mirror of
https://github.com/dcarrillo/whatismyip.git
synced 2025-07-06 17:09:24 +00:00
Compare commits
15 Commits
Author | SHA1 | Date | |
---|---|---|---|
ed0ddccab5
|
|||
20ae50c115
|
|||
9763ed0e29
|
|||
88691a5149
|
|||
6b7fc0bc6a
|
|||
c5a659ff64 | |||
bd06da7b2b
|
|||
b61d64a755
|
|||
3df794ecc4
|
|||
ca1d002974
|
|||
1ee7256506
|
|||
7c70abf07f
|
|||
9070e9a2c2
|
|||
12da27ddab
|
|||
aae2e08240
|
50
.github/workflows/codeql-analysis.yml
vendored
Normal file
50
.github/workflows/codeql-analysis.yml
vendored
Normal file
@ -0,0 +1,50 @@
|
|||||||
|
# For most projects, this workflow file will not need changing; you simply need
|
||||||
|
# to commit it to your repository.
|
||||||
|
#
|
||||||
|
# You may wish to alter this file to override the set of languages analyzed,
|
||||||
|
# or to provide custom queries or build logic.
|
||||||
|
#
|
||||||
|
# ******** NOTE ********
|
||||||
|
# We have attempted to detect the languages in your repository. Please check
|
||||||
|
# the `language` matrix defined below to confirm you have the correct set of
|
||||||
|
# supported CodeQL languages.
|
||||||
|
#
|
||||||
|
name: "CodeQL"
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [ "main" ]
|
||||||
|
pull_request:
|
||||||
|
# The branches below must be a subset of the branches above
|
||||||
|
branches: [ "main" ]
|
||||||
|
schedule:
|
||||||
|
- cron: '21 21 * * 0'
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
analyze:
|
||||||
|
name: Analyze
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
actions: read
|
||||||
|
contents: read
|
||||||
|
security-events: write
|
||||||
|
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
|
# Initializes the CodeQL tools for scanning.
|
||||||
|
- name: Initialize CodeQL
|
||||||
|
uses: github/codeql-action/init@v2
|
||||||
|
with:
|
||||||
|
languages: go
|
||||||
|
|
||||||
|
- run: |
|
||||||
|
echo "Build"
|
||||||
|
make build
|
||||||
|
|
||||||
|
- name: Perform CodeQL Analysis
|
||||||
|
uses: github/codeql-action/analyze@v2
|
10
.github/workflows/main.yml
vendored
10
.github/workflows/main.yml
vendored
@ -11,19 +11,19 @@ on:
|
|||||||
jobs:
|
jobs:
|
||||||
tests:
|
tests:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
make: ["lint", "test"]
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v2.4.0
|
- uses: actions/checkout@v2.4.0
|
||||||
|
|
||||||
- name: install go
|
- name: install go
|
||||||
uses: actions/setup-go@v2
|
uses: actions/setup-go@v2
|
||||||
with:
|
with:
|
||||||
go-version: "^1.18"
|
go-version: "^1.19"
|
||||||
|
|
||||||
- name: Lint
|
- name: Lint
|
||||||
run: make lint
|
run: make ${{ matrix.make }}
|
||||||
|
|
||||||
- name: Tests
|
|
||||||
run: make test
|
|
||||||
|
|
||||||
deploy:
|
deploy:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
@ -1,4 +1,4 @@
|
|||||||
FROM golang:1.18-alpine as builder
|
FROM golang:1.19-alpine as builder
|
||||||
|
|
||||||
ARG ARG_VERSION
|
ARG ARG_VERSION
|
||||||
ENV VERSION $ARG_VERSION
|
ENV VERSION $ARG_VERSION
|
||||||
|
2
Makefile
2
Makefile
@ -16,7 +16,7 @@ integration-test:
|
|||||||
.PHONY: install-tools
|
.PHONY: install-tools
|
||||||
install-tools:
|
install-tools:
|
||||||
@command golangci-lint > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
|
@command golangci-lint > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
|
||||||
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(GOPATH)/bin v1.45.0; \
|
curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(GOPATH)/bin v1.45.2; \
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@command $(GOPATH)/shadow > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
|
