http.go 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244
  1. package libbox
  2. import (
  3. "bytes"
  4. "context"
  5. "crypto/sha256"
  6. "crypto/tls"
  7. "crypto/x509"
  8. "encoding/hex"
  9. "errors"
  10. "fmt"
  11. "io"
  12. "math/rand"
  13. "net"
  14. "net/http"
  15. "net/url"
  16. "os"
  17. "strconv"
  18. "sync"
  19. "time"
  20. "github.com/sagernet/sing/common"
  21. "github.com/sagernet/sing/common/bufio"
  22. E "github.com/sagernet/sing/common/exceptions"
  23. M "github.com/sagernet/sing/common/metadata"
  24. "github.com/sagernet/sing/protocol/socks"
  25. "github.com/sagernet/sing/protocol/socks/socks5"
  26. )
  27. type HTTPClient interface {
  28. RestrictedTLS()
  29. ModernTLS()
  30. PinnedTLS12()
  31. PinnedSHA256(sumHex string)
  32. TrySocks5(port int32)
  33. KeepAlive()
  34. NewRequest() HTTPRequest
  35. Close()
  36. }
  37. type HTTPRequest interface {
  38. SetURL(link string) error
  39. SetMethod(method string)
  40. SetHeader(key string, value string)
  41. SetContent(content []byte)
  42. SetContentString(content string)
  43. RandomUserAgent()
  44. SetUserAgent(userAgent string)
  45. Execute() (HTTPResponse, error)
  46. }
  47. type HTTPResponse interface {
  48. GetContent() ([]byte, error)
  49. GetContentString() (string, error)
  50. WriteTo(path string) error
  51. }
  52. var (
  53. _ HTTPClient = (*httpClient)(nil)
  54. _ HTTPRequest = (*httpRequest)(nil)
  55. _ HTTPResponse = (*httpResponse)(nil)
  56. )
  57. type httpClient struct {
  58. tls tls.Config
  59. client http.Client
  60. transport http.Transport
  61. }
  62. func NewHTTPClient() HTTPClient {
  63. client := new(httpClient)
  64. client.client.Timeout = 15 * time.Second
  65. client.client.Transport = &client.transport
  66. client.transport.TLSClientConfig = &client.tls
  67. client.transport.DisableKeepAlives = true
  68. return client
  69. }
  70. func (c *httpClient) ModernTLS() {
  71. c.tls.MinVersion = tls.VersionTLS12
  72. c.tls.CipherSuites = common.Map(tls.CipherSuites(), func(it *tls.CipherSuite) uint16 { return it.ID })
  73. }
  74. func (c *httpClient) RestrictedTLS() {
  75. c.tls.MinVersion = tls.VersionTLS13
  76. c.tls.CipherSuites = common.Map(common.Filter(tls.CipherSuites(), func(it *tls.CipherSuite) bool {
  77. return common.Contains(it.SupportedVersions, uint16(tls.VersionTLS13))
  78. }), func(it *tls.CipherSuite) uint16 {
  79. return it.ID
  80. })
  81. }
  82. func (c *httpClient) PinnedTLS12() {
  83. c.tls.MinVersion = tls.VersionTLS12
  84. c.tls.MaxVersion = tls.VersionTLS12
  85. }
  86. func (c *httpClient) PinnedSHA256(sumHex string) {
  87. c.tls.VerifyPeerCertificate = func(rawCerts [][]byte, verifiedChains [][]*x509.Certificate) error {
  88. for _, rawCert := range rawCerts {
  89. certSum := sha256.Sum256(rawCert)
  90. if sumHex == hex.EncodeToString(certSum[:]) {
  91. return nil
  92. }
  93. }
  94. return E.New("pinned sha256 sum mismatch")
  95. }
  96. }
  97. func (c *httpClient) TrySocks5(port int32) {
  98. dialer := new(net.Dialer)
  99. c.transport.DialContext = func(ctx context.Context, network, addr string) (net.Conn, error) {
  100. for {
  101. socksConn, err := dialer.DialContext(ctx, "tcp", "127.0.0.1:"+strconv.Itoa(int(port)))
  102. if err != nil {
  103. break
  104. }
  105. _, err = socks.ClientHandshake5(socksConn, socks5.CommandConnect, M.ParseSocksaddr(addr), "", "")
