mirror of
https://github.com/dcarrillo/whatismyip.git
synced 2025-07-06 22:39:25 +00:00
Compare commits
45 Commits
Author | SHA1 | Date | |
---|---|---|---|
901345a337
|
|||
0c14419e7e | |||
db111642d2 | |||
d5b1373e17 | |||
ba8a2ec494 | |||
f8e27bef56 | |||
2bbeeb34c5 | |||
0090b794ee | |||
93f561d6ef | |||
9da6d2fec5 | |||
8e3d731719
|
|||
d5b244dc5f
|
|||
d767afd658
|
|||
f4fd79737e
|
|||
2ab6b29ed5
|
|||
55e6cd4816
|
|||
a490d5f10e
|
|||
994a12da5a | |||
91deff4a14 | |||
81c3a4fbb0 | |||
5b85eef7eb | |||
c54cf5a456
|
|||
7dfa0a2e6d
|
|||
68ef680439 | |||
bd42f712ea | |||
0b31633309
|
|||
b5fa3be506
|
|||
8783db018b
|
|||
e60d1ae5b7
|
|||
84a767ade0
|
|||
19c72f94a5
|
|||
de78dcdf52
|
|||
eb200ddd81
|
|||
5c4ac4a3ee
|
|||
ee328892d6
|
|||
04d983d671
|
|||
202518d547
|
|||
52d14fe78f
|
|||
8aadc4fbb6
|
|||
b6391d8fd1 | |||
35fac1bd57
|
|||
b13a30c354
|
|||
5982683cdd
|
|||
1a986a029f
|
|||
ed0ddccab5
|
16
.github/workflows/codeql-analysis.yml
vendored
16
.github/workflows/codeql-analysis.yml
vendored
@ -29,16 +29,18 @@ jobs:
|
|||||||
contents: read
|
contents: read
|
||||||
security-events: write
|
security-events: write
|
||||||
|
|
||||||
strategy:
|
|
||||||
fail-fast: false
|
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout repository
|
- name: Checkout repository
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: install go
|
||||||
|
uses: actions/setup-go@v5
|
||||||
|
with:
|
||||||
|
go-version-file: go.mod
|
||||||
|
cache: true
|
||||||
|
|
||||||
# Initializes the CodeQL tools for scanning.
|
|
||||||
- name: Initialize CodeQL
|
- name: Initialize CodeQL
|
||||||
uses: github/codeql-action/init@v2
|
uses: github/codeql-action/init@v3
|
||||||
with:
|
with:
|
||||||
languages: go
|
languages: go
|
||||||
|
|
||||||
@ -47,4 +49,4 @@ jobs:
|
|||||||
make build
|
make build
|
||||||
|
|
||||||
- name: Perform CodeQL Analysis
|
- name: Perform CodeQL Analysis
|
||||||
uses: github/codeql-action/analyze@v2
|
uses: github/codeql-action/analyze@v3
|
||||||
|
17
.github/workflows/main.yml
vendored
17
.github/workflows/main.yml
vendored
@ -15,14 +15,14 @@ jobs:
|
|||||||
matrix:
|
matrix:
|
||||||
make: ["lint", "test"]
|
make: ["lint", "test"]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v2.4.0
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: install go
|
- name: install go
|
||||||
uses: actions/setup-go@v2
|
uses: actions/setup-go@v5
|
||||||
with:
|
with:
|
||||||
go-version: "^1.19"
|
go-version-file: go.mod
|
||||||
|
|
||||||
- name: Lint
|
- name: ${{ matrix.make }}
|
||||||
run: make ${{ matrix.make }}
|
run: make ${{ matrix.make }}
|
||||||
|
|
||||||
deploy:
|
deploy:
|
||||||
@ -33,9 +33,14 @@ jobs:
|
|||||||
matrix:
|
matrix:
|
||||||
goosarch: [linux-amd64]
|
goosarch: [linux-amd64]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v2.4.0
|
- uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
- name: install go
|
||||||
|
uses: actions/setup-go@v5
|
||||||
|
with:
|
||||||
|
go-version-file: go.mod
|
||||||
|
cache: true
|
||||||
|
|
||||||
- name: Set env
|
- name: Set env
|
||||||
run: echo "RELEASE_VERSION=${GITHUB_REF#refs/*/}" >> $GITHUB_ENV
|
run: echo "RELEASE_VERSION=${GITHUB_REF#refs/*/}" >> $GITHUB_ENV
|
||||||
@ -56,7 +61,7 @@ jobs:
|
|||||||
sha256sum whatismyip-$RELEASE_VERSION-${{matrix.goosarch}}.tar.gz > whatismyip-$RELEASE_VERSION-${{matrix.goosarch}}.tar.gz.sha256
|
sha256sum whatismyip-$RELEASE_VERSION-${{matrix.goosarch}}.tar.gz > whatismyip-$RELEASE_VERSION-${{matrix.goosarch}}.tar.gz.sha256
|
||||||
|
|
||||||
- name: Release
|
- name: Release
|
||||||
uses: softprops/action-gh-release@v0.1.14
|
uses: softprops/action-gh-release@v1
|
||||||
with:
|
with:
|
||||||
body_path: changelog.txt
|
body_path: changelog.txt
|
||||||
files: |
|
files: |
|
||||||
|
@ -1,4 +1,4 @@
|
|||||||
FROM golang:1.19-alpine as builder
|
FROM golang:1.21-alpine as builder
|
||||||
|
|
||||||
ARG ARG_VERSION
|
ARG ARG_VERSION
|
||||||
ENV VERSION $ARG_VERSION
|
ENV VERSION $ARG_VERSION
|
||||||
@ -7,7 +7,8 @@ WORKDIR /app
|
|||||||
|
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
RUN apk add make git && make build VERSION=$VERSION
|
RUN apk add make git upx && make build VERSION=$VERSION \
|
||||||
|
&& upx --best --lzma whatismyip
|
||||||
|
|
||||||
# Build final image
|
# Build final image
|
||||||
FROM scratch
|
FROM scratch
|
||||||
|
13
Makefile
13
Makefile
@ -7,29 +7,24 @@ test: unit-test integration-test
|
|||||||
|
|
||||||
.PHONY: unit-test
|
.PHONY: unit-test
|
||||||
unit-test:
|
unit-test:
|
||||||
go test -race -short -cover ./...
|
go test -count=1 -race -short -cover ./...
|
||||||
|
|
||||||
.PHONY: integration-test
|
.PHONY: integration-test
|
||||||
integration-test:
|
integration-test:
|
||||||
go test ./integration-tests -v
|
go test -count=1 -v ./integration-tests
|
||||||
|
|
||||||
.PHONY: install-tools
|
.PHONY: install-tools
|
||||||
install-tools:
|
install-tools:
|
||||||
@command golangci-lint > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
|
@command golangci-lint > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
|
||||||
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(GOPATH)/bin v1.45.2; \
|
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(GOPATH)/bin; \
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@command $(GOPATH)/shadow > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
|
@command $(GOPATH)/shadow > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
|
||||||
go install golang.org/x/tools/go/analysis/passes/shadow/cmd/shadow@v0.1.10; \
|
go install golang.org/x/tools/go/analysis/passes/shadow/cmd/shadow@latest; \
|
||||||
fi
|
|
||||||
|
|
||||||
@command $(GOPATH)/golines > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
|
|
||||||
go install github.com/segmentio/golines@latest; \
|
|
||||||
fi
|
fi
|
||||||
.PHONY: lint
|
.PHONY: lint
|
||||||
lint: install-tools
|
lint: install-tools
|
||||||
gofmt -l . && test -z $$(gofmt -l .)
|
gofmt -l . && test -z $$(gofmt -l .)
|
||||||
golines -l . && test -z $$(golines -l .)
|
|
||||||
golangci-lint run
|
golangci-lint run
|
||||||
shadow ./...