@command $(GOPATH)/shadow > /dev/null 2>&1; if [ $$? -ne 0 ]; then \
|
||||||
|
22
README.md
22
README.md
@ -1,6 +1,7 @@
|
|||||||
# What is my IP address
|
# What is my IP address
|
||||||
|
|
||||||
[](https://github.com/dcarrillo/whatismyip/actions)
|
[](https://github.com/dcarrillo/whatismyip/actions)
|
||||||
|
[](https://github.com/dcarrillo/whatismyip/actions/workflows/codeql-analysis.yml)
|
||||||
[](https://goreportcard.com/report/github.com/dcarrillo/whatismyip)
|
[](https://goreportcard.com/report/github.com/dcarrillo/whatismyip)
|
||||||
[](https://github.com/dcarrillo/whatismyip/releases/)
|
[](https://github.com/dcarrillo/whatismyip/releases/)
|
||||||
[](./LICENSE)
|
[](./LICENSE)
|
||||||
@ -13,7 +14,7 @@
|
|||||||
- [Examples](#examples)
|
- [Examples](#examples)
|
||||||
- [Run a default TCP server](#run-a-default-tcp-server)
|
- [Run a default TCP server](#run-a-default-tcp-server)
|
||||||
- [Run a TLS (HTTP/2) server only](#run-a-tls-http2-server-only)
|
- [Run a TLS (HTTP/2) server only](#run-a-tls-http2-server-only)
|
||||||
- [Run a default TCP server with a custom template and trust a custom header set by an upstream proxy](#run-a-default-tcp-server-with-a-custom-template-and-trust-a-custom-header-set-by-an-upstream-proxy)
|
- [Run a default TCP server with a custom template and trust a pair of custom headers set by an upstream proxy](#run-a-default-tcp-server-with-a-custom-template-and-trust-a-pair-of-custom-headers-set-by-an-upstream-proxy)
|
||||||
- [Download](#download)
|
- [Download](#download)
|
||||||
- [Docker](#docker)
|
- [Docker](#docker)
|
||||||
- [Run a container locally using test databases](#run-a-container-locally-using-test-databases)
|
- [Run a container locally using test databases](#run-a-container-locally-using-test-databases)
|
||||||
@ -36,7 +37,7 @@ curl -6 ifconfig.es
|
|||||||
## Features
|
## Features
|
||||||
|
|
||||||
- TLS and HTTP/2.
|
- TLS and HTTP/2.
|
||||||
- Can run behind a proxy by trusting a custom header (usually `X-Real-IP`) to figure out the source IP address.
|
- Can run behind a proxy by trusting a custom header (usually `X-Real-IP`) to figure out the source IP address. It also supports a custom header to resolve the client port, if the proxy can only add a header for the IP (for example a fixed header from CDNs) the client port is shown as unknown.
|
||||||
- IPv4 and IPv6.
|
- IPv4 and IPv6.
|
||||||
- Geolocation info including ASN. This feature is possible thanks to [maxmind](https://dev.maxmind.com/geoip/geolite2-free-geolocation-data?lang=en) GeoLite2 databases. In order to use these databases, a license key is needed. Please visit Maxmind site for further instructions and get a free license.
|
- Geolocation info including ASN. This feature is possible thanks to [maxmind](https://dev.maxmind.com/geoip/geolite2-free-geolocation-data?lang=en) GeoLite2 databases. In order to use these databases, a license key is needed. Please visit Maxmind site for further instructions and get a free license.
|
||||||
- High performance.
|
- High performance.
|
||||||
@ -47,7 +48,8 @@ curl -6 ifconfig.es
|
|||||||
## Endpoints
|
## Endpoints
|
||||||
|
|
||||||
- https://ifconfig.es/
|
- https://ifconfig.es/
|
||||||
- https://ifconfig.es/json
|
- https://ifconfig.es/client-port
|
||||||
|
- https://ifconfig.es/json (this is the same as `curl -H "Accept: application/json" https://ifconfig.es/`)
|
||||||
- https://ifconfig.es/geo
|
- https://ifconfig.es/geo
|
||||||
- https://ifconfig.es/geo/city
|
- https://ifconfig.es/geo/city
|
||||||
- https://ifconfig.es/geo/country
|
- https://ifconfig.es/geo/country
|
||||||
@ -72,9 +74,11 @@ Golang >= 1.17 is required. Previous versions may work.
