http.go 5.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241
  1. package libbox
  2. import (
  3. "bytes"
  4. "context"
  5. "crypto/sha256"
  6. "crypto/tls"
  7. "crypto/x509"
  8. "encoding/hex"
  9. "errors"
  10. "fmt"
  11. "io"
  12. "math/rand"
  13. "net"
  14. "net/http"
  15. "net/url"
  16. "os"
  17. "strconv"
  18. "sync"
  19. C "github.com/sagernet/sing-box/constant"
  20. "github.com/sagernet/sing/common"
  21. "github.com/sagernet/sing/common/bufio"
  22. E "github.com/sagernet/sing/common/exceptions"
  23. M "github.com/sagernet/sing/common/metadata"
  24. "github.com/sagernet/sing/protocol/socks"
  25. "github.com/sagernet/sing/protocol/socks/socks5"
  26. )
  27. type HTTPClient interface {
  28. RestrictedTLS()
  29. ModernTLS()
  30. PinnedTLS12()
  31. PinnedSHA256(sumHex string)
  32. TrySocks5(port int32)
  33. KeepAlive()
  34. NewRequest() HTTPRequest
  35. Close()
  36. }
  37. type HTTPRequest interface {
  38. SetURL(link string) error
  39. SetMethod(method string)
  40. SetHeader(key string, value string)
  41. SetContent(content []byte)
  42. SetContentString(content string)
  43. RandomUserAgent()
  44. SetUserAgent(userAgent string)
  45. Execute() (HTTPResponse, error)
  46. }
  47. type HTTPResponse interface {
  48. GetContent() (*StringBox, error)
  49. WriteTo(path string) error
  50. }
  51. var (
  52. _ HTTPClient = (*httpClient)(nil)
  53. _ HTTPRequest = (*httpRequest)(nil)
  54. _ HTTPResponse = (*httpResponse)(nil)
  55. )
  56. type httpClient struct {
  57. tls tls.Config
  58. client http.Client
  59. transport http.Transport
  60. }
  61. func NewHTTPClient() HTTPClient {
  62. client := new(httpClient)
  63. client.client.Transport = &client.transport
  64. client.transport.ForceAttemptHTTP2 = true
  65. client.transport.TLSHandshakeTimeout = C.TCPTimeout
  66. client.transport.TLSClientConfig = &client.tls
  67. client.transport.DisableKeepAlives = true
  68. return client
  69. }
  70. func (c *httpClient) ModernTLS() {
  71. c.setTLSVersion(tls.VersionTLS12, 0, func(suite *tls.CipherSuite) bool { return true })
  72. }
  73. func (c *httpClient) RestrictedTLS() {
  74. c.setTLSVersion(tls.VersionTLS13, 0, func(suite *tls.CipherSuite) bool {
  75. return common.Contains(suite.SupportedVersions, uint16(tls.VersionTLS13))
  76. })
  77. }
  78. func (c *httpClient) setTLSVersion(minVersion, maxVersion uint16, filter func(*tls.CipherSuite) bool) {
  79. c.tls.MinVersion = minVersion
  80. if maxVersion != 0 {
  81. c.tls.MaxVersion = maxVersion
  82. }
  83. c.tls.CipherSuites = common.Map(common.Filter(tls.CipherSuites(), filter), func(it *tls.CipherSuite) uint16 {
  84. return it.ID
  85. })
  86. }
  87. func (c *httpClient) PinnedTLS12() {
  88. c.setTLSVersion(tls.VersionTLS12, tls.VersionTLS12, func(suite *tls.CipherSuite) bool { return true })
  89. }
  90. func (c *httpClient) PinnedSHA256(sumHex string) {
  91. c.tls.VerifyPeerCertificate = func(rawCerts [][]byte, verifiedChains [][]*x509.Certificate) error {
  92. for _, rawCert := range rawCerts {
  93. certSum := sha256.Sum256(rawCert)
  94. if sumHex == hex.EncodeToString(certSum[:]) {
  95. return nil
  96. }
  97. }
  98. return E.New("pinned sha256 sum mismatch")
  99. }
  100. }
  101. func (c *httpClient) TrySocks5(port int32) {
  102. dialer := new(net.Dialer)
  103. c.transport.DialContext = func(ctx context.Context, network, addr string) (net.Conn, error) {