|
shadow ./...
|
||||||
|
|
||||||
|
24
README.md
24
README.md
@ -14,13 +14,15 @@
|
|||||||
- [Examples](#examples)
|
- [Examples](#examples)
|
||||||
- [Run a default TCP server](#run-a-default-tcp-server)
|
- [Run a default TCP server](#run-a-default-tcp-server)
|
||||||
- [Run a TLS (HTTP/2) server only](#run-a-tls-http2-server-only)
|
- [Run a TLS (HTTP/2) server only](#run-a-tls-http2-server-only)
|
||||||
|
- [Run an HTTP/3 server](#run-an-http3-server)
|
||||||
- [Run a default TCP server with a custom template and trust a pair of custom headers set by an upstream proxy](#run-a-default-tcp-server-with-a-custom-template-and-trust-a-pair-of-custom-headers-set-by-an-upstream-proxy)
|
- [Run a default TCP server with a custom template and trust a pair of custom headers set by an upstream proxy](#run-a-default-tcp-server-with-a-custom-template-and-trust-a-pair-of-custom-headers-set-by-an-upstream-proxy)
|
||||||
- [Download](#download)
|
- [Download](#download)
|
||||||
- [Docker](#docker)
|
- [Docker](#docker)
|
||||||
- [Run a container locally using test databases](#run-a-container-locally-using-test-databases)
|
- [Run a container locally using test databases](#run-a-container-locally-using-test-databases)
|
||||||
- [From Docker Hub](#from-docker-hub)
|
- [From Docker Hub](#from-docker-hub)
|
||||||
|
|
||||||
Just another "what is my IP address" service, including geolocation and headers information, written in go with high performance in mind, it uses [gin](https://github.com/gin-gonic/gin) which uses [httprouter](https://github.com/julienschmidt/httprouter) a lightweight high performance HTTP multiplexer.
|
Just another "what is my IP address" service, including geolocation, TCP open port checking, and headers information. Written in go with high performance in mind,
|
||||||
|
it uses [gin](https://github.com/gin-gonic/gin) which uses [httprouter](https://github.com/julienschmidt/httprouter) a lightweight high performance HTTP multiplexer.
|
||||||
|
|
||||||
Take a look at [ifconfig.es](https://ifconfig.es) a live site using `whatismyip`
|
Take a look at [ifconfig.es](https://ifconfig.es) a live site using `whatismyip`
|
||||||
|
|
||||||
@ -37,11 +39,13 @@ curl -6 ifconfig.es
|
|||||||
## Features
|
## Features
|
||||||
|
|
||||||
- TLS and HTTP/2.
|
- TLS and HTTP/2.
|
||||||
|
- Experimental HTTP/3 support. HTTP/3 requires a TLS server running (`-tls-bind`), as HTTP/3 starts as a TLS connection that then gets upgraded to UDP. The UDP port is the same as the one used for the TLS server.
|
||||||
- Can run behind a proxy by trusting a custom header (usually `X-Real-IP`) to figure out the source IP address. It also supports a custom header to resolve the client port, if the proxy can only add a header for the IP (for example a fixed header from CDNs) the client port is shown as unknown.
|
- Can run behind a proxy by trusting a custom header (usually `X-Real-IP`) to figure out the source IP address. It also supports a custom header to resolve the client port, if the proxy can only add a header for the IP (for example a fixed header from CDNs) the client port is shown as unknown.
|
||||||
- IPv4 and IPv6.
|
- IPv4 and IPv6.
|
||||||
- Geolocation info including ASN. This feature is possible thanks to [maxmind](https://dev.maxmind.com/geoip/geolite2-free-geolocation-data?lang=en) GeoLite2 databases. In order to use these databases, a license key is needed. Please visit Maxmind site for further instructions and get a free license.
|
- Geolocation info including ASN. This feature is possible thanks to [maxmind](https://dev.maxmind.com/geoip/geolite2-free-geolocation-data?lang=en) GeoLite2 databases. In order to use these databases, a license key is needed. Please visit Maxmind site for further instructions and get a free license.
|
||||||
|
- Checking TCP open ports.
|
||||||
- High performance.
|
- High performance.
|
||||||
- Self-contained server what can reload GeoLite2 databases and/or SSL certificates without stop/start. The `hup` signal is honored.
|
- Self-contained server that can reload GeoLite2 databases and/or SSL certificates without stop/start. The `hup` signal is honored.
|
||||||
- HTML templates for the landing page.
|
- HTML templates for the landing page.
|
||||||
- Text plain and JSON output.
|
- Text plain and JSON output.
|
||||||
|
|
||||||
@ -64,10 +68,11 @@ curl -6 ifconfig.es
|
|||||||
- https://ifconfig.es/all
|
- https://ifconfig.es/all
|
||||||
- https://ifconfig.es/headers
|
- https://ifconfig.es/headers
|
||||||
- https://ifconfig.es/<header_name>
|
- https://ifconfig.es/<header_name>
|
||||||
|
- https://ifconfig.es/scan/tcp/<port_number>
|
||||||
|
|
||||||
## Build
|
## Build
|
||||||
|
|
||||||
Golang >= 1.17 is required. Previous versions may work.
|
Golang >= 1.19 is required.
|
||||||
|
|
||||||
`make build`
|
`make build`
|
||||||
|
|
||||||
@ -77,6 +82,8 @@ Golang >= 1.17 is required. Previous versions may work.
|
|||||||
Usage of whatismyip:
|
Usage of whatismyip:
|
||||||
-bind string
|
-bind string
|
||||||
Listening address (see https://pkg.go.dev/net?#Listen) (default ":8080")
|
Listening address (see https://pkg.go.dev/net?#Listen) (default ":8080")
|
||||||
|
-enable-http3
|
||||||
|
Enable HTTP/3 protocol. HTTP/3 requires --tls-bind set, as HTTP/3 starts as a TLS connection that then gets upgraded to UDP. The UDP port is the same as the one used for the TLS server.
|
||||||
-enable-secure-headers
|
-enable-secure-headers
|
||||||
Add sane security-related headers to every response
|
Add sane security-related headers to every response
|
||||||
-geoip2-asn string
|
-geoip2-asn string
|
||||||
@ -114,6 +121,13 @@ Usage of whatismyip:
|
|||||||
-bind "" -tls-bind :8081 -tls-crt ./test/server.pem -tls-key ./test/server.key
|
-bind "" -tls-bind :8081 -tls-crt ./test/server.pem -tls-key ./test/server.key
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Run an HTTP/3 server
|
||||||
|
|
||||||
|
```bash
|
||||||
|
./whatismyip -geoip2-city ./test/GeoIP2-City-Test.mmdb -geoip2-asn ./test/GeoLite2-ASN-Test.mmdb \
|
||||||
|
-bind "" -tls-bind :8081 -tls-crt ./test/server.pem -tls-key ./test/server.key -enable-http3
|
||||||
|
```
|
||||||
|
|
||||||
### Run a default TCP server with a custom template and trust a pair of custom headers set by an upstream proxy
|
### Run a default TCP server with a custom template and trust a pair of custom headers set by an upstream proxy
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
@ -123,11 +137,11 @@ Usage of whatismyip:
|
|||||||
|
|
||||||
## Download
|
## Download
|
||||||
|
|
||||||
Download latest version from https://github.com/dcarrillo/whatismyip/releases
|
Download the latest version from https://github.com/dcarrillo/whatismyip/releases
|
||||||
|
|
||||||
## Docker
|
## Docker
|
||||||
|
|
||||||
An ultra-light (~10MB) image is available at [docker hub](https://hub.docker.com/r/dcarrillo/whatismyip).
|
An ultra-light (~4MB) image is available on [docker hub](https://hub.docker.com/r/dcarrillo/whatismyip). Since version `2.1.2`, the binary is compressed using [upx](https://github.com/upx/upx).
