customHeaders.html 29 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640
  1. <!DOCTYPE html>
  2. <html>
  3. <head>
  4. <!-- Notes: This should be open in its original path-->
  5. <meta charset="utf-8">
  6. <link rel="stylesheet" href="../script/semantic/semantic.min.css">
  7. <script src="../script/jquery-3.6.0.min.js"></script>
  8. <script src="../script/semantic/semantic.min.js"></script>
  9. <style>
  10. .ui.tabular.menu .item.narrowpadding{
  11. padding: 0.6em !important;
  12. margin: 0.15em !important;
  13. }
  14. #permissionPolicyEditor.disabled{
  15. opacity: 0.4;
  16. pointer-events: none;
  17. user-select: none;
  18. }
  19. #permissionPolicyEditor .experimental{
  20. background-color: rgb(241, 241, 241);
  21. }
  22. </style>
  23. </head>
  24. <body>
  25. <br>
  26. <div class="ui container">
  27. <div class="ui header">
  28. <div class="content">
  29. Custom Headers
  30. <div class="sub header" id="epname"></div>
  31. </div>
  32. </div>
  33. <div class="ui divider"></div>
  34. <div class="ui small pointing secondary menu">
  35. <a class="item active narrowpadding" data-tab="customheaders">Custom Headers</a>
  36. <a class="item narrowpadding" data-tab="security">Security Headers</a>
  37. </div>
  38. <div class="ui tab basic segment active" data-tab="customheaders">
  39. <table class="ui very basic compacted unstackable celled table">
  40. <thead>
  41. <tr>
  42. <th>Key</th>
  43. <th>Value</th>
  44. <th>Remove</th>
  45. </tr></thead>
  46. <tbody id="headerTable">
  47. <tr>
  48. <td colspan="3"><i class="ui green circle check icon"></i> No Additonal Header</td>
  49. </tr>
  50. </tbody>
  51. </table>
  52. <p>
  53. <i class="angle double right blue icon"></i> Add or remove headers before sending to origin server <br>
  54. <i class="angle double left orange icon"></i> Modify headers from origin server responses before sending to client
  55. </p>
  56. <div class="ui divider"></div>
  57. <h4>Edit Custom Header</h4>
  58. <p>Add or remove custom header(s) over this proxy target</p>
  59. <div class="scrolling content ui form">
  60. <div class="five small fields credentialEntry">
  61. <div class="field" align="center">
  62. <button id="toOriginButton" style="margin-top: 0.6em;" title="Downstream to Upstream" class="ui circular basic active button">Zoraxy <i class="angle double right blue icon" style="margin-right: 0.4em;"></i> Origin</button>
  63. <button id="toClientButton" style="margin-top: 0.6em;" title="Upstream to Downstream" class="ui circular basic button">Client <i class="angle double left orange icon" style="margin-left: 0.4em;"></i> Zoraxy</button>
  64. </div>
  65. <div class="field" align="center">
  66. <button id="headerModeAdd" style="margin-top: 0.6em;" class="ui circular basic active button"><i class="ui green circle add icon"></i> Add Header</button>
  67. <button id="headerModeRemove" style="margin-top: 0.6em;" class="ui circular basic button"><i class="ui red circle times icon"></i> Remove Header</button>
  68. </div>
  69. <div class="field">
  70. <label>Header Key</label>
  71. <input id="headerName" type="text" placeholder="X-Custom-Header" autocomplete="off">
  72. <small>The header key is <b>NOT</b> case sensitive</small>
  73. </div>
  74. <div class="field">
  75. <label>Header Value</label>
  76. <input id="headerValue" type="text" placeholder="value1,value2,value3" autocomplete="off">
  77. </div>
  78. <div class="field" >
  79. <button class="ui basic button" onclick="addCustomHeader();"><i class="green add icon"></i> Add Header Rewrite Rule</button>