|
|||||||
## Usage
|
## Usage
|
||||||
|
|
||||||
```text
|
```text
|
||||||
Usage of ./whatismyip:
|
Usage of whatismyip:
|
||||||
-bind string
|
-bind string
|
||||||
Listening address (see https://pkg.go.dev/net?#Listen) (default ":8080")
|
Listening address (see https://pkg.go.dev/net?#Listen) (default ":8080")
|
||||||
|
-enable-secure-headers
|
||||||
|
Add sane security-related headers to every response
|
||||||
-geoip2-asn string
|
-geoip2-asn string
|
||||||
Path to GeoIP2 ASN database
|
Path to GeoIP2 ASN database
|
||||||
-geoip2-city string
|
-geoip2-city string
|
||||||
@ -88,7 +92,9 @@ Usage of ./whatismyip:
|
|||||||
-tls-key string
|
-tls-key string
|
||||||
When using TLS, path to private key file
|
When using TLS, path to private key file
|
||||||
-trusted-header string
|
-trusted-header string
|
||||||
Trusted request header for remote IP (e.g. X-Real-IP)
|
Trusted request header for remote IP (e.g. X-Real-IP). When using this feature if -trusted-port-header is not set the client port is shown as 'unknown'
|
||||||
|
-trusted-port-header string
|
||||||
|
Trusted request header for remote client port (e.g. X-Real-Port). When this parameter is set -trusted-header becomes mandatory
|
||||||
-version
|
-version
|
||||||
Output version information and exit
|
Output version information and exit
|
||||||
```
|
```
|
||||||
@ -108,11 +114,11 @@ Usage of ./whatismyip:
|
|||||||
-bind "" -tls-bind :8081 -tls-crt ./test/server.pem -tls-key ./test/server.key
|
-bind "" -tls-bind :8081 -tls-crt ./test/server.pem -tls-key ./test/server.key
|
||||||
```
|
```
|
||||||
|
|
||||||
### Run a default TCP server with a custom template and trust a custom header set by an upstream proxy
|
### Run a default TCP server with a custom template and trust a pair of custom headers set by an upstream proxy
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
./whatismyip -geoip2-city ./test/GeoIP2-City-Test.mmdb -geoip2-asn ./test/GeoLite2-ASN-Test.mmdb \
|
./whatismyip -geoip2-city ./test/GeoIP2-City-Test.mmdb -geoip2-asn ./test/GeoLite2-ASN-Test.mmdb \
|
||||||
-trusted-header X-Real-IP -template mytemplate.tmpl
|
-trusted-header X-Real-IP -trusted-port-header X-Real-Port -template mytemplate.tmpl
|
||||||
```
|
```
|
||||||
|
|
||||||
## Download
|
## Download
|
||||||
@ -121,7 +127,7 @@ Download latest version from https://github.com/dcarrillo/whatismyip/releases
|
|||||||
|
|
||||||
## Docker
|
## Docker
|
||||||
|
|
||||||
An ultra-light (~9MB) image is available.
|
An ultra-light (~10MB) image is available at [docker hub](https://hub.docker.com/r/dcarrillo/whatismyip).
|
||||||
|
|
||||||
### Run a container locally using test databases
|
### Run a container locally using test databases
|
||||||
|
|
||||||
|
@ -13,6 +13,8 @@ import (
|
|||||||
|
|
||||||
"github.com/dcarrillo/whatismyip/internal/httputils"
|
"github.com/dcarrillo/whatismyip/internal/httputils"
|
||||||
"github.com/dcarrillo/whatismyip/internal/setting"
|
"github.com/dcarrillo/whatismyip/internal/setting"
|
||||||
|
"github.com/gin-contrib/secure"
|
||||||
|
|
||||||
"github.com/dcarrillo/whatismyip/models"
|
"github.com/dcarrillo/whatismyip/models"
|
||||||
"github.com/dcarrillo/whatismyip/router"
|
"github.com/dcarrillo/whatismyip/router"
|
||||||
|
|
||||||
@ -138,6 +140,13 @@ func setupEngine() {
|
|||||||
engine = gin.New()
|
engine = gin.New()
|
||||||
engine.Use(gin.LoggerWithFormatter(httputils.GetLogFormatter))
|
engine.Use(gin.LoggerWithFormatter(httputils.GetLogFormatter))
|
||||||
engine.Use(gin.Recovery())
|
engine.Use(gin.Recovery())
|
||||||
|
if setting.App.EnableSecureHeaders {
|
||||||
|
engine.Use(secure.New(secure.Config{
|
||||||
|
BrowserXssFilter: true,
|
||||||
|
ContentTypeNosniff: true,
|
||||||
|
FrameDeny: true,
|
||||||
|
}))
|
||||||