|
||||||
|
|
||||||
### Run a container locally using test databases
|
### Run a container locally using test databases
|
||||||
|
|
||||||
|
@ -2,142 +2,47 @@ package main
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"errors"
|
|
||||||
"flag"
|
"flag"
|
||||||
"fmt"
|
"fmt"
|
||||||
"log"
|
|
||||||
"net/http"
|
"net/http"
|
||||||
"os"
|
"os"
|
||||||
"os/signal"
|
|
||||||
"syscall"
|
|
||||||
|
|
||||||
"github.com/dcarrillo/whatismyip/internal/httputils"
|
"github.com/dcarrillo/whatismyip/internal/httputils"
|
||||||
"github.com/dcarrillo/whatismyip/internal/setting"
|
"github.com/dcarrillo/whatismyip/internal/setting"
|
||||||
|
"github.com/dcarrillo/whatismyip/server"
|
||||||
"github.com/gin-contrib/secure"
|
"github.com/gin-contrib/secure"
|
||||||
|
|
||||||
"github.com/dcarrillo/whatismyip/models"
|
"github.com/dcarrillo/whatismyip/models"
|
||||||
"github.com/dcarrillo/whatismyip/router"
|
"github.com/dcarrillo/whatismyip/router"
|
||||||
|
|
||||||
"github.com/gin-gonic/gin"
|
"github.com/gin-gonic/gin"
|
||||||
)
|
)
|
||||||
|
|
||||||
var (
|
|
||||||
tcpServer *http.Server
|
|
||||||
tlsServer *http.Server
|
|
||||||
engine *gin.Engine
|
|
||||||
)
|
|
||||||
|
|
||||||
func main() {
|
func main() {
|
||||||
o, err := setting.Setup(os.Args[1:])
|
o, err := setting.Setup(os.Args[1:])
|
||||||
if err == flag.ErrHelp || err == setting.ErrVersion {
|
if err == flag.ErrHelp || err == setting.ErrVersion {
|
||||||
fmt.Print(o)
|
fmt.Print(o)
|
||||||
os.Exit(0)
|
os.Exit(0)
|
||||||
} else if err != nil {
|
} else if err != nil {
|
||||||
fmt.Print(err)
|
fmt.Println(err)
|
||||||
os.Exit(1)
|
os.Exit(1)
|
||||||
}
|
}
|
||||||
|
|
||||||
models.Setup(setting.App.GeodbPath.City, setting.App.GeodbPath.ASN)
|
models.Setup(setting.App.GeodbPath.City, setting.App.GeodbPath.ASN)
|
||||||
setupEngine()
|
engine := setupEngine()
|
||||||
router.SetupTemplate(engine)
|
router.SetupTemplate(engine)
|
||||||
router.Setup(engine)
|
router.Setup(engine)
|
||||||
|
servers := setupHTTPServers(context.Background(), engine.Handler())
|
||||||
|
|
||||||
if setting.App.BindAddress != "" {
|
whatismyip := server.Setup(servers)
|
||||||
runTCPServer()
|
whatismyip.Run()
|
||||||
}
|
|
||||||
|
|
||||||
if setting.App.TLSAddress != "" {
|
|
||||||
runTLSServer()
|
|
||||||
}
|
|
||||||
|
|
||||||
runHandler()
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func runHandler() {
|
func setupEngine() *gin.Engine {
|
||||||
signalChan := make(chan os.Signal, 3)
|
|
||||||
signal.Notify(signalChan, syscall.SIGHUP, syscall.SIGINT, syscall.SIGTERM)
|
|
||||||
ctx := context.Background()
|
|
||||||
var s os.Signal
|
|
||||||
|
|
||||||
for {
|
|
||||||
s = <-signalChan
|
|
||||||
|
|
||||||
if s == syscall.SIGHUP {
|
|
||||||
models.CloseDBs()
|
|
||||||
models.Setup(setting.App.GeodbPath.City, setting.App.GeodbPath.ASN)
|
|
||||||
router.SetupTemplate(engine)
|
|
||||||
|
|
||||||
if setting.App.BindAddress != "" {
|
|
||||||
if err := tcpServer.Shutdown(ctx); err != nil {
|
|
||||||
log.Printf("TCP server forced to shutdown: %s", err)
|
|
||||||
}
|
|
||||||
runTCPServer()
|
|
||||||
}
|
|
||||||
if setting.App.TLSAddress != "" {
|
|
||||||
if err := tlsServer.Shutdown(ctx); err != nil {
|
|
||||||
log.Printf("TLS server forced to shutdown: %s", err)
|
|
||||||
}
|
|
||||||
runTLSServer()
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
log.Printf("Shutting down...")
|
|
||||||
if setting.App.BindAddress != "" {
|
|
||||||
if err := tcpServer.Shutdown(ctx); err != nil {
|
|
||||||
log.Printf("TCP server forced to shutdown: %s", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if setting.App.TLSAddress != "" {
|
|
||||||
if err := tlsServer.Shutdown(ctx); err != nil {
|
|
||||||
log.Printf("TLS server forced to shutdown: %s", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
models.CloseDBs()
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func runTCPServer() {
|
|
||||||
tcpServer = &http.Server{
|
|
||||||
Addr: setting.App.BindAddress,
|
|
||||||
Handler: engine,
|
|
||||||
ReadTimeout: setting.App.Server.ReadTimeout,
|
|
||||||
WriteTimeout: setting.App.Server.WriteTimeout,
|
|
||||||
}
|
|
||||||
|
|
||||||
go func() {
|
|
||||||
log.Printf("Starting TCP server listening on %s", setting.App.BindAddress)
|
|
||||||
if err := tcpServer.ListenAndServe(); err != nil && !errors.Is(err, http.ErrServerClosed) {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
log.Printf("Stopping TCP server...")
|
|
||||||
}()
|
|
||||||
}
|
|
||||||
|
|
||||||
func runTLSServer() {
|
|
||||||
tlsServer = &http.Server{
|
|
||||||
Addr: setting.App.TLSAddress,
|
|
||||||
Handler: engine,
|
|
||||||
ReadTimeout: setting.App.Server.ReadTimeout,
|
|
||||||
WriteTimeout: setting.App.Server.WriteTimeout,
|
|
||||||
}
|
|
||||||
|
|
||||||
go func() {
|
|
||||||
log.Printf("Starting TLS server listening on %s", setting.App.TLSAddress)
|
|
||||||
if err := tlsServer.ListenAndServeTLS(setting.App.TLSCrtPath, setting.App.TLSKeyPath); err != nil &&
|
|
||||||
!errors.Is(err, http.ErrServerClosed) {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
log.Printf("Stopping TLS server...")