  80. </div>
  81. <div class="ui divider"></div>
  82. </div>
  83. </div>
  84. <div class="ui divider"></div>
  85. <div class="ui basic segment" style="background-color: #f7f7f7; border-radius: 1em;">
  86. <div class="ui fluid accordion">
  87. <div class="title">
  88. <i class="dropdown icon" tabindex="0"><div class="menu" tabindex="-1"></div></i>
  89. Advance Settings
  90. </div>
  91. <div class="content">
  92. <br>
  93. <div class="ui yellow message">
  94. <p><i class="exclamation triangle icon"></i>Settings in this section are for advanced users. Invalid settings might cause werid, unexpected behavior.</p>
  95. </div>
  96. <div class="ui container">
  97. <h4>Overwrite Host Header</h4>
  98. <p>Manual override the automatic "Host" header rewrite logic. Leave empty for automatic.</p>
  99. <div class="ui fluid action input">
  100. <input type="text" id="manualHostOverwrite" placeholder="Overwrite Host name">
  101. <button onclick="updateManualHostOverwrite();" class="ui basic icon button" title="Update"><i class="ui green save icon"></i></button>
  102. <button onclick="clearManualHostOverwrite();" class="ui basic icon button" title="Clear"><i class="ui grey remove icon"></i></button>
  103. </div>
  104. <div class="ui divider"></div>
  105. <h4>Remove Hop-by-hop Headers</h4>
  106. <p>Remove headers like "Connection" and "Keep-Alive" from both upstream and downstream requests. Set to ON by default.</p>
  107. <div class="ui toggle checkbox">
  108. <input type="checkbox" id="removeHopByHop" name="">
  109. <label>Remove Hop-by-hop Header<br>
  110. <small>This should be ON by default</small></label>
  111. </div>
  112. <div class="ui divider"></div>
  113. </div>
  114. </div>
  115. </div>
  116. </div>
  117. </div>
  118. <div class="ui tab basic segment" data-tab="security">
  119. <h4>HTTP Strict Transport Security</h4>
  120. <p>Force future attempts to access this site to only use HTTPS</p>
  121. <div class="ui toggle checkbox">
  122. <input type="checkbox" id="enableHSTS" name="enableHSTS">
  123. <label>Enable HSTS<br>
  124. <small>HSTS header will be automatically ignored if the site is accessed using HTTP</small></label>
  125. </div>
  126. <div class="ui divider"></div>
  127. <h4>Permission Policy</h4>
  128. <p>Explicitly declare what functionality can and cannot be used on this website. </p>
  129. <div class="ui toggle checkbox" style="margin-top: 0.6em;">
  130. <input type="checkbox" id="enablePP" name="enablePP">
  131. <label>Enable Permission Policy<br>
  132. <small>Enable Permission-Policy header with all allowed state.</small></label>
  133. </div>
  134. <div style="margin-top: 1em;" id="permissionPolicyEditor">
  135. <table class="ui celled unstackable very compact table">
  136. <thead>
  137. <tr><th>Feature</th>
  138. <th>Enabled</th>
  139. <th>Allow All (*)</th>
  140. <th>Self Only (self)</th>
  141. </tr></thead>
  142. <tbody id="permissionPolicyEditTable">
  143. <tr>
  144. <td colspan="4"><i class="ui loading spinner icon"></i> Generating</td>
  145. </tr>
  146. </tbody>
  147. </table>
  148. </div>
  149. <small><i class="ui yellow exclamation triangle icon"></i> Grey out fields are non-standard permission policies</small>
  150. <br><br>
  151. <button class="ui basic button" onclick="savePermissionPolicy();"><i class="green save icon"></i> Save</button>
  152. </div>
  153. <div class="field" >
  154. <button class="ui basic button" style="float: right;" onclick="closeThisWrapper();">Close</button>