|
}
|
||||||
_ = engine.SetTrustedProxies(nil)
|
_ = engine.SetTrustedProxies(nil)
|
||||||
engine.TrustedPlatform = setting.App.TrustedHeader
|
engine.TrustedPlatform = setting.App.TrustedHeader
|
||||||
}
|
}
|
||||||
|
56
go.mod
56
go.mod
@ -1,30 +1,33 @@
|
|||||||
module github.com/dcarrillo/whatismyip
|
module github.com/dcarrillo/whatismyip
|
||||||
|
|
||||||
go 1.18
|
go 1.19
|
||||||
|
|
||||||
require (
|
require (
|
||||||
github.com/gin-gonic/gin v1.7.7
|
github.com/gin-contrib/secure v0.0.1
|
||||||
github.com/oschwald/maxminddb-golang v1.8.0
|
github.com/gin-gonic/gin v1.8.1
|
||||||
github.com/stretchr/testify v1.7.1
|
github.com/oschwald/maxminddb-golang v1.10.0
|
||||||
github.com/testcontainers/testcontainers-go v0.12.0
|
github.com/stretchr/testify v1.8.0
|
||||||
|
github.com/testcontainers/testcontainers-go v0.13.0
|
||||||
)
|
)
|
||||||
|
|
||||||
require (
|
require (
|
||||||
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
|
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
|
||||||
github.com/Microsoft/go-winio v0.5.2 // indirect
|
github.com/Microsoft/go-winio v0.5.2 // indirect
|
||||||
github.com/Microsoft/hcsshim v0.9.2 // indirect
|
github.com/Microsoft/hcsshim v0.9.4 // indirect
|
||||||
github.com/cenkalti/backoff v2.2.1+incompatible // indirect
|
github.com/cenkalti/backoff/v4 v4.1.3 // indirect
|
||||||
github.com/containerd/cgroups v1.0.3 // indirect
|
github.com/containerd/cgroups v1.0.4 // indirect
|
||||||
github.com/containerd/containerd v1.6.1 // indirect
|
github.com/containerd/containerd v1.6.8 // indirect
|
||||||
|
github.com/containerd/continuity v0.3.0 // indirect
|
||||||
github.com/davecgh/go-spew v1.1.1 // indirect
|
github.com/davecgh/go-spew v1.1.1 // indirect
|
||||||
github.com/docker/distribution v2.8.1+incompatible // indirect
|
github.com/docker/distribution v2.8.1+incompatible // indirect
|
||||||
github.com/docker/docker v20.10.13+incompatible // indirect
|
github.com/docker/docker v20.10.17+incompatible // indirect
|
||||||
github.com/docker/go-connections v0.4.0 // indirect
|
github.com/docker/go-connections v0.4.0 // indirect
|
||||||
github.com/docker/go-units v0.4.0 // indirect
|
github.com/docker/go-units v0.4.0 // indirect
|
||||||
github.com/gin-contrib/sse v0.1.0 // indirect
|
github.com/gin-contrib/sse v0.1.0 // indirect
|
||||||
github.com/go-playground/locales v0.14.0 // indirect
|
github.com/go-playground/locales v0.14.0 // indirect
|
||||||
github.com/go-playground/universal-translator v0.18.0 // indirect
|
github.com/go-playground/universal-translator v0.18.0 // indirect
|
||||||
github.com/go-playground/validator/v10 v10.10.1 // indirect
|
github.com/go-playground/validator/v10 v10.11.1 // indirect
|
||||||
|
github.com/goccy/go-json v0.9.11 // indirect
|
||||||
github.com/gogo/protobuf v1.3.2 // indirect
|
github.com/gogo/protobuf v1.3.2 // indirect
|
||||||
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
|
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
|
||||||
github.com/golang/protobuf v1.5.2 // indirect
|
github.com/golang/protobuf v1.5.2 // indirect
|
||||||
@ -32,28 +35,29 @@ require (
|
|||||||
github.com/json-iterator/go v1.1.12 // indirect
|
github.com/json-iterator/go v1.1.12 // indirect
|
||||||
github.com/leodido/go-urn v1.2.1 // indirect
|
github.com/leodido/go-urn v1.2.1 // indirect
|
||||||
github.com/magiconair/properties v1.8.6 // indirect
|
github.com/magiconair/properties v1.8.6 // indirect
|
||||||
github.com/mattn/go-isatty v0.0.14 // indirect
|
github.com/mattn/go-isatty v0.0.16 // indirect
|
||||||
github.com/moby/sys/mount v0.3.1 // indirect
|
github.com/moby/sys/mount v0.3.3 // indirect
|
||||||
github.com/moby/sys/mountinfo v0.6.0 // indirect
|
github.com/moby/sys/mountinfo v0.6.2 // indirect
|
||||||
