cert.go 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316
  1. package main
  2. import (
  3. "crypto/x509"
  4. "encoding/json"
  5. "encoding/pem"
  6. "fmt"
  7. "io"
  8. "net/http"
  9. "os"
  10. "path/filepath"
  11. "strings"
  12. "time"
  13. "imuslab.com/zoraxy/mod/acme"
  14. "imuslab.com/zoraxy/mod/utils"
  15. )
  16. // Check if the default certificates is correctly setup
  17. func handleDefaultCertCheck(w http.ResponseWriter, r *http.Request) {
  18. type CheckResult struct {
  19. DefaultPubExists bool
  20. DefaultPriExists bool
  21. }
  22. pub, pri := tlsCertManager.DefaultCertExistsSep()
  23. js, _ := json.Marshal(CheckResult{
  24. pub,
  25. pri,
  26. })
  27. utils.SendJSONResponse(w, string(js))
  28. }
  29. // Return a list of domains where the certificates covers
  30. func handleListCertificate(w http.ResponseWriter, r *http.Request) {
  31. filenames, err := tlsCertManager.ListCertDomains()
  32. if err != nil {
  33. http.Error(w, err.Error(), http.StatusInternalServerError)
  34. return
  35. }
  36. showDate, _ := utils.GetPara(r, "date")
  37. if showDate == "true" {
  38. type CertInfo struct {
  39. Domain string
  40. LastModifiedDate string
  41. ExpireDate string
  42. RemainingDays int
  43. UseDNS bool
  44. }
  45. results := []*CertInfo{}
  46. for _, filename := range filenames {
  47. certFilepath := filepath.Join(tlsCertManager.CertStore, filename+".pem")
  48. //keyFilepath := filepath.Join(tlsCertManager.CertStore, filename+".key")
  49. fileInfo, err := os.Stat(certFilepath)
  50. if err != nil {
  51. utils.SendErrorResponse(w, "invalid domain certificate discovered: "+filename)
  52. return
  53. }
  54. modifiedTime := fileInfo.ModTime().Format("2006-01-02 15:04:05")
  55. certExpireTime := "Unknown"
  56. certBtyes, err := os.ReadFile(certFilepath)
  57. expiredIn := 0
  58. if err != nil {
  59. //Unable to load this file
  60. continue
  61. } else {
  62. //Cert loaded. Check its expire time
  63. block, _ := pem.Decode(certBtyes)
  64. if block != nil {
  65. cert, err := x509.ParseCertificate(block.Bytes)
  66. if err == nil {
  67. certExpireTime = cert.NotAfter.Format("2006-01-02 15:04:05")
  68. duration := cert.NotAfter.Sub(time.Now())
  69. // Convert the duration to days
  70. expiredIn = int(duration.Hours() / 24)
  71. }
  72. }
  73. }
  74. certInfoFilename := filepath.Join(tlsCertManager.CertStore, filename+".json")
  75. certInfo, err := acme.LoadCertInfoJSON(certInfoFilename)
  76. if err != nil {
  77. SystemWideLogger.PrintAndLog("Could not Load CertInfoJson", certInfoFilename, err)
  78. }
  79. thisCertInfo := CertInfo{
  80. Domain: filename,
  81. LastModifiedDate: modifiedTime,
  82. ExpireDate: certExpireTime,
  83. RemainingDays: expiredIn,
  84. UseDNS: certInfo.UseDNS,
  85. }
  86. results = append(results, &thisCertInfo)
  87. }
  88. js, _ := json.Marshal(results)
  89. w.Header().Set("Content-Type", "application/json")
  90. w.Write(js)
  91. } else {
  92. response, err := json.Marshal(filenames)
  93. if err != nil {
  94. http.Error(w, err.Error(), http.StatusInternalServerError)
  95. return
  96. }
  97. w.Header().Set("Content-Type", "application/json")
  98. w.Write(response)
  99. }
  100. }
  101. // List all certificates and map all their domains to the cert filename
  102. func handleListDomains(w http.ResponseWriter, r *http.Request) {
  103. filenames, err := os.ReadDir("./conf/certs/")
  104. if err != nil {
  105. utils.SendErrorResponse(w, err.Error())
  106. return
  107. }
  108. certnameToDomainMap := map[string]string{}
  109. for _, filename := range filenames {
  110. if filename.IsDir() {
  111. continue
  112. }
  113. certFilepath := filepath.Join("./conf/certs/", filename.Name())
  114. certBtyes, err := os.ReadFile(certFilepath)
  115. if err != nil {
  116. // Unable to load this file
  117. SystemWideLogger.PrintAndLog("TLS", "Unable to load certificate: "+certFilepath, err)
  118. continue
  119. } else {
  120. // Cert loaded. Check its expiry time
  121. block, _ := pem.Decode(certBtyes)
  122. if block != nil {
  123. cert, err := x509.ParseCertificate(block.Bytes)
  124. if err == nil {
  125. certname := strings.TrimSuffix(filepath.Base(certFilepath), filepath.Ext(certFilepath))
  126. for _, dnsName := range cert.DNSNames {
  127. certnameToDomainMap[dnsName] = certname
  128. }
  129. certnameToDomainMap[cert.Subject.CommonName] = certname
  130. }
  131. }
  132. }
  133. }
  134. requireCompact, _ := utils.GetPara(r, "compact")
  135. if requireCompact == "true" {
  136. result := make(map[string][]string)
  137. for key, value := range certnameToDomainMap {
  138. if _, ok := result[value]; !ok {
  139. result[value] = make([]string, 0)
  140. }