  106. if err != nil {
  107. break
  108. }
  109. //nolint:staticcheck
  110. return socksConn, err
  111. }
  112. return dialer.DialContext(ctx, network, addr)
  113. }
  114. }
  115. func (c *httpClient) KeepAlive() {
  116. c.transport.ForceAttemptHTTP2 = true
  117. c.transport.DisableKeepAlives = false
  118. }
  119. func (c *httpClient) NewRequest() HTTPRequest {
  120. req := &httpRequest{httpClient: c}
  121. req.request = http.Request{
  122. Method: "GET",
  123. Header: http.Header{},
  124. }
  125. return req
  126. }
  127. func (c *httpClient) Close() {
  128. c.transport.CloseIdleConnections()
  129. }
  130. type httpRequest struct {
  131. *httpClient
  132. request http.Request
  133. }
  134. func (r *httpRequest) SetURL(link string) (err error) {
  135. r.request.URL, err = url.Parse(link)
  136. if err != nil {
  137. return
  138. }
  139. if r.request.URL.User != nil {
  140. user := r.request.URL.User.Username()
  141. password, _ := r.request.URL.User.Password()
  142. r.request.SetBasicAuth(user, password)
  143. }
  144. return
  145. }
  146. func (r *httpRequest) SetMethod(method string) {
  147. r.request.Method = method
  148. }
  149. func (r *httpRequest) SetHeader(key string, value string) {
  150. r.request.Header.Set(key, value)
  151. }
  152. func (r *httpRequest) RandomUserAgent() {
  153. r.request.Header.Set("User-Agent", fmt.Sprintf("curl/7.%d.%d", rand.Int()%54, rand.Int()%2))
  154. }
  155. func (r *httpRequest) SetUserAgent(userAgent string) {
  156. r.request.Header.Set("User-Agent", userAgent)
  157. }
  158. func (r *httpRequest) SetContent(content []byte) {
  159. buffer := bytes.Buffer{}
  160. buffer.Write(content)
  161. r.request.Body = io.NopCloser(bytes.NewReader(buffer.Bytes()))
  162. r.request.ContentLength = int64(len(content))
  163. }
  164. func (r *httpRequest) SetContentString(content string) {
  165. r.SetContent([]byte(content))
  166. }
  167. func (r *httpRequest) Execute() (HTTPResponse, error) {
  168. response, err := r.client.Do(&r.request)
  169. if err != nil {
  170. return nil, err
  171. }
  172. httpResp := &httpResponse{Response: response}
  173. if response.StatusCode != http.StatusOK {
  174. return nil, errors.New(httpResp.errorString())
  175. }
  176. return httpResp, nil
  177. }
  178. type httpResponse struct {
  179. *http.Response
  180. getContentOnce sync.Once
  181. content []byte
  182. contentError error
  183. }
  184. func (h *httpResponse) errorString() string {
  185. content, err := h.GetContentString()
  186. if err != nil {
  187. return fmt.Sprint("HTTP ", h.Status)
  188. }
  189. return fmt.Sprint("HTTP ", h.Status, ": ", content)
  190. }
  191. func (h *httpResponse) GetContent() ([]byte, error) {
  192. h.getContentOnce.Do(func() {
  193. defer h.Body.Close()
  194. h.content, h.contentError = io.ReadAll(h.Body)
  195. })
  196. return h.content, h.contentError
  197. }
  198. func (h *httpResponse) GetContentString() (string, error) {
  199. content, err := h.GetContent()
  200. if err != nil {
  201. return "", err
  202. }
  203. return string(content), nil
  204. }
  205. func (h *httpResponse) WriteTo(path string) error {
  206. defer h.Body.Close()
  207. file, err := os.Create(path)
  208. if err != nil {
  209. return err
  210. }
  211. defer file.Close()
  212. return common.Error(bufio.Copy(file, h.Body))
  213. }