github.com/moby/term v0.0.0-20210619224110-3f7ff695adc6 // indirect
|
github.com/moby/term v0.0.0-20220808134915-39b0c02b01ae // indirect
|
||||||
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
|
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
|
||||||
github.com/modern-go/reflect2 v1.0.2 // indirect
|
github.com/modern-go/reflect2 v1.0.2 // indirect
|
||||||
github.com/morikuni/aec v1.0.0 // indirect
|
github.com/morikuni/aec v1.0.0 // indirect
|
||||||
github.com/opencontainers/go-digest v1.0.0 // indirect
|
github.com/opencontainers/go-digest v1.0.0 // indirect
|
||||||
github.com/opencontainers/image-spec v1.0.2 // indirect
|
github.com/opencontainers/image-spec v1.0.3-0.20211202183452-c5a74bcca799 // indirect
|
||||||
github.com/opencontainers/runc v1.1.0 // indirect
|
github.com/opencontainers/runc v1.1.3 // indirect
|
||||||
|
github.com/pelletier/go-toml/v2 v2.0.5 // indirect
|
||||||
github.com/pkg/errors v0.9.1 // indirect
|
github.com/pkg/errors v0.9.1 // indirect
|
||||||
github.com/pmezard/go-difflib v1.0.0 // indirect
|
github.com/pmezard/go-difflib v1.0.0 // indirect
|
||||||
github.com/sirupsen/logrus v1.8.1 // indirect
|
github.com/sirupsen/logrus v1.9.0 // indirect
|
||||||
github.com/ugorji/go/codec v1.2.7 // indirect
|
github.com/ugorji/go/codec v1.2.7 // indirect
|
||||||
go.opencensus.io v0.23.0 // indirect
|
go.opencensus.io v0.23.0 // indirect
|
||||||
golang.org/x/crypto v0.0.0-20220315160706-3147a52a75dd // indirect
|
golang.org/x/crypto v0.1.0 // indirect
|
||||||
golang.org/x/net v0.0.0-20220225172249-27dd8689420f // indirect
|
golang.org/x/net v0.1.0 // indirect
|
||||||
golang.org/x/sys v0.0.0-20220319134239-a9b59b0215f8 // indirect
|
golang.org/x/sys v0.1.0 // indirect
|
||||||
golang.org/x/text v0.3.7 // indirect
|
golang.org/x/text v0.4.0 // indirect
|
||||||
google.golang.org/genproto v0.0.0-20220317150908-0efb43f6373e // indirect
|
google.golang.org/genproto v0.0.0-20220810155839-1856144b1d9c // indirect
|
||||||
google.golang.org/grpc v1.45.0 // indirect
|
google.golang.org/grpc v1.48.0 // indirect
|
||||||
google.golang.org/protobuf v1.27.1 // indirect
|
google.golang.org/protobuf v1.28.1 // indirect
|
||||||
gopkg.in/yaml.v2 v2.4.0 // indirect
|
gopkg.in/yaml.v2 v2.4.0 // indirect
|
||||||
gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b // indirect
|
gopkg.in/yaml.v3 v3.0.1 // indirect
|
||||||
)
|
)
|
||||||
|
@ -4,7 +4,7 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"crypto/tls"
|
"crypto/tls"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"io/ioutil"
|
"io"
|
||||||
"log"
|
"log"
|
||||||
"net/http"
|
"net/http"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
@ -34,15 +34,22 @@ func buildContainer() testcontainers.ContainerRequest {
|
|||||||
"-tls-crt", "/tmp/server.pem",
|
"-tls-crt", "/tmp/server.pem",
|
||||||
"-tls-key", "/tmp/server.key",
|
"-tls-key", "/tmp/server.key",
|
||||||
"-trusted-header", "X-Real-IP",
|
"-trusted-header", "X-Real-IP",
|
||||||
|
"-enable-secure-headers",
|
||||||
},
|
},
|
||||||
ExposedPorts: []string{"8000:8000", "8001:8001"},
|
ExposedPorts: []string{"8000:8000", "8001:8001"},
|
||||||
WaitingFor: wait.ForLog("Starting TLS server listening on :8001"),
|
WaitingFor: wait.ForLog("Starting TLS server listening on :8001"),
|
||||||
BindMounts: map[string]string{
|
Mounts: testcontainers.Mounts(
|
||||||
"/tmp/GeoIP2-City-Test.mmdb": filepath.Join(dir, "/../test/GeoIP2-City-Test.mmdb"),
|
testcontainers.BindMount(
|
||||||
"/tmp/GeoLite2-ASN-Test.mmdb": filepath.Join(dir, "/../test/GeoLite2-ASN-Test.mmdb"),
|
filepath.Join(dir, "/../test/GeoIP2-City-Test.mmdb"),
|
||||||
"/tmp/server.pem": filepath.Join(dir, "/../test/server.pem"),
|
"/tmp/GeoIP2-City-Test.mmdb",
|
||||||
"/tmp/server.key": filepath.Join(dir, "/../test/server.key"),