  141. result[value] = append(result[value], key)
  142. }
  143. js, _ := json.Marshal(result)
  144. utils.SendJSONResponse(w, string(js))
  145. return
  146. }
  147. js, _ := json.Marshal(certnameToDomainMap)
  148. utils.SendJSONResponse(w, string(js))
  149. }
  150. // Handle front-end toggling TLS mode
  151. func handleToggleTLSProxy(w http.ResponseWriter, r *http.Request) {
  152. currentTlsSetting := false
  153. if sysdb.KeyExists("settings", "usetls") {
  154. sysdb.Read("settings", "usetls", &currentTlsSetting)
  155. }
  156. newState, err := utils.PostPara(r, "set")
  157. if err != nil {
  158. //No setting. Get the current status
  159. js, _ := json.Marshal(currentTlsSetting)
  160. utils.SendJSONResponse(w, string(js))
  161. } else {
  162. if newState == "true" {
  163. sysdb.Write("settings", "usetls", true)
  164. SystemWideLogger.Println("Enabling TLS mode on reverse proxy")
  165. dynamicProxyRouter.UpdateTLSSetting(true)
  166. } else if newState == "false" {
  167. sysdb.Write("settings", "usetls", false)
  168. SystemWideLogger.Println("Disabling TLS mode on reverse proxy")
  169. dynamicProxyRouter.UpdateTLSSetting(false)
  170. } else {
  171. utils.SendErrorResponse(w, "invalid state given. Only support true or false")
  172. return
  173. }
  174. utils.SendOK(w)
  175. }
  176. }
  177. // Handle the GET and SET of reverse proxy TLS versions
  178. func handleSetTlsRequireLatest(w http.ResponseWriter, r *http.Request) {
  179. newState, err := utils.PostPara(r, "set")
  180. if err != nil {
  181. //GET
  182. var reqLatestTLS bool = false
  183. if sysdb.KeyExists("settings", "forceLatestTLS") {
  184. sysdb.Read("settings", "forceLatestTLS", &reqLatestTLS)
  185. }
  186. js, _ := json.Marshal(reqLatestTLS)
  187. utils.SendJSONResponse(w, string(js))
  188. } else {
  189. if newState == "true" {
  190. sysdb.Write("settings", "forceLatestTLS", true)
  191. SystemWideLogger.Println("Updating minimum TLS version to v1.2 or above")
  192. dynamicProxyRouter.UpdateTLSVersion(true)
  193. } else if newState == "false" {
  194. sysdb.Write("settings", "forceLatestTLS", false)
  195. SystemWideLogger.Println("Updating minimum TLS version to v1.0 or above")
  196. dynamicProxyRouter.UpdateTLSVersion(false)
  197. } else {
  198. utils.SendErrorResponse(w, "invalid state given")
  199. }
  200. }
  201. }
  202. // Handle upload of the certificate
  203. func handleCertUpload(w http.ResponseWriter, r *http.Request) {
  204. // check if request method is POST
  205. if r.Method != "POST" {
  206. http.Error(w, "Method not allowed", http.StatusMethodNotAllowed)
  207. return
  208. }
  209. // get the key type
  210. keytype, err := utils.GetPara(r, "ktype")
  211. overWriteFilename := ""
  212. if err != nil {
  213. http.Error(w, "Not defined key type (pub / pri)", http.StatusBadRequest)
  214. return
  215. }
  216. // get the domain
  217. domain, err := utils.GetPara(r, "domain")
  218. if err != nil {
  219. //Assume localhost
  220. domain = "default"
  221. }
  222. if keytype == "pub" {
  223. overWriteFilename = domain + ".pem"
  224. } else if keytype == "pri" {
  225. overWriteFilename = domain + ".key"
  226. } else {
  227. http.Error(w, "Not supported keytype: "+keytype, http.StatusBadRequest)
  228. return
  229. }
  230. // parse multipart form data
  231. err = r.ParseMultipartForm(10 << 20) // 10 MB
  232. if err != nil {
  233. http.Error(w, "Failed to parse form data", http.StatusBadRequest)
  234. return
  235. }
  236. // get file from form data
  237. file, _, err := r.FormFile("file")
  238. if err != nil {
  239. http.Error(w, "Failed to get file", http.StatusBadRequest)
  240. return
  241. }
  242. defer file.Close()
  243. // create file in upload directory
  244. os.MkdirAll("./conf/certs", 0775)
  245. f, err := os.Create(filepath.Join("./conf/certs", overWriteFilename))
  246. if err != nil {
  247. http.Error(w, "Failed to create file", http.StatusInternalServerError)
  248. return
  249. }
  250. defer f.Close()
  251. // copy file contents to destination file
  252. _, err = io.Copy(f, file)
  253. if err != nil {
  254. http.Error(w, "Failed to save file", http.StatusInternalServerError)
  255. return
  256. }
  257. //Update cert list
  258. tlsCertManager.UpdateLoadedCertList()
  259. // send response
  260. fmt.Fprintln(w, "File upload successful!")
  261. }
  262. // Handle cert remove
  263. func handleCertRemove(w http.ResponseWriter, r *http.Request) {
  264. domain, err := utils.PostPara(r, "domain")
  265. if err != nil {
  266. utils.SendErrorResponse(w, "invalid domain given")
  267. return
  268. }
  269. err = tlsCertManager.RemoveCert(domain)
  270. if err != nil {
  271. utils.SendErrorResponse(w, err.Error())
  272. }
  273. }