index.js 6.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284
  1. 'use strict'
  2. /**
  3. * static files (404.html, sw.js, conf.js)
  4. */
  5. const ASSET_URL = 'https://zjcqoo.github.io'
  6. const JS_VER = 10
  7. const MAX_RETRY = 1
  8. /** @type {RequestInit} */
  9. const PREFLIGHT_INIT = {
  10. status: 204,
  11. headers: new Headers({
  12. 'access-control-allow-origin': '*',
  13. 'access-control-allow-methods': 'GET,POST,PUT,PATCH,TRACE,DELETE,HEAD,OPTIONS',
  14. 'access-control-allow-headers': '--raw-info,--level,--url,--referer,--cookie,--origin,--ext,--aceh,--ver,--type,--mode,accept,accept-charset,accept-encoding,accept-language,accept-datetime,authorization,cache-control,content-length,content-type,date,if-match,if-modified-since,if-none-match,if-range,if-unmodified-since,max-forwards,pragma,range,te,upgrade,upgrade-insecure-requests,x-requested-with,chrome-proxy,purpose',
  15. 'access-control-max-age': '1728000',
  16. }),
  17. }
  18. /**
  19. * @param {any} body
  20. * @param {number} status
  21. * @param {Object<string, string>} headers
  22. */
  23. function makeRes(body, status = 200, headers = {}) {
  24. headers['cache-control'] = 'no-cache'
  25. headers['vary'] = '--url'
  26. headers['--ver'] = JS_VER
  27. headers['access-control-allow-origin'] = '*'
  28. return new Response(body, {status, headers})
  29. }
  30. addEventListener('fetch', e => {
  31. const ret = fetchHandler(e)
  32. .catch(err => makeRes('cfworker error:\n' + err.stack, 502))
  33. e.respondWith(ret)
  34. })
  35. /**
  36. * @param {FetchEvent} e
  37. */
  38. async function fetchHandler(e) {
  39. const req = e.request
  40. const urlStr = req.url
  41. const urlObj = new URL(urlStr)
  42. if (urlObj.protocol === 'http:') {
  43. urlObj.protocol = 'https:'
  44. return makeRes('', 301, {
  45. 'strict-transport-security': 'max-age=99999999; includeSubDomains; preload',
  46. 'location': urlObj.href,
  47. })
  48. }
  49. switch (urlObj.pathname) {
  50. case '/http':
  51. return httpHandler(req)
  52. case '/ws':
  53. return makeRes('not support', 400)
  54. case '/works':
  55. return makeRes('it works')
  56. default:
  57. // static files
  58. return fetch(ASSET_URL + urlObj.pathname)
  59. }
  60. }
  61. /**
  62. * @param {Request} req
  63. */
  64. function httpHandler(req) {
  65. const reqHdrRaw = req.headers
  66. if (reqHdrRaw.has('x-jsproxy')) {
  67. return Response.error()
  68. }
  69. // preflight
  70. if (req.method === 'OPTIONS' &&
  71. reqHdrRaw.has('access-control-request-headers')
  72. ) {
  73. return new Response(null, PREFLIGHT_INIT)
  74. }
  75. let urlObj = null
  76. let extHdrs = null
  77. let acehOld = false
  78. let rawSvr = ''
  79. let rawLen = ''
  80. let rawEtag = ''
  81. const reqHdrNew = new Headers(reqHdrRaw)
  82. reqHdrNew.set('x-jsproxy', '1')
  83. for (const [k, v] of reqHdrRaw.entries()) {
  84. if (!k.startsWith('--')) {
  85. continue
  86. }
  87. reqHdrNew.delete(k)
  88. const k2 = k.substr(2)
  89. switch (k2) {
  90. case 'url':
  91. urlObj = new URL(v)
  92. break
  93. case 'aceh':
  94. acehOld = true
  95. break
  96. case 'raw-info':
  97. [rawSvr, rawLen, rawEtag] = v.split('|')
  98. break
  99. case 'level':
  100. case 'mode':
  101. case 'type':
  102. break
  103. case 'ext':
  104. extHdrs = JSON.parse(v)
  105. break
  106. default:
  107. if (v) {
  108. reqHdrNew.set(k2, v)
  109. } else {
  110. reqHdrNew.delete(k2)
  111. }
  112. break
  113. }
  114. }
  115. if (extHdrs) {
  116. for (const [k, v] of Object.entries(extHdrs)) {
  117. reqHdrNew.set(k, v)
  118. }