|
),
|
||||||
},
|
testcontainers.BindMount(
|
||||||
|
filepath.Join(dir, "/../test/GeoLite2-ASN-Test.mmdb"),
|
||||||
|
"/tmp/GeoLite2-ASN-Test.mmdb",
|
||||||
|
),
|
||||||
|
testcontainers.BindMount(filepath.Join(dir, "/../test/server.pem"), "/tmp/server.pem"),
|
||||||
|
testcontainers.BindMount(filepath.Join(dir, "/../test/server.key"), "/tmp/server.key"),
|
||||||
|
),
|
||||||
}
|
}
|
||||||
|
|
||||||
return req
|
return req
|
||||||
@ -69,16 +76,21 @@ func TestContainerIntegration(t *testing.T) {
|
|||||||
}()
|
}()
|
||||||
|
|
||||||
http.DefaultTransport.(*http.Transport).TLSClientConfig = &tls.Config{InsecureSkipVerify: true}
|
http.DefaultTransport.(*http.Transport).TLSClientConfig = &tls.Config{InsecureSkipVerify: true}
|
||||||
for _, url := range []string{"http://localhost:8000/json", "https://localhost:8001/json"} {
|
for _, url := range []string{"http://localhost:8000", "https://localhost:8001"} {
|
||||||
resp, _ := http.Get(url)
|
client := &http.Client{}
|
||||||
|
req, _ := http.NewRequest("GET", url, nil)
|
||||||
|
req.Header.Set("Accept", "application/json")
|
||||||
|
resp, _ := client.Do(req)
|
||||||
assert.Equal(t, 200, resp.StatusCode)
|
assert.Equal(t, 200, resp.StatusCode)
|
||||||
|
|
||||||
var dat router.JSONResponse
|
body, err := io.ReadAll(resp.Body)
|
||||||
body, err := ioutil.ReadAll(resp.Body)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Fatal(err)
|
log.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
||||||
assert.NoError(t, json.Unmarshal(body, &dat))
|
assert.NoError(t, json.Unmarshal(body, &router.JSONResponse{}))
|
||||||
|
assert.Equal(t, "DENY", resp.Header.Get("X-Frame-Options"))
|
||||||
|
assert.Equal(t, "nosniff", resp.Header.Get("X-Content-Type-Options"))
|
||||||
|
assert.Equal(t, "1; mode=block", resp.Header.Get("X-Xss-Protection"))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -3,9 +3,11 @@ package httputils
|
|||||||
import (
|
import (
|
||||||
"fmt"
|
"fmt"
|
||||||
"net/http"
|
"net/http"
|
||||||
|
"net/textproto"
|
||||||
"sort"
|
"sort"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
|
"github.com/dcarrillo/whatismyip/internal/setting"
|
||||||
"github.com/gin-gonic/gin"
|
"github.com/gin-gonic/gin"
|
||||||
)
|
)
|
||||||
|
|
||||||
@ -32,6 +34,17 @@ func HeadersToSortedString(headers http.Header) string {
|
|||||||
return output
|
return output
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// GetHeadersWithoutTrustedHeaders return a http.Heade object with the original headers except trusted headers
|
||||||
|
func GetHeadersWithoutTrustedHeaders(ctx *gin.Context) http.Header {
|
||||||
|
h := ctx.Request.Header
|
||||||
|
|
||||||
|
for _, k := range []string{setting.App.TrustedHeader, setting.App.TrustedPortHeader} {
|
||||||
|
delete(h, textproto.CanonicalMIMEHeaderKey(k))
|
||||||
|
}
|
||||||
|
|
||||||
|
return h
|
||||||
|
}
|
||||||
|
|
||||||
// GetLogFormatter returns our custom log format
|
// GetLogFormatter returns our custom log format
|
||||||
func GetLogFormatter(param gin.LogFormatterParams) string {
|
func GetLogFormatter(param gin.LogFormatterParams) string {
|
||||||
return fmt.Sprintf("%s - [%s] \"%s %s %s\" %d %d %d %s \"%s\" \"%s\" \"%s\"\n",
|
return fmt.Sprintf("%s - [%s] \"%s %s %s\" %d %d %d %s \"%s\" \"%s\" \"%s\"\n",
|
||||||
|
@ -20,15 +20,17 @@ type serverSettings struct {
|
|||||||
WriteTimeout time.Duration
|
WriteTimeout time.Duration
|
||||||
}
|
}
|
||||||
type settings struct {
|
type settings struct {
|
||||||
GeodbPath geodbPath
|
GeodbPath geodbPath
|
||||||
TemplatePath string
|
TemplatePath string
|
||||||
BindAddress string
|
BindAddress string
|
||||||
TLSAddress string
|
TLSAddress string
|
||||||
TLSCrtPath string
|
TLSCrtPath string
|
||||||
TLSKeyPath string
|