  104. for {
  105. socksConn, err := dialer.DialContext(ctx, "tcp", "127.0.0.1:"+strconv.Itoa(int(port)))
  106. if err != nil {
  107. break
  108. }
  109. _, err = socks.ClientHandshake5(socksConn, socks5.CommandConnect, M.ParseSocksaddr(addr), "", "")
  110. if err != nil {
  111. break
  112. }
  113. //nolint:staticcheck
  114. return socksConn, err
  115. }
  116. return dialer.DialContext(ctx, network, addr)
  117. }
  118. }
  119. func (c *httpClient) KeepAlive() {
  120. c.transport.DisableKeepAlives = false
  121. }
  122. func (c *httpClient) NewRequest() HTTPRequest {
  123. req := &httpRequest{httpClient: c}
  124. req.request = http.Request{
  125. Method: "GET",
  126. Header: http.Header{},
  127. }
  128. return req
  129. }
  130. func (c *httpClient) Close() {
  131. c.transport.CloseIdleConnections()
  132. }
  133. type httpRequest struct {
  134. *httpClient
  135. request http.Request
  136. }
  137. func (r *httpRequest) SetURL(link string) (err error) {
  138. r.request.URL, err = url.Parse(link)
  139. if err != nil {
  140. return
  141. }
  142. if r.request.URL.User != nil {
  143. user := r.request.URL.User.Username()
  144. password, _ := r.request.URL.User.Password()
  145. r.request.SetBasicAuth(user, password)
  146. }
  147. return
  148. }
  149. func (r *httpRequest) SetMethod(method string) {
  150. r.request.Method = method
  151. }
  152. func (r *httpRequest) SetHeader(key string, value string) {
  153. r.request.Header.Set(key, value)
  154. }
  155. func (r *httpRequest) RandomUserAgent() {
  156. r.request.Header.Set("User-Agent", fmt.Sprintf("curl/7.%d.%d", rand.Int()%54, rand.Int()%2))
  157. }
  158. func (r *httpRequest) SetUserAgent(userAgent string) {
  159. r.request.Header.Set("User-Agent", userAgent)
  160. }
  161. func (r *httpRequest) SetContent(content []byte) {
  162. r.request.Body = io.NopCloser(bytes.NewReader(content))
  163. r.request.ContentLength = int64(len(content))
  164. }
  165. func (r *httpRequest) SetContentString(content string) {
  166. r.SetContent([]byte(content))
  167. }
  168. func (r *httpRequest) Execute() (HTTPResponse, error) {
  169. response, err := r.client.Do(&r.request)
  170. if err != nil {
  171. return nil, err
  172. }
  173. httpResp := &httpResponse{Response: response}
  174. if response.StatusCode != http.StatusOK {
  175. return nil, errors.New(httpResp.errorString())
  176. }
  177. return httpResp, nil
  178. }
  179. type httpResponse struct {
  180. *http.Response
  181. getContentOnce sync.Once
  182. content []byte
  183. contentError error
  184. }
  185. func (h *httpResponse) errorString() string {
  186. content, err := h.GetContent()
  187. if err != nil {
  188. return fmt.Sprint("HTTP ", h.Status)
  189. }
  190. return fmt.Sprint("HTTP ", h.Status, ": ", content)
  191. }
  192. func (h *httpResponse) GetContent() (*StringBox, error) {
  193. h.getContentOnce.Do(func() {
  194. defer h.Body.Close()
  195. h.content, h.contentError = io.ReadAll(h.Body)
  196. })
  197. if h.contentError != nil {
  198. return nil, h.contentError
  199. }
  200. return wrapString(string(h.content)), nil
  201. }
  202. func (h *httpResponse) WriteTo(path string) error {
  203. defer h.Body.Close()
  204. file, err := os.Create(path)
  205. if err != nil {
  206. return err
  207. }
  208. defer file.Close()
  209. return common.Error(bufio.Copy(file, h.Body))
  210. }