  119. }
  120. if (!urlObj) {
  121. return makeRes('missing url param', 403)
  122. }
  123. /** @type {RequestInit} */
  124. const reqInit = {
  125. method: req.method,
  126. headers: reqHdrNew,
  127. redirect: 'manual',
  128. }
  129. if (req.method === 'POST') {
  130. reqInit.body = req.body
  131. }
  132. return proxy(urlObj, reqInit, acehOld, rawLen, 0)
  133. }
  134. /**
  135. *
  136. * @param {URL} urlObj
  137. * @param {RequestInit} reqInit
  138. * @param {number} retryTimes
  139. */
  140. async function proxy(urlObj, reqInit, acehOld, rawLen, retryTimes) {
  141. const res = await fetch(urlObj.href, reqInit)
  142. const resHdrOld = res.headers
  143. const resHdrNew = new Headers(resHdrOld)
  144. let expose = '*'
  145. let vary = '--url'
  146. for (const [k, v] of resHdrOld.entries()) {
  147. if (k === 'access-control-allow-origin' ||
  148. k === 'access-control-expose-headers' ||
  149. k === 'location' ||
  150. k === 'set-cookie'
  151. ) {
  152. const x = '--' + k
  153. resHdrNew.set(x, v)
  154. if (acehOld) {
  155. expose = expose + ',' + x
  156. }
  157. resHdrNew.delete(k)
  158. }
  159. else if (k === 'vary') {
  160. vary = vary + ',' + v
  161. }
  162. else if (acehOld &&
  163. k !== 'cache-control' &&
  164. k !== 'content-language' &&
  165. k !== 'content-type' &&
  166. k !== 'expires' &&
  167. k !== 'last-modified' &&
  168. k !== 'pragma'
  169. ) {
  170. expose = expose + ',' + k
  171. }
  172. }
  173. if (acehOld) {
  174. expose = expose + ',--s'
  175. resHdrNew.set('--t', '1')
  176. }
  177. // verify
  178. if (rawLen) {
  179. const newLen = resHdrOld.get('content-length') || ''
  180. const badLen = (rawLen !== newLen)
  181. if (badLen) {
  182. if (retryTimes < MAX_RETRY) {
  183. urlObj = await parseYtVideoRedir(urlObj, newLen, res)
  184. if (urlObj) {
  185. return proxy(urlObj, reqInit, acehOld, rawLen, retryTimes + 1)
  186. }
  187. }
  188. return makeRes(res.body, 400, {
  189. '--error': `bad len: ${newLen}, except: ${rawLen}`,
  190. 'access-control-expose-headers': '--error',
  191. })
  192. }
  193. if (retryTimes > 1) {
  194. resHdrNew.set('--retry', retryTimes)
  195. }
  196. }
  197. let status = res.status
  198. resHdrNew.set('access-control-expose-headers', expose)
  199. resHdrNew.set('access-control-allow-origin', '*')
  200. resHdrNew.set('vary', vary)
  201. resHdrNew.set('--s', status)
  202. resHdrNew.set('--ver', JS_VER)
  203. resHdrNew.delete('content-security-policy')
  204. resHdrNew.delete('content-security-policy-report-only')
  205. resHdrNew.delete('clear-site-data')
  206. if (status === 301 ||
  207. status === 302 ||
  208. status === 303 ||
  209. status === 307 ||
  210. status === 308
  211. ) {
  212. status = status + 10
  213. }
  214. return new Response(res.body, {
  215. status,
  216. headers: resHdrNew,
  217. })
  218. }
  219. /**
  220. * @param {URL} urlObj
  221. */
  222. function isYtUrl(urlObj) {
  223. return (
  224. urlObj.host.endsWith('.googlevideo.com') &&
  225. urlObj.pathname.startsWith('/videoplayback')
  226. )
  227. }
  228. /**
  229. * @param {URL} urlObj
  230. * @param {number} newLen
  231. * @param {Response} res
  232. */
  233. async function parseYtVideoRedir(urlObj, newLen, res) {
  234. if (newLen > 2000) {
  235. return null
  236. }
  237. if (!isYtUrl(urlObj)) {
  238. return null
  239. }
  240. try {
  241. const data = await res.text()
  242. urlObj = new URL(data)
  243. } catch (err) {
  244. return null
  245. }
  246. if (!isYtUrl(urlObj)) {
  247. return null
  248. }
  249. return urlObj
  250. }