|
|
||||||
}()
|
|
||||||
}
|
|
||||||
|
|
||||||
func setupEngine() {
|
|
||||||
gin.DisableConsoleColor()
|
gin.DisableConsoleColor()
|
||||||
if os.Getenv(gin.EnvGinMode) == "" {
|
if os.Getenv(gin.EnvGinMode) == "" {
|
||||||
gin.SetMode(gin.ReleaseMode)
|
gin.SetMode(gin.ReleaseMode)
|
||||||
}
|
}
|
||||||
engine = gin.New()
|
engine := gin.New()
|
||||||
engine.Use(gin.LoggerWithFormatter(httputils.GetLogFormatter))
|
engine.Use(gin.LoggerWithFormatter(httputils.GetLogFormatter))
|
||||||
engine.Use(gin.Recovery())
|
engine.Use(gin.Recovery())
|
||||||
if setting.App.EnableSecureHeaders {
|
if setting.App.EnableSecureHeaders {
|
||||||
@ -149,4 +54,26 @@ func setupEngine() {
|
|||||||
}
|
}
|
||||||
_ = engine.SetTrustedProxies(nil)
|
_ = engine.SetTrustedProxies(nil)
|
||||||
engine.TrustedPlatform = setting.App.TrustedHeader
|
engine.TrustedPlatform = setting.App.TrustedHeader
|
||||||
|
|
||||||
|
return engine
|
||||||
|
}
|
||||||
|
|
||||||
|
func setupHTTPServers(ctx context.Context, handler http.Handler) []server.Server {
|
||||||
|
var servers []server.Server
|
||||||
|
|
||||||
|
if setting.App.BindAddress != "" {
|
||||||
|
tcpServer := server.NewTCPServer(ctx, &handler)
|
||||||
|
servers = append(servers, tcpServer)
|
||||||
|
}
|
||||||
|
|
||||||
|
if setting.App.TLSAddress != "" {
|
||||||
|
tlsServer := server.NewTLSServer(ctx, &handler)
|
||||||
|
servers = append(servers, tlsServer)
|
||||||
|
if setting.App.EnableHTTP3 {
|
||||||
|
quicServer := server.NewQuicServer(ctx, tlsServer)
|
||||||
|
servers = append(servers, quicServer)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return servers
|
||||||
}
|
}
|
||||||
|
109
go.mod
109
go.mod
@ -1,63 +1,90 @@
|
|||||||
module github.com/dcarrillo/whatismyip
|
module github.com/dcarrillo/whatismyip
|
||||||
|
|
||||||
go 1.19
|
go 1.21.3
|
||||||
|
|
||||||
require (
|
require (
|
||||||
github.com/gin-contrib/secure v0.0.1
|
github.com/gin-contrib/secure v0.0.1
|
||||||
github.com/gin-gonic/gin v1.8.1
|
github.com/gin-gonic/gin v1.9.1
|
||||||
github.com/oschwald/maxminddb-golang v1.10.0
|
github.com/oschwald/maxminddb-golang v1.12.0
|
||||||
github.com/stretchr/testify v1.8.0
|
github.com/quic-go/quic-go v0.40.1
|
||||||
github.com/testcontainers/testcontainers-go v0.13.0
|
github.com/stretchr/testify v1.8.4
|
||||||
|
github.com/testcontainers/testcontainers-go v0.27.0
|
||||||
)
|
)
|
||||||
|
|
||||||
require (
|
require (
|
||||||
|
dario.cat/mergo v1.0.0 // indirect
|
||||||
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
|
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
|
||||||
github.com/Microsoft/go-winio v0.5.2 // indirect
|
github.com/Microsoft/go-winio v0.6.1 // indirect
|
||||||
github.com/Microsoft/hcsshim v0.9.4 // indirect
|
github.com/Microsoft/hcsshim v0.11.4 // indirect
|
||||||
github.com/cenkalti/backoff/v4 v4.1.3 // indirect
|
github.com/bytedance/sonic v1.10.2 // indirect
|
||||||
github.com/containerd/cgroups v1.0.4 // indirect
|
github.com/cenkalti/backoff/v4 v4.2.1 // indirect
|
||||||
github.com/containerd/containerd v1.6.8 // indirect
|
github.com/chenzhuoyu/base64x v0.0.0-20230717121745-296ad89f973d // indirect
|
||||||
github.com/containerd/continuity v0.3.0 // indirect
|
github.com/chenzhuoyu/iasm v0.9.1 // indirect
|
||||||
|
github.com/containerd/containerd v1.7.11 // indirect
|
||||||
|
github.com/containerd/log v0.1.0 // indirect
|
||||||
|
github.com/cpuguy83/dockercfg v0.3.1 // indirect
|
||||||
github.com/davecgh/go-spew v1.1.1 // indirect
|
github.com/davecgh/go-spew v1.1.1 // indirect
|
||||||
github.com/docker/distribution v2.8.1+incompatible // indirect
|
github.com/docker/distribution v2.8.2+incompatible // indirect
|
||||||
github.com/docker/docker v20.10.17+incompatible // indirect
|
github.com/docker/docker v24.0.9+incompatible // indirect
|
||||||
github.com/docker/go-connections v0.4.0 // indirect
|
github.com/docker/go-connections v0.4.0 // indirect
|
||||||
github.com/docker/go-units v0.4.0 // indirect
|
github.com/docker/go-units v0.5.0 // indirect
|
||||||
|
github.com/gabriel-vasile/mimetype v1.4.3 // indirect
|
||||||
github.com/gin-contrib/sse v0.1.0 // indirect
|
github.com/gin-contrib/sse v0.1.0 // indirect
|
||||||
github.com/go-playground/locales v0.14.0 // indirect
|
github.com/go-ole/go-ole v1.2.6 // indirect
|
||||||
github.com/go-playground/universal-translator v0.18.0 // indirect
|
github.com/go-playground/locales v0.14.1 // indirect
|
||||||
github.com/go-playground/validator/v10 v10.11.0 // indirect
|
github.com/go-playground/universal-translator v0.18.1 // indirect
|
||||||
github.com/goccy/go-json v0.9.11 // indirect
|
github.com/go-playground/validator/v10 v10.16.0 // indirect
|
||||||
|
github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572 // indirect
|
||||||
|
github.com/goccy/go-json v0.10.2 // indirect
|
||||||
github.com/gogo/protobuf v1.3.2 // indirect
|
github.com/gogo/protobuf v1.3.2 // indirect
|
||||||
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
|
github.com/golang/protobuf v1.5.3 // indirect
|
||||||
github.com/golang/protobuf v1.5.2 // indirect
|
github.com/google/pprof v0.0.0-20231229205709-960ae82b1e42 // indirect
|
||||||
github.com/google/uuid v1.3.0 // indirect
|
github.com/google/uuid v1.4.0 // indirect
|
||||||
github.com/json-iterator/go v1.1.12 // indirect
|
github.com/json-iterator/go v1.1.12 // indirect
|
||||||
github.com/leodido/go-urn v1.2.1 // indirect
|
github.com/klauspost/compress v1.16.5 // indirect
|
||||||
github.com/magiconair/properties v1.8.6 // indirect
|
github.com/klauspost/cpuid/v2 v2.2.6 // indirect
|
||||||
github.com/mattn/go-isatty v0.0.16 // indirect