TLSKeyPath string
|
||||||
TrustedHeader string
|
TrustedHeader string
|
||||||
Server serverSettings
|
TrustedPortHeader string
|
||||||
version bool
|
EnableSecureHeaders bool
|
||||||
|
Server serverSettings
|
||||||
|
version bool
|
||||||
}
|
}
|
||||||
|
|
||||||
const defaultAddress = ":8080"
|
const defaultAddress = ":8080"
|
||||||
@ -68,12 +70,25 @@ func Setup(args []string) (output string, err error) {
|
|||||||
)
|
)
|
||||||
flags.StringVar(&App.TLSCrtPath, "tls-crt", "", "When using TLS, path to certificate file")
|
flags.StringVar(&App.TLSCrtPath, "tls-crt", "", "When using TLS, path to certificate file")
|
||||||
flags.StringVar(&App.TLSKeyPath, "tls-key", "", "When using TLS, path to private key file")
|
flags.StringVar(&App.TLSKeyPath, "tls-key", "", "When using TLS, path to private key file")
|
||||||
flags.StringVar(&App.TrustedHeader,
|
flags.StringVar(
|
||||||
|
&App.TrustedHeader,
|
||||||
"trusted-header",
|
"trusted-header",
|
||||||
"",
|
"",
|
||||||
"Trusted request header for remote IP (e.g. X-Real-IP)",
|
"Trusted request header for remote IP (e.g. X-Real-IP). When using this feature if -trusted-port-header is not set the client port is shown as 'unknown'",
|
||||||
|
)
|
||||||
|
flags.StringVar(
|
||||||
|
&App.TrustedPortHeader,
|
||||||
|
"trusted-port-header",
|
||||||
|
"",
|
||||||
|
"Trusted request header for remote client port (e.g. X-Real-Port). When this parameter is set -trusted-header becomes mandatory",
|
||||||
)
|
)
|
||||||
flags.BoolVar(&App.version, "version", false, "Output version information and exit")
|
flags.BoolVar(&App.version, "version", false, "Output version information and exit")
|
||||||
|
flags.BoolVar(
|
||||||
|
&App.EnableSecureHeaders,
|
||||||
|
"enable-secure-headers",
|
||||||
|
false,
|
||||||
|
"Add sane security-related headers to every response",
|
||||||
|
)
|
||||||
|
|
||||||
err = flags.Parse(args)
|
err = flags.Parse(args)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@ -84,21 +99,25 @@ func Setup(args []string) (output string, err error) {
|
|||||||
return fmt.Sprintf("whatismyip version %s", core.Version), ErrVersion
|
return fmt.Sprintf("whatismyip version %s", core.Version), ErrVersion
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if App.TrustedPortHeader != "" && App.TrustedHeader == "" {
|
||||||
|
return "", fmt.Errorf("truster-header is mandatory when truster-port-header is set\n")
|
||||||
|
}
|
||||||
|
|
||||||
if App.GeodbPath.City == "" || App.GeodbPath.ASN == "" {
|
if App.GeodbPath.City == "" || App.GeodbPath.ASN == "" {
|
||||||
return "", fmt.Errorf("geoip2-city and geoip2-asn parameters are mandatory")
|
return "", fmt.Errorf("geoip2-city and geoip2-asn parameters are mandatory\n")
|
||||||
}
|
}
|
||||||
|
|
||||||
if (App.TLSAddress != "") && (App.TLSCrtPath == "" || App.TLSKeyPath == "") {
|
if (App.TLSAddress != "") && (App.TLSCrtPath == "" || App.TLSKeyPath == "") {
|
||||||
return "", fmt.Errorf("In order to use TLS -tls-crt and -tls-key flags are mandatory")
|
return "", fmt.Errorf("In order to use TLS -tls-crt and -tls-key flags are mandatory\n")
|
||||||
}
|
}
|
||||||
|
|
||||||
if App.TemplatePath != "" {
|
if App.TemplatePath != "" {
|
||||||
info, err := os.Stat(App.TemplatePath)
|
info, err := os.Stat(App.TemplatePath)
|
||||||
if os.IsNotExist(err) {
|
if os.IsNotExist(err) {
|
||||||
return "", fmt.Errorf("%s no such file or directory", App.TemplatePath)
|
return "", fmt.Errorf("%s no such file or directory\n", App.TemplatePath)
|
||||||
}
|
}
|
||||||
if info.IsDir() {
|
if info.IsDir() {
|
||||||
return "", fmt.Errorf("%s must be a file", App.TemplatePath)
|
return "", fmt.Errorf("%s must be a file\n", App.TemplatePath)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -8,51 +8,51 @@ import (
|
