553. $.get("/api/proxy/header/handleHopByHop?domain=" + editingEndpoint.ep, function(data){
  554. if (data.error != undefined){
  555. parent.msgbox(data.error);
  556. }else{
  557. if (data == true){
  558. $("#removeHopByHop").parent().checkbox("set checked");
  559. }else{
  560. $("#removeHopByHop").parent().checkbox("set unchecked");
  561. }
  562. //Bind event to the checkbox
  563. $("#removeHopByHop").on("change", function(evt){
  564. let isChecked = $(this)[0].checked;
  565. $.cjax({
  566. url: "/api/proxy/header/handleHopByHop",
  567. method: "POST",
  568. data: {
  569. "domain": editingEndpoint.ep,
  570. "removeHopByHop": isChecked,
  571. },
  572. success: function(data){
  573. if (data.error != undefined){
  574. parent.msgbox(data.error, false);
  575. }else{
  576. parent.msgbox("Hop-by-Hop header rule updated");
  577. }
  578. }
  579. })
  580. })
  581. }
  582. })
  583. }
  584. initHopByHopRemoverState();
  585. </script>
  586. </body>
  587. </html>