  155. </div>
  156. </div>
  157. <br><br><br><br>
  158. <script>
  159. $('.menu .item').tab();
  160. $(".accordion").accordion();
  161. let permissionPolicyKeys = [];
  162. let editingEndpoint = {};
  163. if (window.location.hash.length > 1){
  164. let payloadHash = window.location.hash.substr(1);
  165. try{
  166. payloadHash = JSON.parse(decodeURIComponent(payloadHash));
  167. $("#epname").text(payloadHash.ep);
  168. editingEndpoint = payloadHash;
  169. }catch(ex){
  170. console.log("Unable to load endpoint data from hash")
  171. }
  172. }
  173. function closeThisWrapper(){
  174. parent.hideSideWrapper(true);
  175. }
  176. //Bind events to header mod mode
  177. $("#headerModeAdd").on("click", function(){
  178. $("#headerModeAdd").addClass("active");
  179. $("#headerModeRemove").removeClass("active");
  180. $("#headerValue").parent().show();
  181. });
  182. $("#headerModeRemove").on("click", function(){
  183. $("#headerModeAdd").removeClass("active");
  184. $("#headerModeRemove").addClass("active");
  185. $("#headerValue").parent().hide();
  186. $("#headerValue").val("");
  187. });
  188. //Bind events to header directions option
  189. $("#toOriginButton").on("click", function(){
  190. $("#toOriginButton").addClass("active");
  191. $("#toClientButton").removeClass("active");
  192. });
  193. $("#toClientButton").on("click", function(){
  194. $("#toOriginButton").removeClass("active");
  195. $("#toClientButton").addClass("active");
  196. });
  197. //Return "add" or "remove" depending on mode user selected
  198. function getHeaderEditMode(){
  199. if ($("#headerModeAdd").hasClass("active")){
  200. return "add";
  201. }
  202. return "remove";
  203. }
  204. //Return "toOrigin" or "toClient"
  205. function getHeaderDirection(){
  206. if ($("#toOriginButton").hasClass("active")){
  207. return "toOrigin";
  208. }
  209. return "toClient";
  210. }
  211. //$("#debug").text(JSON.stringify(editingEndpoint));
  212. function addCustomHeader(){
  213. let name = $("#headerName").val().trim();
  214. let value = $("#headerValue").val().trim();
  215. if (name == ""){
  216. $("#headerName").parent().addClass("error");
  217. return
  218. }else{
  219. $("#headerName").parent().removeClass("error");
  220. }
  221. if (getHeaderEditMode() == "add"){
  222. if (value == ""){
  223. $("#headerValue").parent().addClass("error");
  224. return
  225. }else{
  226. $("#headerValue").parent().removeClass("error");
  227. }
  228. }
  229. $.ajax({
  230. url: "/api/proxy/header/add",
  231. data: {
  232. "type": getHeaderEditMode(),
  233. "domain": editingEndpoint.ep,
  234. "direction":getHeaderDirection(),
  235. "name": name,
  236. "value": value
  237. },
  238. success: function(data){
  239. if (data.error != undefined){
  240. if (parent != undefined && parent.msgbox != undefined){
  241. parent.msgbox(data.error,false);
  242. }else{
  243. alert(data.error);
  244. }
  245. }else{
  246. listCustomHeaders();
  247. if (parent != undefined && parent.msgbox != undefined){
  248. parent.msgbox("Custom header added",true);
  249. }
  250. //Clear the form
  251. $("#headerName").val("");
  252. $("#headerValue").val("");
  253. }
  254. }
  255. });
  256. }
  257. function deleteCustomHeader(name){
  258. $.ajax({
  259. url: "/api/proxy/header/remove",
  260. data: {
  261. //"type": editingEndpoint.ept,
  262. "domain": editingEndpoint.ep,
  263. "name": name,
  264. },
  265. success: function(data){
  266. listCustomHeaders();
  267. if (parent != undefined && parent.msgbox != undefined){
