  1. package main
  2. import (
  3. "crypto/x509"
  4. "encoding/json"
  5. "encoding/pem"
  6. "fmt"
  7. "io"
  8. "net/http"
  9. "os"
  10. "path/filepath"
  11. "strings"
  12. "time"
  13. "imuslab.com/zoraxy/mod/acme"
  14. "imuslab.com/zoraxy/mod/utils"
  15. )
  16. // Check if the default certificates is correctly setup
  17. func handleDefaultCertCheck(w http.ResponseWriter, r *http.Request) {
  18. type CheckResult struct {
  19. DefaultPubExists bool
  20. DefaultPriExists bool
  21. }
  22. pub, pri := tlsCertManager.DefaultCertExistsSep()
  23. js, _ := json.Marshal(CheckResult{
  24. pub,
  25. pri,
  26. })
  27. utils.SendJSONResponse(w, string(js))
  28. }
  29. // Return a list of domains where the certificates covers
  30. func handleListCertificate(w http.ResponseWriter, r *http.Request) {
  31. filenames, err := tlsCertManager.ListCertDomains()
  32. if err != nil {
  33. http.Error(w, err.Error(), http.StatusInternalServerError)
  34. return
  35. }
  36. showDate, _ := utils.GetPara(r, "date")
  37. if showDate == "true" {
  38. type CertInfo struct {
  39. Domain string
  40. LastModifiedDate string
  41. ExpireDate string
  42. RemainingDays int
  43. UseDNS bool
  44. }
  45. results := []*CertInfo{}
  46. for _, filename := range filenames {
  47. certFilepath := filepath.Join(tlsCertManager.CertStore, filename+".pem")
  48. //keyFilepath := filepath.Join(tlsCertManager.CertStore, filename+".key")
  49. fileInfo, err := os.Stat(certFilepath)
  50. if err != nil {
  51. utils.SendErrorResponse(w, "invalid domain certificate discovered: "+filename)
  52. return
  53. }
  54. modifiedTime := fileInfo.ModTime().Format("2006-01-02 15:04:05")
  55. certExpireTime := "Unknown"
  56. certBtyes, err := os.ReadFile(certFilepath)
  57. expiredIn := 0
  58. if err != nil {
  59. //Unable to load this file
  60. continue
  61. } else {
  62. //Cert loaded. Check its expire time
  63. block, _ := pem.Decode(certBtyes)
  64. if block != nil {
  65. cert, err := x509.ParseCertificate(block.Bytes)
  66. if err == nil {
  67. certExpireTime = cert.NotAfter.Format("2006-01-02 15:04:05")
  68. duration := cert.NotAfter.Sub(time.Now())
  69. // Convert the duration to days
  70. expiredIn = int(duration.Hours() / 24)
  71. }
  72. }
  73. }
  74. certInfoFilename := filepath.Join(tlsCertManager.CertStore, filename+".json")
  75. useDNSValidation := false //Default to false for HTTP TLS certificates
  76. certInfo, err := acme.LoadCertInfoJSON(certInfoFilename) //Note: Not all certs have info json
  77. if err == nil {
  78. useDNSValidation = certInfo.UseDNS
  79. }
  80. thisCertInfo := CertInfo{
  81. Domain: filename,
  82. LastModifiedDate: modifiedTime,
  83. ExpireDate: certExpireTime,
  84. RemainingDays: expiredIn,
  85. UseDNS: useDNSValidation,
  86. }
  87. results = append(results, &thisCertInfo)
  88. }
  89. js, _ := json.Marshal(results)
  90. w.Header().Set("Content-Type", "application/json")
  91. w.Write(js)
  92. } else {
  93. response, err := json.Marshal(filenames)
  94. if err != nil {
  95. http.Error(w, err.Error(), http.StatusInternalServerError)
  96. return
  97. }
  98. w.Header().Set("Content-Type", "application/json")
  99. w.Write(response)
  100. }
  101. }
  102. // List all certificates and map all their domains to the cert filename
  103. func handleListDomains(w http.ResponseWriter, r *http.Request) {
  104. filenames, err := os.ReadDir("./conf/certs/")
  105. if err != nil {
  106. utils.SendErrorResponse(w, err.Error())
  107. return
  108. }
  109. certnameToDomainMap := map[string]string{}
  110. for _, filename := range filenames {
  111. if filename.IsDir() {
  112. continue
  113. }
  114. certFilepath := filepath.Join("./conf/certs/", filename.Name())