|
github.com/kr/pretty v0.3.1 // indirect
|
||||||
github.com/moby/sys/mount v0.3.3 // indirect
|
github.com/leodido/go-urn v1.2.4 // indirect
|
||||||
github.com/moby/sys/mountinfo v0.6.2 // indirect
|
github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0 // indirect
|
||||||
github.com/moby/term v0.0.0-20220808134915-39b0c02b01ae // indirect
|
github.com/magiconair/properties v1.8.7 // indirect
|
||||||
|
github.com/mattn/go-isatty v0.0.20 // indirect
|
||||||
|
github.com/moby/patternmatcher v0.6.0 // indirect
|
||||||
|
github.com/moby/sys/sequential v0.5.0 // indirect
|
||||||
|
github.com/moby/term v0.5.0 // indirect
|
||||||
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
|
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
|
||||||
github.com/modern-go/reflect2 v1.0.2 // indirect
|
github.com/modern-go/reflect2 v1.0.2 // indirect
|
||||||
github.com/morikuni/aec v1.0.0 // indirect
|
github.com/morikuni/aec v1.0.0 // indirect
|
||||||
|
github.com/onsi/ginkgo/v2 v2.13.2 // indirect
|
||||||
github.com/opencontainers/go-digest v1.0.0 // indirect
|
github.com/opencontainers/go-digest v1.0.0 // indirect
|
||||||
github.com/opencontainers/image-spec v1.0.3-0.20211202183452-c5a74bcca799 // indirect
|
github.com/opencontainers/image-spec v1.1.0-rc5 // indirect
|
||||||
github.com/opencontainers/runc v1.1.3 // indirect
|
github.com/opencontainers/runc v1.1.12 // indirect
|
||||||
github.com/pelletier/go-toml/v2 v2.0.5 // indirect
|
github.com/pelletier/go-toml/v2 v2.1.1 // indirect
|
||||||
github.com/pkg/errors v0.9.1 // indirect
|
github.com/pkg/errors v0.9.1 // indirect
|
||||||
github.com/pmezard/go-difflib v1.0.0 // indirect
|
github.com/pmezard/go-difflib v1.0.0 // indirect
|
||||||
github.com/sirupsen/logrus v1.9.0 // indirect
|
github.com/power-devops/perfstat v0.0.0-20210106213030-5aafc221ea8c // indirect
|
||||||
github.com/ugorji/go/codec v1.2.7 // indirect
|
github.com/quic-go/qpack v0.4.0 // indirect
|
||||||
go.opencensus.io v0.23.0 // indirect
|
github.com/quic-go/qtls-go1-20 v0.4.1 // indirect
|
||||||
golang.org/x/crypto v0.0.0-20220829220503-c86fa9a7ed90 // indirect
|
github.com/rogpeppe/go-internal v1.10.0 // indirect
|
||||||
golang.org/x/net v0.0.0-20220909164309-bea034e7d591 // indirect
|
github.com/shirou/gopsutil/v3 v3.23.11 // indirect
|
||||||
golang.org/x/sys v0.0.0-20220913175220-63ea55921009 // indirect
|
github.com/shoenig/go-m1cpu v0.1.6 // indirect
|
||||||
golang.org/x/text v0.3.7 // indirect
|
github.com/sirupsen/logrus v1.9.3 // indirect
|
||||||
google.golang.org/genproto v0.0.0-20220810155839-1856144b1d9c // indirect
|
github.com/tklauser/go-sysconf v0.3.12 // indirect
|
||||||
google.golang.org/grpc v1.48.0 // indirect
|
github.com/tklauser/numcpus v0.6.1 // indirect
|
||||||
google.golang.org/protobuf v1.28.1 // indirect
|
github.com/twitchyliquid64/golang-asm v0.15.1 // indirect
|
||||||
gopkg.in/yaml.v2 v2.4.0 // indirect
|
github.com/ugorji/go/codec v1.2.12 // indirect
|
||||||
|
github.com/yusufpapurcu/wmi v1.2.3 // indirect
|
||||||
|
go.uber.org/mock v0.4.0 // indirect
|
||||||
|
golang.org/x/arch v0.6.0 // indirect
|
||||||
|
golang.org/x/crypto v0.18.0 // indirect
|
||||||
|
golang.org/x/exp v0.0.0-20231226003508-02704c960a9b // indirect
|
||||||
|
golang.org/x/mod v0.14.0 // indirect
|
||||||
|
golang.org/x/net v0.20.0 // indirect
|
||||||
|
golang.org/x/sys v0.16.0 // indirect
|
||||||
|
golang.org/x/text v0.14.0 // indirect
|
||||||
|
golang.org/x/tools v0.17.0 // indirect
|
||||||
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20230822172742-b8732ec3820d // indirect
|
||||||
|
google.golang.org/grpc v1.59.0 // indirect
|
||||||
|
google.golang.org/protobuf v1.33.0 // indirect
|
||||||
gopkg.in/yaml.v3 v3.0.1 // indirect
|
gopkg.in/yaml.v3 v3.0.1 // indirect
|
||||||
|
gotest.tools/v3 v3.5.1 // indirect
|
||||||
)
|
)
|
||||||
|
@ -4,14 +4,17 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"crypto/tls"
|
"crypto/tls"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"log"
|
|
||||||
"net/http"
|
"net/http"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"runtime"
|
"runtime"
|
||||||
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
"github.com/dcarrillo/whatismyip/router"
|
"github.com/dcarrillo/whatismyip/router"
|
||||||
|
"github.com/quic-go/quic-go"
|
||||||
|
"github.com/quic-go/quic-go/http3"
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
"github.com/testcontainers/testcontainers-go"
|
"github.com/testcontainers/testcontainers-go"
|
||||||
"github.com/testcontainers/testcontainers-go/wait"
|
"github.com/testcontainers/testcontainers-go/wait"
|
||||||
@ -27,70 +30,178 @@ func buildContainer() testcontainers.ContainerRequest {
|
|||||||
Dockerfile: "Dockerfile",
|
Dockerfile: "Dockerfile",
|
||||||
},
|
},
|
||||||
Cmd: []string{
|
Cmd: []string{
|
||||||
"-geoip2-city", "/tmp/GeoIP2-City-Test.mmdb",
|
"-geoip2-city", "/GeoIP2-City-Test.mmdb",
|
||||||
"-geoip2-asn", "/tmp/GeoLite2-ASN-Test.mmdb",
|
"-geoip2-asn", "/GeoLite2-ASN-Test.mmdb",
|
||||||
"-bind", ":8000",
|
"-bind", ":8000",
|
||||||
"-tls-bind", ":8001",
|
"-tls-bind", ":8001",
|
||||||
"-tls-crt", "/tmp/server.pem",
|
"-tls-crt", "/server.pem",
|
||||||
"-tls-key", "/tmp/server.key",
|
"-tls-key", "/server.key",
|
||||||
"-trusted-header", "X-Real-IP",
|
"-trusted-header", "X-Real-IP",
|
||||||
"-enable-secure-headers",
|
"-enable-secure-headers",
|
||||||
|
"-enable-http3",
|
||||||
|
},
|
||||||
|
ExposedPorts: []string{"8000:8000", "8001:8001", "8001:8001/udp"},
|
||||||
|
WaitingFor: wait.ForHTTP("/geo").
|
||||||
|
WithTLS(true, &tls.Config{InsecureSkipVerify: true}).