  268. parent.msgbox("Custom header removed",true);
  269. }
  270. }
  271. });
  272. }
  273. function listCustomHeaders(){
  274. $("#headerTable").html(`<tr><td colspan="3"><i class="ui loading spinner icon"></i> Loading</td></tr>`);
  275. $.ajax({
  276. url: "/api/proxy/header/list",
  277. data: {
  278. "type": editingEndpoint.ept,
  279. "domain": editingEndpoint.ep,
  280. },
  281. success: function(data){
  282. if (data.error != undefined){
  283. alert(data.error);
  284. }else{
  285. $("#headerTable").html("");
  286. data.forEach(header => {
  287. let editModeIcon = header.IsRemove?`<i class="ui red times circle icon"></i>`:`<i class="ui green add circle icon"></i>`;
  288. let direction = (header.Direction==0)?`<i class="angle double right blue icon"></i>`:`<i class="angle double left orange icon"></i>`;
  289. let valueField = header.Value;
  290. if (header.IsRemove){
  291. valueField = "<small style='color: grey;'>(Field Removed)</small>";
  292. }
  293. $("#headerTable").append(`
  294. <tr>
  295. <td>${direction} ${header.Key}</td>
  296. <td>${editModeIcon} ${valueField}</td>
  297. <td><button class="ui basic circular mini red icon button" onclick="deleteCustomHeader('${header.Key}');"><i class="ui trash icon"></i></button></td>
  298. </tr>
  299. `);
  300. });
  301. if (data.length == 0){
  302. $("#headerTable").html(`<tr>
  303. <td colspan="3"><i class="ui green circle check icon"></i> No Additonal Header</td>
  304. </tr>`);
  305. }
  306. }
  307. },
  308. });
  309. }
  310. listCustomHeaders();
  311. //Start HSTS state
  312. function initHSTSState(){
  313. $.get("/api/proxy/header/handleHSTS?domain=" + editingEndpoint.ep, function(data){
  314. if (data == 0){
  315. //HSTS disabled
  316. $("#enableHSTS").parent().checkbox("set unchecked");
  317. }else{
  318. //HSTS enabled
  319. $("#enableHSTS").parent().checkbox("set checked");
  320. }
  321. /* Bind events to toggles */
  322. $("#enableHSTS").on("change", function(){
  323. let HSTSEnabled = $("#enableHSTS")[0].checked;
  324. $.ajax({
  325. url: "/api/proxy/header/handleHSTS",
  326. method: "POST",
  327. data: {
  328. "domain": editingEndpoint.ep,
  329. "maxage": 31536000
  330. },
  331. success: function(data){
  332. if (data.error != undefined){
  333. parent.msgbox(data.error, false);
  334. }else{
  335. parent.msgbox(`HSTS ${HSTSEnabled?"Enabled":"Disabled"}`);
  336. }
  337. }
  338. })
  339. });
  340. });
  341. }
  342. initHSTSState();
  343. //Return true if this is an proposed permission policy feature
  344. function isExperimentalFeature(header) {
  345. // List of experimental features
  346. const experimentalFeatures = [
  347. "clipboard-read",
  348. "clipboard-write",
  349. "gamepad",
  350. "speaker-selection",
  351. "conversion-measurement",
  352. "focus-without-user-activation",
  353. "hid",
  354. "idle-detection",
  355. "interest-cohort",
  356. "serial",
  357. "sync-script",
  358. "trust-token-redemption",
  359. "unload",
  360. "window-placement",
  361. "vertical-scroll"
  362. ];
  363. header = header.replaceAll("_","-");
  364. // Check if the header is in the list of experimental features
  365. return experimentalFeatures.includes(header);
  366. }
  367. /* List permission policy header from server */
  368. function initPermissionPolicy(){
  369. $.get("/api/proxy/header/handlePermissionPolicy?domain=" + editingEndpoint.ep, function(data){
  370. if (data.error != undefined){
  371. console.log(data.error);