  115. certBtyes, err := os.ReadFile(certFilepath)
  116. if err != nil {
  117. // Unable to load this file
  118. SystemWideLogger.PrintAndLog("TLS", "Unable to load certificate: "+certFilepath, err)
  119. continue
  120. } else {
  121. // Cert loaded. Check its expiry time
  122. block, _ := pem.Decode(certBtyes)
  123. if block != nil {
  124. cert, err := x509.ParseCertificate(block.Bytes)
  125. if err == nil {
  126. certname := strings.TrimSuffix(filepath.Base(certFilepath), filepath.Ext(certFilepath))
  127. for _, dnsName := range cert.DNSNames {
  128. certnameToDomainMap[dnsName] = certname
  129. }
  130. certnameToDomainMap[cert.Subject.CommonName] = certname
  131. }
  132. }
  133. }
  134. }
  135. requireCompact, _ := utils.GetPara(r, "compact")
  136. if requireCompact == "true" {
  137. result := make(map[string][]string)
  138. for key, value := range certnameToDomainMap {
  139. if _, ok := result[value]; !ok {
  140. result[value] = make([]string, 0)
  141. }
  142. result[value] = append(result[value], key)
  143. }
  144. js, _ := json.Marshal(result)
  145. utils.SendJSONResponse(w, string(js))
  146. return
  147. }
  148. js, _ := json.Marshal(certnameToDomainMap)
  149. utils.SendJSONResponse(w, string(js))
  150. }
  151. // Handle front-end toggling TLS mode
  152. func handleToggleTLSProxy(w http.ResponseWriter, r *http.Request) {
  153. currentTlsSetting := false
  154. if sysdb.KeyExists("settings", "usetls") {
  155. sysdb.Read("settings", "usetls", &currentTlsSetting)
  156. }
  157. newState, err := utils.PostPara(r, "set")
  158. if err != nil {
  159. //No setting. Get the current status
  160. js, _ := json.Marshal(currentTlsSetting)
  161. utils.SendJSONResponse(w, string(js))
  162. } else {
  163. if newState == "true" {
  164. sysdb.Write("settings", "usetls", true)
  165. SystemWideLogger.Println("Enabling TLS mode on reverse proxy")
  166. dynamicProxyRouter.UpdateTLSSetting(true)
  167. } else if newState == "false" {
  168. sysdb.Write("settings", "usetls", false)
  169. SystemWideLogger.Println("Disabling TLS mode on reverse proxy")
  170. dynamicProxyRouter.UpdateTLSSetting(false)
  171. } else {
  172. utils.SendErrorResponse(w, "invalid state given. Only support true or false")
  173. return
  174. }
  175. utils.SendOK(w)
  176. }
  177. }
  178. // Handle the GET and SET of reverse proxy TLS versions
  179. func handleSetTlsRequireLatest(w http.ResponseWriter, r *http.Request) {
  180. newState, err := utils.PostPara(r, "set")
  181. if err != nil {
  182. //GET
  183. var reqLatestTLS bool = false
  184. if sysdb.KeyExists("settings", "forceLatestTLS") {
  185. sysdb.Read("settings", "forceLatestTLS", &reqLatestTLS)
  186. }
  187. js, _ := json.Marshal(reqLatestTLS)
  188. utils.SendJSONResponse(w, string(js))
  189. } else {
  190. if newState == "true" {
  191. sysdb.Write("settings", "forceLatestTLS", true)
  192. SystemWideLogger.Println("Updating minimum TLS version to v1.2 or above")
  193. dynamicProxyRouter.UpdateTLSVersion(true)
  194. } else if newState == "false" {
  195. sysdb.Write("settings", "forceLatestTLS", false)
  196. SystemWideLogger.Println("Updating minimum TLS version to v1.0 or above")
  197. dynamicProxyRouter.UpdateTLSVersion(false)
  198. } else {
  199. utils.SendErrorResponse(w, "invalid state given")
  200. }
  201. }
  202. }
  203. // Handle download of the selected certificate
  204. func handleCertDownload(w http.ResponseWriter, r *http.Request) {
  205. // get the certificate name
  206. certname, err := utils.GetPara(r, "certname")
  207. if err != nil {
  208. utils.SendErrorResponse(w, "invalid certname given")
  209. return
  210. }
  211. certname = filepath.Base(certname) //prevent path escape