|
||||||
|
WithPort("8001"),
|
||||||
|
Files: []testcontainers.ContainerFile{
|
||||||
|
{
|
||||||
|
HostFilePath: filepath.Join(dir, "/../test/GeoIP2-City-Test.mmdb"),
|
||||||
|
ContainerFilePath: "/GeoIP2-City-Test.mmdb",
|
||||||
|
FileMode: 0644,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
HostFilePath: filepath.Join(dir, "/../test/GeoLite2-ASN-Test.mmdb"),
|
||||||
|
ContainerFilePath: "/GeoLite2-ASN-Test.mmdb",
|
||||||
|
FileMode: 0644,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
HostFilePath: filepath.Join(dir, "/../test/server.pem"),
|
||||||
|
ContainerFilePath: "/server.pem",
|
||||||
|
FileMode: 0644,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
HostFilePath: filepath.Join(dir, "/../test/server.key"),
|
||||||
|
ContainerFilePath: "/server.key",
|
||||||
|
FileMode: 0644,
|
||||||
|
},
|
||||||
},
|
},
|
||||||
ExposedPorts: []string{"8000:8000", "8001:8001"},
|
|
||||||
WaitingFor: wait.ForLog("Starting TLS server listening on :8001"),
|
|
||||||
Mounts: testcontainers.Mounts(
|
|
||||||
testcontainers.BindMount(
|
|
||||||
filepath.Join(dir, "/../test/GeoIP2-City-Test.mmdb"),
|
|
||||||
"/tmp/GeoIP2-City-Test.mmdb",
|
|
||||||
),
|
|
||||||
testcontainers.BindMount(
|
|
||||||
filepath.Join(dir, "/../test/GeoLite2-ASN-Test.mmdb"),
|
|
||||||
"/tmp/GeoLite2-ASN-Test.mmdb",
|
|
||||||
),
|
|
||||||
testcontainers.BindMount(filepath.Join(dir, "/../test/server.pem"), "/tmp/server.pem"),
|
|
||||||
testcontainers.BindMount(filepath.Join(dir, "/../test/server.key"), "/tmp/server.key"),
|
|
||||||
),
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return req
|
return req
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func initContainer(t assert.TestingT, request testcontainers.ContainerRequest) func() {
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
container, err := testcontainers.GenericContainer(ctx, testcontainers.GenericContainerRequest{
|
||||||
|
ContainerRequest: request,
|
||||||
|
Started: true,
|
||||||
|
})
|
||||||
|
assert.NoError(t, err)
|
||||||
|
|
||||||
|
return func() {
|
||||||
|
assert.NoError(t, container.Terminate(ctx))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestContainerIntegration(t *testing.T) {
|
func TestContainerIntegration(t *testing.T) {
|
||||||
if testing.Short() {
|
if testing.Short() {
|
||||||
t.Skip("Skiping integration tests")
|
t.Skip("Skiping integration tests")
|
||||||
}
|
}
|
||||||
|
|
||||||
ctx := context.Background()
|
t.Cleanup(initContainer(t, buildContainer()))
|
||||||
container, err := testcontainers.GenericContainer(ctx, testcontainers.GenericContainerRequest{
|
|
||||||
ContainerRequest: buildContainer(),
|
|
||||||
Started: true,
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
defer func() {
|
|
||||||
err := container.Terminate(ctx)
|
|
||||||
if err != nil {
|
|
||||||
log.Fatal(err)
|
|
||||||
}
|
|
||||||
}()
|
|
||||||
|
|
||||||
http.DefaultTransport.(*http.Transport).TLSClientConfig = &tls.Config{InsecureSkipVerify: true}
|
http.DefaultTransport.(*http.Transport).TLSClientConfig = &tls.Config{InsecureSkipVerify: true}
|
||||||
for _, url := range []string{"http://localhost:8000", "https://localhost:8001"} {
|
tests := []struct {
|
||||||
client := &http.Client{}
|
name string
|
||||||
req, _ := http.NewRequest("GET", url, nil)
|
url string
|
||||||
req.Header.Set("Accept", "application/json")
|
quic bool
|
||||||
resp, _ := client.Do(req)
|
}{
|
||||||
assert.Equal(t, 200, resp.StatusCode)
|
{
|
||||||
|
name: "RequestOverHTTP",
|
||||||
body, err := io.ReadAll(resp.Body)
|
url: "http://localhost:8000",
|
||||||
if err != nil {
|
quic: false,
|
||||||
log.Fatal(err)
|
},
|
||||||
|
{
|
||||||
|
name: "RequestOverHTTPs",
|
||||||
|
url: "https://localhost:8001",
|
||||||
|
quic: false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "RequestOverUDPWithQuic",
|
||||||
|
url: "https://localhost:8001",
|
||||||
|
quic: true,
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
|
testsPortScan := []struct {
|
||||||
|
name string
|
||||||
|
port int
|
||||||
|
want bool
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "RequestOpenPortScan",
|
||||||
|
port: 8000,
|
||||||
|
want: true,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "RequestClosedPortScan",
|
||||||
|
port: 65533,
|
||||||
|
want: false,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
req, err := http.NewRequest("GET", tt.url, nil)
|
||||||
|
assert.NoError(t, err)
|
||||||
|
req.Header.Set("Accept", "application/json")
|
||||||
|
|
||||||
|
var resp *http.Response
|
||||||
|
var body []byte
|
||||||
|
if tt.quic {
|
||||||
|
resp, body, err = doQuicRequest(req)
|
||||||
|
} else {
|
||||||
|
client := &http.Client{}
|
||||||
|
resp, _ = client.Do(req)
|
||||||
|
body, err = io.ReadAll(resp.Body)
|
||||||
|
if strings.Contains(tt.url, "https://") {
|
||||||
|
assert.Equal(t, `h3=":8001"; ma=2592000`, resp.Header.Get("Alt-Svc"))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
assert.NoError(t, err)
|
||||||
|
assert.Equal(t, 200, resp.StatusCode)
|
||||||
|
|
||||||
assert.NoError(t, json.Unmarshal(body, &router.JSONResponse{}))
|
assert.NoError(t, json.Unmarshal(body, &router.JSONResponse{}))
|
||||||
assert.Equal(t, "DENY", resp.Header.Get("X-Frame-Options"))
|
assert.Equal(t, "DENY", resp.Header.Get("X-Frame-Options"))
|
||||||
assert.Equal(t, "nosniff", resp.Header.Get("X-Content-Type-Options"))
|
assert.Equal(t, "nosniff", resp.Header.Get("X-Content-Type-Options"))
|
||||||
assert.Equal(t, "1; mode=block", resp.Header.Get("X-Xss-Protection"))
|
assert.Equal(t, "1; mode=block", resp.Header.Get("X-Xss-Protection"))
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range testsPortScan {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
req, err := http.NewRequest("GET", fmt.Sprintf("http://localhost:8000/scan/tcp/%d", tt.port), nil)
|
||||||
|
assert.NoError(t, err)
|
||||||
|
req.Header.Set("Accept", "application/json")
|
||||||
|
req.Header.Set("X-Real-IP", "127.0.0.1")
|
||||||
|
|
||||||
|
client := &http.Client{}
|
||||||
|
resp, err := client.Do(req)
|
||||||
|
assert.NoError(t, err)
|
||||||
|
assert.Equal(t, 200, resp.StatusCode)
|
||||||
|
|
||||||
|
body, err := io.ReadAll(resp.Body)
|
||||||
|
assert.NoError(t, err)
|
||||||
|
j := router.JSONScanResponse{}
|
||||||
|
assert.NoError(t, json.Unmarshal(body, &j))
|
||||||
|
assert.Equal(t, tt.want, j.Reachable)
|
||||||
|
})
|
||||||
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func doQuicRequest(req *http.Request) (*http.Response, []byte, error) {
|
||||||
|
roundTripper := &http3.RoundTripper{
|
||||||
|
TLSClientConfig: &tls.Config{
|
||||||
|
InsecureSkipVerify: true,
|
||||||
|
},
|
||||||
|
QuicConfig: &quic.Config{},
|
||||||
|
}
|
||||||
|
defer roundTripper.Close()
|
||||||
|
|
||||||
|
client := &http.Client{
|
||||||
|
Transport: roundTripper,
|
||||||
|
}
|
||||||
|
|
||||||
|
resp, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return nil, nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
defer resp.Body.Close()
|
||||||
|
body, _ := io.ReadAll(resp.Body)
|
||||||
|
|
||||||
|
return resp, body, nil
|
||||||
|
}
|
||||||
|
@ -63,7 +63,7 @@ func GetLogFormatter(param gin.LogFormatterParams) string {
|
|||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
func normalizeLog(log interface{}) interface{} {
|
func normalizeLog(log any) any {
|
||||||
switch v := log.(type) {
|
switch v := log.(type) {
|
||||||
case string:
|
case string:
|
||||||
if v == "" {
|
if v == "" {
|
||||||
|
@ -29,6 +29,7 @@ type settings struct {
|
|||||||
TrustedHeader string
|
TrustedHeader string
|
||||||
TrustedPortHeader string
|
TrustedPortHeader string
|
||||||
EnableSecureHeaders bool
|
EnableSecureHeaders bool
|
||||||
|
EnableHTTP3 bool
|
||||||
Server serverSettings