  372. $("#enablePP").parent().addClass('disabled');
  373. return;
  374. }
  375. //Set checkbox initial state
  376. if (data.PPEnabled){
  377. $("#enablePP").parent().checkbox("set checked");
  378. $("#permissionPolicyEditor").removeClass("disabled");
  379. }else{
  380. $("#enablePP").parent().checkbox("set unchecked");
  381. $("#permissionPolicyEditor").addClass("disabled");
  382. }
  383. //Bind toggle change events
  384. $("#enablePP").on("change", function(evt){
  385. //Set checkbox state
  386. let ppEnabled = $("#enablePP")[0].checked;
  387. if (ppEnabled){
  388. $("#permissionPolicyEditor").removeClass("disabled");
  389. }else{
  390. $("#permissionPolicyEditor").addClass("disabled");
  391. }
  392. $.ajax({
  393. url: "/api/proxy/header/handlePermissionPolicy",
  394. method: "POST",
  395. data: {
  396. enable: ppEnabled,
  397. domain: editingEndpoint.ep
  398. },
  399. success: function(data){
  400. if (data.error != undefined){
  401. parent.msgbox(data.error, false);
  402. }else{
  403. parent.msgbox(`Permission Policy ${ppEnabled?"Enabled":"Disabled"}`)
  404. }
  405. }
  406. })
  407. });
  408. //Render the table to list
  409. $("#permissionPolicyEditTable").html("");
  410. for (const [key, value] of Object.entries(data.CurrentPolicy)) {
  411. let allowall = "";
  412. let allowself = "";
  413. let enabled = "checked";
  414. if (value.length == 1 && value[0] == "*"){
  415. allowall = "checked";
  416. }else if (value.length == 1 && value[0] == "self"){
  417. allowself = "checked";
  418. }
  419. if (value.length == 0){
  420. enabled = ""
  421. allowall = "checked"; //default state
  422. }
  423. let isExperimental = isExperimentalFeature(key);
  424. $("#permissionPolicyEditTable").append(`<tr class="${isExperimental?"experimental":""}">
  425. <td>${key.replaceAll("_","-")}</td>
  426. <td>
  427. <div class="ui checkbox">
  428. <input class="enabled" type="checkbox" name="${key}" ${enabled}>
  429. <label></label>
  430. </div>
  431. </td>
  432. <td>
  433. <div class="ui radio checkbox targetinput ${!enabled?"disabled":""}">
  434. <input type="radio" value="all" name="${key}-target" ${allowall} ${!enabled?"disabled=\"\"":""}>
  435. <label></label>
  436. </div>
  437. </td>
  438. <td>
  439. <div class="ui radio checkbox targetinput ${!enabled?"disabled":""}">
  440. <input type="radio" value="self" name="${key}-target" ${allowself} ${!enabled?"disabled=\"\"":""}>
  441. <label></label>
  442. </div>
  443. </td>
  444. </tr>`);
  445. permissionPolicyKeys.push(key);
  446. }
  447. $("#permissionPolicyEditTable .enabled").on("change", function(){
  448. console.log($(this)[0].checked);
  449. let fieldGroup = $(this).parent().parent().parent();
  450. if ($(this)[0].checked){
  451. fieldGroup.find(".targetinput").removeClass("disabled");
  452. fieldGroup.find("input[type=radio]").prop('disabled', false);
  453. }else{
  454. fieldGroup.find(".targetinput").addClass("disabled");
  455. fieldGroup.find("input[type=radio]").prop('disabled', true);
  456. }
  457. })
  458. });
  459. }
  460. initPermissionPolicy();
  461. //Generate the permission policy object for sending to backend
  462. function generatePermissionPolicyObject(){
  463. function getStructuredFieldValueFromDOM(fieldKey){
  464. var policyTarget = $(`#permissionPolicyEditTable input[name="${fieldKey}-target"]:checked`).val();
  465. var isPolicyEnabled = $(`#permissionPolicyEditTable input[name="${fieldKey}"]`).is(':checked');
  466. if (!isPolicyEnabled){
  467. return [];
  468. }