  212. // check if the cert exists
  213. pubKey := filepath.Join(filepath.Join("./conf/certs"), certname+".key")
  214. priKey := filepath.Join(filepath.Join("./conf/certs"), certname+".pem")
  215. if utils.FileExists(pubKey) && utils.FileExists(priKey) {
  216. //Zip them and serve them via http download
  217. seeking, _ := utils.GetBool(r, "seek")
  218. if seeking {
  219. //This request only check if the key exists. Do not provide download
  220. utils.SendOK(w)
  221. return
  222. }
  223. //Serve both file in zip
  224. zipTmpFolder := "./tmp/download"
  225. os.MkdirAll(zipTmpFolder, 0775)
  226. zipFileName := filepath.Join(zipTmpFolder, certname+".zip")
  227. err := utils.ZipFiles(zipFileName, pubKey, priKey)
  228. if err != nil {
  229. http.Error(w, "Failed to create zip file", http.StatusInternalServerError)
  230. return
  231. }
  232. defer os.Remove(zipFileName) // Clean up the zip file after serving
  233. // Serve the zip file
  234. w.Header().Set("Content-Disposition", "attachment; filename=\""+certname+"_export.zip\"")
  235. w.Header().Set("Content-Type", "application/zip")
  236. http.ServeFile(w, r, zipFileName)
  237. } else {
  238. //Not both key exists
  239. utils.SendErrorResponse(w, "invalid key-pairs: private key or public key not found in key store")
  240. return
  241. }
  242. }
  243. // Handle upload of the certificate
  244. func handleCertUpload(w http.ResponseWriter, r *http.Request) {
  245. // check if request method is POST
  246. if r.Method != "POST" {
  247. http.Error(w, "Method not allowed", http.StatusMethodNotAllowed)
  248. return
  249. }
  250. // get the key type
  251. keytype, err := utils.GetPara(r, "ktype")
  252. overWriteFilename := ""
  253. if err != nil {
  254. http.Error(w, "Not defined key type (pub / pri)", http.StatusBadRequest)
  255. return
  256. }
  257. // get the domain
  258. domain, err := utils.GetPara(r, "domain")
  259. if err != nil {
  260. //Assume localhost
  261. domain = "default"
  262. }
  263. if keytype == "pub" {
  264. overWriteFilename = domain + ".pem"
  265. } else if keytype == "pri" {
  266. overWriteFilename = domain + ".key"
  267. } else {
  268. http.Error(w, "Not supported keytype: "+keytype, http.StatusBadRequest)
  269. return
  270. }
  271. // parse multipart form data
  272. err = r.ParseMultipartForm(10 << 20) // 10 MB
  273. if err != nil {
  274. http.Error(w, "Failed to parse form data", http.StatusBadRequest)
  275. return
  276. }
  277. // get file from form data
  278. file, _, err := r.FormFile("file")
  279. if err != nil {
  280. http.Error(w, "Failed to get file", http.StatusBadRequest)
  281. return
  282. }
  283. defer file.Close()
  284. // create file in upload directory
  285. os.MkdirAll("./conf/certs", 0775)
  286. f, err := os.Create(filepath.Join("./conf/certs", overWriteFilename))
  287. if err != nil {
  288. http.Error(w, "Failed to create file", http.StatusInternalServerError)
  289. return
  290. }
  291. defer f.Close()
  292. // copy file contents to destination file
  293. _, err = io.Copy(f, file)
  294. if err != nil {
  295. http.Error(w, "Failed to save file", http.StatusInternalServerError)
  296. return
  297. }
  298. //Update cert list
  299. tlsCertManager.UpdateLoadedCertList()
  300. // send response
  301. fmt.Fprintln(w, "File upload successful!")
  302. }
  303. // Handle cert remove
  304. func handleCertRemove(w http.ResponseWriter, r *http.Request) {
  305. domain, err := utils.PostPara(r, "domain")
  306. if err != nil {
  307. utils.SendErrorResponse(w, "invalid domain given")
  308. return
  309. }
  310. err = tlsCertManager.RemoveCert(domain)
  311. if err != nil {
  312. utils.SendErrorResponse(w, err.Error())
  313. }
  314. }