|
Server serverSettings
|
||||||
version bool
|
version bool
|
||||||
}
|
}
|
||||||
@ -89,6 +90,12 @@ func Setup(args []string) (output string, err error) {
|
|||||||
false,
|
false,
|
||||||
"Add sane security-related headers to every response",
|
"Add sane security-related headers to every response",
|
||||||
)
|
)
|
||||||
|
flags.BoolVar(
|
||||||
|
&App.EnableHTTP3,
|
||||||
|
"enable-http3",
|
||||||
|
false,
|
||||||
|
"Enable HTTP/3 protocol. HTTP/3 requires --tls-bind set, as HTTP/3 starts as a TLS connection that then gets upgraded to UDP. The UDP port is the same as the one used for the TLS server.",
|
||||||
|
)
|
||||||
|
|
||||||
err = flags.Parse(args)
|
err = flags.Parse(args)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@ -100,24 +107,28 @@ func Setup(args []string) (output string, err error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if App.TrustedPortHeader != "" && App.TrustedHeader == "" {
|
if App.TrustedPortHeader != "" && App.TrustedHeader == "" {
|
||||||
return "", fmt.Errorf("truster-header is mandatory when truster-port-header is set\n")
|
return "", fmt.Errorf("truster-header is mandatory when truster-port-header is set")
|
||||||
}
|
}
|
||||||
|
|
||||||
if App.GeodbPath.City == "" || App.GeodbPath.ASN == "" {
|
if App.GeodbPath.City == "" || App.GeodbPath.ASN == "" {
|
||||||
return "", fmt.Errorf("geoip2-city and geoip2-asn parameters are mandatory\n")
|
return "", fmt.Errorf("geoip2-city and geoip2-asn parameters are mandatory")
|
||||||
}
|
}
|
||||||
|
|
||||||
if (App.TLSAddress != "") && (App.TLSCrtPath == "" || App.TLSKeyPath == "") {
|
if (App.TLSAddress != "") && (App.TLSCrtPath == "" || App.TLSKeyPath == "") {
|
||||||
return "", fmt.Errorf("In order to use TLS -tls-crt and -tls-key flags are mandatory\n")
|
return "", fmt.Errorf("in order to use TLS, the -tls-crt and -tls-key flags are mandatory")
|
||||||
|
}
|
||||||
|
|
||||||
|
if App.EnableHTTP3 && App.TLSAddress == "" {
|
||||||
|
return "", fmt.Errorf("in order to use HTTP3, the -tls-bind is mandatory")
|
||||||
}
|
}
|
||||||
|
|
||||||
if App.TemplatePath != "" {
|
if App.TemplatePath != "" {
|
||||||
info, err := os.Stat(App.TemplatePath)
|
info, err := os.Stat(App.TemplatePath)
|
||||||
if os.IsNotExist(err) {
|
if os.IsNotExist(err) {
|
||||||
return "", fmt.Errorf("%s no such file or directory\n", App.TemplatePath)
|
return "", fmt.Errorf("%s no such file or directory", App.TemplatePath)
|
||||||
}
|
}
|
||||||
if info.IsDir() {
|
if info.IsDir() {
|
||||||
return "", fmt.Errorf("%s must be a file\n", App.TemplatePath)
|
return "", fmt.Errorf("%s must be a file", App.TemplatePath)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -41,6 +41,11 @@ func TestParseMandatoryFlags(t *testing.T) {
|
|||||||
"-tls-key", "/key-path",
|
"-tls-key", "/key-path",
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
[]string{
|
||||||
|
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path", "-enable-http3",
|
||||||
|
},
|
||||||
|
},
|
||||||
{
|
{
|
||||||
[]string{
|
[]string{
|
||||||
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path", "-bind", ":8000",
|
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path", "-bind", ":8000",
|
||||||
|
@ -68,18 +68,10 @@ func CloseDBs() {
|
|||||||
|
|
||||||
// LookUp an IP and get city data
|
// LookUp an IP and get city data
|
||||||
func (record *GeoRecord) LookUp(ip net.IP) error {
|
func (record *GeoRecord) LookUp(ip net.IP) error {
|
||||||
if err := db.city.Lookup(ip, record); err != nil {
|
return db.city.Lookup(ip, record)
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// LookUp an IP and get ASN data
|
// LookUp an IP and get ASN data
|
||||||
func (record *ASNRecord) LookUp(ip net.IP) error {
|
func (record *ASNRecord) LookUp(ip net.IP) error {
|
||||||
if err := db.asn.Lookup(ip, record); err != nil {
|
return db.asn.Lookup(ip, record)
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
}
|
||||||
|
54
router/port_scanner.go
Normal file
54
router/port_scanner.go
Normal file
@ -0,0 +1,54 @@
|
|||||||
|
package router
|
||||||
|
|
||||||
|
import (
|
||||||
|
"fmt"
|
||||||
|
"net"
|
||||||
|
"net/http"
|
||||||
|
"strconv"
|
||||||
|
|
||||||
|
"github.com/dcarrillo/whatismyip/service"
|
||||||
|
"github.com/gin-gonic/gin"
|
||||||
|
)
|
||||||
|
|
||||||
|
type JSONScanResponse struct {
|
||||||
|
IP string `json:"ip"`
|
||||||
|
Port int `json:"port"`
|
||||||
|
Reachable bool `json:"reachable"`
|
||||||
|
Reason string `json:"reason"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func scanTCPPort(ctx *gin.Context) {
|
||||||
|
port, err := strconv.Atoi(ctx.Params.ByName("port"))
|
||||||
|
if err == nil && (port < 1 || port > 65535) {
|
||||||
|
err = fmt.Errorf("%d is not a valid port number", port)
|
||||||
|
}
|
||||||
|
if err != nil {
|
||||||
|
ctx.JSON(http.StatusBadRequest, JSONScanResponse{
|
||||||
|
Reason: err.Error(),
|
||||||
|
})
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
add := net.TCPAddr{
|
||||||
|
IP: net.ParseIP(ctx.ClientIP()),
|
||||||
|
Port: port,
|
||||||
|
}
|
||||||
|
|
||||||
|
scan := service.PortScanner{
|
||||||
|
Address: &add,
|
||||||
|
}
|
||||||
|
|
||||||
|
isOpen, err := scan.IsPortOpen()
|
||||||
|
reason := ""
|
||||||
|
if err != nil {
|
||||||
|
reason = err.Error()
|
||||||
|
}
|
||||||
|
|
||||||
|
response := JSONScanResponse{
|
||||||
|
IP: ctx.ClientIP(),
|
||||||
|
Port: port,
|
||||||
|
Reachable: isOpen,
|
||||||
|
Reason: reason,
|
||||||
|
}
|
||||||
|
ctx.JSON(http.StatusOK, response)
|
||||||
|
}
|
@ -22,6 +22,7 @@ func SetupTemplate(r *gin.Engine) {
|
|||||||
// Setup defines the endpoints
|
// Setup defines the endpoints
|
||||||
func Setup(r *gin.Engine) {
|
func Setup(r *gin.Engine) {
|
||||||
r.GET("/", getRoot)
|
r.GET("/", getRoot)
|
||||||
|
r.GET("/scan/tcp/:port", scanTCPPort)
|
||||||
r.GET("/client-port", getClientPortAsString)
|
r.GET("/client-port", getClientPortAsString)
|
||||||
r.GET("/geo", getGeoAsString)
|
r.GET("/geo", getGeoAsString)
|
||||||
r.GET("/geo/:field", getGeoAsString)
|
r.GET("/geo/:field", getGeoAsString)
|
||||||
|
55
server/quic.go
Normal file
55
server/quic.go
Normal file
@ -0,0 +1,55 @@
|
|||||||
|
package server
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"log"
|
||||||
|
"net/http"
|
||||||
|
|
||||||
|
"github.com/dcarrillo/whatismyip/internal/setting"
|
||||||
|
"github.com/quic-go/quic-go/http3"
|
||||||
|
)
|
||||||
|
|
||||||
|
type Quic struct {
|
||||||
|
server *http3.Server
|
||||||
|
tlsServer *TLS
|
||||||
|
ctx context.Context
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewQuicServer(ctx context.Context, tlsServer *TLS) *Quic {
|
||||||
|
return &Quic{
|
||||||
|
tlsServer: tlsServer,
|
||||||
|
ctx: ctx,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (q *Quic) Start() {
|
||||||
|
q.server = &http3.Server{
|
||||||
|
Addr: setting.App.TLSAddress,
|
||||||
|
Handler: q.tlsServer.server.Handler,
|
||||||
|
}
|
||||||
|
|
||||||
|
parentHandler := q.tlsServer.server.Handler
|
||||||
|
q.tlsServer.server.Handler = http.HandlerFunc(func(rw http.ResponseWriter, req *http.Request) {
|
||||||
|
if err := q.server.SetQuicHeaders(rw.Header()); err != nil {
|
||||||
|
log.Fatal(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
parentHandler.ServeHTTP(rw, req)
|
||||||
|
})
|
||||||
|
|
||||||
|
log.Printf("Starting QUIC server listening on %s (udp)", setting.App.TLSAddress)
|
||||||
|
go func() {
|
||||||
|
if err := q.server.ListenAndServeTLS(setting.App.TLSCrtPath, setting.App.TLSKeyPath); err != nil &&
|
||||||
|
!errors.Is(err, http.ErrServerClosed) {
|
||||||
|
log.Fatal(err)
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
}
|
||||||
|
|
||||||
|
func (q *Quic) Stop() {
|
||||||
|
log.Printf("Stopping QUIC server...")