  469. if (policyTarget == "all"){
  470. //Rewrite all to correct syntax
  471. policyTarget = "*";
  472. }
  473. return [policyTarget];
  474. }
  475. let newPermissionPolicyKeyValuePair = {};
  476. permissionPolicyKeys.forEach(policyKey => {
  477. newPermissionPolicyKeyValuePair[policyKey] = getStructuredFieldValueFromDOM(policyKey);
  478. });
  479. console.log(newPermissionPolicyKeyValuePair);
  480. return newPermissionPolicyKeyValuePair;
  481. }
  482. //Handle saving of permission policy
  483. function savePermissionPolicy(){
  484. let permissionPolicy = generatePermissionPolicyObject();
  485. let domain = editingEndpoint.ep;
  486. $.ajax({
  487. url: "/api/proxy/header/handlePermissionPolicy",
  488. method: "PUT",
  489. data: {
  490. "domain": domain,
  491. "pp": JSON.stringify(permissionPolicy),
  492. },
  493. success: function(data){
  494. if (data.error != undefined){
  495. parent.msgbox(data.error, false);
  496. }else{
  497. parent.msgbox("Permission Policy Updated");
  498. }
  499. }
  500. })
  501. }
  502. /* Manual HOST header overwrite */
  503. function updateManualHostOverwrite(){
  504. updateManualHostOverwriteVal(function(data){
  505. if (data.error != undefined){
  506. parent.msgbox(data.error, false);
  507. }else{
  508. parent.msgbox("Host field Overwrite Updated");
  509. initManualHostOverwriteValue();
  510. }
  511. });
  512. }
  513. function clearManualHostOverwrite(){
  514. $('#manualHostOverwrite').val('');
  515. updateManualHostOverwriteVal(function(data){
  516. if (data.error != undefined){
  517. parent.msgbox(data.error, false);
  518. }else{
  519. parent.msgbox("Host field Overwrite Cleared");
  520. initManualHostOverwriteValue();
  521. }
  522. })
  523. }
  524. function updateManualHostOverwriteVal(callback=undefined){
  525. let newHostname = $("#manualHostOverwrite").val().trim();
  526. $.ajax({
  527. url: "/api/proxy/header/handleHostOverwrite",
  528. method: "POST",
  529. data: {
  530. "domain": editingEndpoint.ep,
  531. "hostname": newHostname,
  532. },
  533. success: function(data){
  534. callback(data);
  535. }
  536. })
  537. }
  538. function initManualHostOverwriteValue(){
  539. $.get("/api/proxy/header/handleHostOverwrite?domain=" + editingEndpoint.ep, function(data){
  540. if (data.error != undefined){
  541. parent.msgbox(data.error, false);
  542. }else{
  543. $("#manualHostOverwrite").val(data);
  544. }
  545. });
  546. }
  547. initManualHostOverwriteValue();
  548. /* Hop-by-hop headers */
  549. function initHopByHopRemoverState(){
  550. $.get("/api/proxy/header/handleHopByHop?domain=" + editingEndpoint.ep, function(data){
  551. if (data.error != undefined){
  552. parent.msgbox(data.error);
  553. }else{
  554. if (data == true){
  555. $("#removeHopByHop").parent().checkbox("set checked");
  556. }else{
  557. $("#removeHopByHop").parent().checkbox("set unchecked");
  558. }
  559. //Bind event to the checkbox
  560. $("#removeHopByHop").on("change", function(evt){
  561. let isChecked = $(this)[0].checked;
  562. $.ajax({
  563. url: "/api/proxy/header/handleHopByHop",
  564. method: "POST",
  565. data: {
  566. "domain": editingEndpoint.ep,
  567. "removeHopByHop": isChecked,
  568. },
  569. success: function(data){
  570. if (data.error != undefined){
  571. parent.msgbox(data.error, false);
  572. }else{
  573. parent.msgbox("Hop-by-Hop header rule updated");
  574. }
  575. }
  576. })
  577. })
  578. }
  579. })
  580. }
  581. initHopByHopRemoverState();
  582. </script>
  583. </body>
  584. </html>