|
||||||
|
if err := q.server.Close(); err != nil {
|
||||||
|
log.Printf("QUIC server forced to shutdown")
|
||||||
|
}
|
||||||
|
}
|
61
server/server.go
Normal file
61
server/server.go
Normal file
@ -0,0 +1,61 @@
|
|||||||
|
package server
|
||||||
|
|
||||||
|
import (
|
||||||
|
"log"
|
||||||
|
"os"
|
||||||
|
"os/signal"
|
||||||
|
"syscall"
|
||||||
|
|
||||||
|
"github.com/dcarrillo/whatismyip/internal/setting"
|
||||||
|
"github.com/dcarrillo/whatismyip/models"
|
||||||
|
)
|
||||||
|
|
||||||
|
type Server interface {
|
||||||
|
Start()
|
||||||
|
Stop()
|
||||||
|
}
|
||||||
|
|
||||||
|
type Manager struct {
|
||||||
|
servers []Server
|
||||||
|
}
|
||||||
|
|
||||||
|
func Setup(servers []Server) *Manager {
|
||||||
|
return &Manager{
|
||||||
|
servers: servers,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (m *Manager) Run() {
|
||||||
|
m.start()
|
||||||
|
|
||||||
|
signalChan := make(chan os.Signal, len(m.servers))
|
||||||
|
signal.Notify(signalChan, syscall.SIGHUP, syscall.SIGINT, syscall.SIGTERM)
|
||||||
|
var s os.Signal
|
||||||
|
for {
|
||||||
|
s = <-signalChan
|
||||||
|
|
||||||
|
if s == syscall.SIGHUP {
|
||||||
|
m.stop()
|
||||||
|
models.CloseDBs()
|
||||||
|
models.Setup(setting.App.GeodbPath.City, setting.App.GeodbPath.ASN)
|
||||||
|
m.start()
|
||||||
|
} else {
|
||||||
|
log.Printf("Shutting down...")
|
||||||
|
m.stop()
|
||||||
|
models.CloseDBs()
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (m *Manager) start() {
|
||||||
|
for _, s := range m.servers {
|
||||||
|
s.Start()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (m *Manager) stop() {
|
||||||
|
for _, s := range m.servers {
|
||||||
|
s.Stop()
|
||||||
|
}
|
||||||
|
}
|
46
server/tcp.go
Normal file
46
server/tcp.go
Normal file
@ -0,0 +1,46 @@
|
|||||||
|
package server
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"log"
|
||||||
|
"net/http"
|
||||||
|
|
||||||
|
"github.com/dcarrillo/whatismyip/internal/setting"
|
||||||
|
)
|
||||||
|
|
||||||
|
type TCP struct {
|
||||||
|
server *http.Server
|
||||||
|
handler *http.Handler
|
||||||
|
ctx context.Context
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewTCPServer(ctx context.Context, handler *http.Handler) *TCP {
|
||||||
|
return &TCP{
|
||||||
|
handler: handler,
|
||||||
|
ctx: ctx,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *TCP) Start() {
|
||||||
|
t.server = &http.Server{
|
||||||
|
Addr: setting.App.BindAddress,
|
||||||
|
Handler: *t.handler,
|
||||||
|
ReadTimeout: setting.App.Server.ReadTimeout,
|
||||||
|
WriteTimeout: setting.App.Server.WriteTimeout,
|
||||||
|
}
|
||||||
|
|
||||||
|
log.Printf("Starting TCP server listening on %s", setting.App.BindAddress)
|
||||||
|
go func() {
|
||||||
|
if err := t.server.ListenAndServe(); err != nil && !errors.Is(err, http.ErrServerClosed) {
|
||||||
|
log.Fatal(err)
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *TCP) Stop() {
|
||||||
|
log.Printf("Stopping TCP server...")
|
||||||
|
if err := t.server.Shutdown(t.ctx); err != nil {
|
||||||
|
log.Printf("TCP server forced to shutdown: %s", err)
|
||||||
|
}
|
||||||
|
}
|
47
server/tls.go
Normal file
47
server/tls.go
Normal file
@ -0,0 +1,47 @@
|
|||||||
|
package server
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"log"
|
||||||
|
"net/http"
|
||||||
|
|
||||||
|
"github.com/dcarrillo/whatismyip/internal/setting"
|
||||||
|
)
|
||||||
|
|
||||||
|
type TLS struct {
|
||||||
|
server *http.Server
|
||||||
|
handler *http.Handler
|
||||||
|
ctx context.Context
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewTLSServer(ctx context.Context, handler *http.Handler) *TLS {
|
||||||
|
return &TLS{
|
||||||
|
handler: handler,
|
||||||
|
ctx: ctx,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *TLS) Start() {
|
||||||
|
t.server = &http.Server{
|
||||||
|
Addr: setting.App.TLSAddress,
|
||||||
|
Handler: *t.handler,
|
||||||
|
ReadTimeout: setting.App.Server.ReadTimeout,
|
||||||
|
WriteTimeout: setting.App.Server.WriteTimeout,
|
||||||
|
}
|
||||||
|
|
||||||
|
log.Printf("Starting TLS server listening on %s", setting.App.TLSAddress)
|
||||||
|
go func() {
|
||||||
|
if err := t.server.ListenAndServeTLS(setting.App.TLSCrtPath, setting.App.TLSKeyPath); err != nil &&
|
||||||
|
!errors.Is(err, http.ErrServerClosed) {
|
||||||
|
log.Fatal(err)
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
}
|
||||||
|
|
||||||
|
func (t *TLS) Stop() {
|
||||||
|
log.Printf("Stopping TLS server...")
|
||||||
|
if err := t.server.Shutdown(t.ctx); err != nil {
|
||||||
|
log.Printf("TLS server forced to shutdown: %s", err)
|
||||||
|
}
|
||||||
|
}
|
24
service/port_scanner.go
Normal file
24
service/port_scanner.go
Normal file
@ -0,0 +1,24 @@
|
|||||||
|
package service
|
||||||
|
|
||||||
|
import (
|
||||||
|
"net"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
const scannerTimeOut = 3 * time.Second
|
||||||
|
|
||||||
|
type PortScanner struct {
|
||||||
|
Address net.Addr
|
||||||
|
}
|
||||||
|
|
||||||
|
func (p *PortScanner) IsPortOpen() (bool, error) {
|
||||||
|
conn, err := net.DialTimeout(p.Address.Network(), p.Address.String(), scannerTimeOut)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
if conn != nil {
|
||||||
|
defer conn.Close()
|
||||||
|
}
|
||||||
|
|
||||||
|
return true, nil
|
||||||
|
}
|
Reference in New Issue
Block a user