|||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestParseMandatoryFlags(t *testing.T) {
|
func TestParseMandatoryFlags(t *testing.T) {
|
||||||
var mandatoryFlags = []struct {
|
var mandatoryFlags = []struct {
|
||||||
args []string
|
args []string
|
||||||
conf settings
|
|
||||||
}{
|
}{
|
||||||
{
|
{
|
||||||
[]string{},
|
[]string{},
|
||||||
settings{},
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
[]string{"-geoip2-city", "/city-path"},
|
[]string{"-geoip2-city", "/city-path"},
|
||||||
settings{},
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
[]string{"-geoip2-asn", "/asn-path"},
|
[]string{"-geoip2-asn", "/asn-path"},
|
||||||
settings{},
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
[]string{
|
[]string{
|
||||||
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path", "-tls-bind", ":9000",
|
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path", "-tls-bind", ":9000",
|
||||||
},
|
},
|
||||||
settings{},
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
[]string{
|
[]string{
|
||||||
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path", "-tls-bind", ":9000",
|
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path", "-tls-bind", ":9000",
|
||||||
"-tls-crt", "/crt-path",
|
"-tls-crt", "/crt-path",
|
||||||
},
|
},
|
||||||
settings{},
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
[]string{
|
[]string{
|
||||||
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path", "-tls-bind", ":9000",
|
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path", "-tls-bind", ":9000",
|
||||||
"-tls-key", "/key-path",
|
"-tls-key", "/key-path",
|
||||||
},
|
},
|
||||||
settings{},
|
},
|
||||||
|
{
|
||||||
|
[]string{
|
||||||
|
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path", "-bind", ":8000",
|
||||||
|
"-trusted-port-header", "port-header",
|
||||||
|
},
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tt := range mandatoryFlags {
|
for _, tt := range mandatoryFlags {
|
||||||
t.Run(strings.Join(tt.args, " "), func(t *testing.T) {
|
t.Run(strings.Join(tt.args, " "), func(t *testing.T) {
|
||||||
_, err := Setup(tt.args)
|
_, err := Setup(tt.args)
|
||||||
assert.NotNil(t, err)
|
require.NotNil(t, err)
|
||||||
assert.Contains(t, err.Error(), "mandatory")
|
assert.Contains(t, err.Error(), "mandatory")
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@ -70,12 +70,7 @@ func TestParseFlags(t *testing.T) {
|
|||||||
City: "/city-path",
|
City: "/city-path",
|
||||||
ASN: "/asn-path",
|
ASN: "/asn-path",
|
||||||
},
|
},
|
||||||
TemplatePath: "",
|
BindAddress: ":8080",
|
||||||
BindAddress: ":8080",
|
|
||||||
TLSAddress: "",
|
|
||||||
TLSCrtPath: "",
|
|
||||||
TLSKeyPath: "",
|
|
||||||
TrustedHeader: "",
|
|
||||||
Server: serverSettings{
|
Server: serverSettings{
|
||||||
ReadTimeout: 10 * time.Second,
|
ReadTimeout: 10 * time.Second,
|
||||||
WriteTimeout: 10 * time.Second,
|
WriteTimeout: 10 * time.Second,
|
||||||
@ -89,12 +84,7 @@ func TestParseFlags(t *testing.T) {
|
|||||||
City: "/city-path",
|
City: "/city-path",
|
||||||
ASN: "/asn-path",
|
ASN: "/asn-path",
|
||||||
},
|
},
|
||||||
TemplatePath: "",
|
BindAddress: ":8001",
|
||||||
BindAddress: ":8001",
|
|
||||||
TLSAddress: "",
|
|
||||||
TLSCrtPath: "",
|
|
||||||
TLSKeyPath: "",
|
|
||||||
TrustedHeader: "",
|
|
||||||
Server: serverSettings{
|
Server: serverSettings{
|
||||||
ReadTimeout: 10 * time.Second,
|
ReadTimeout: 10 * time.Second,
|
||||||
WriteTimeout: 10 * time.Second,
|
WriteTimeout: 10 * time.Second,
|
||||||
@ -111,12 +101,10 @@ func TestParseFlags(t *testing.T) {
|
|||||||
City: "/city-path",
|
City: "/city-path",
|
||||||
ASN: "/asn-path",
|
ASN: "/asn-path",
|
||||||
},
|
},
|
||||||
TemplatePath: "",
|
BindAddress: ":8080",
|
||||||
BindAddress: ":8080",
|
TLSAddress: ":9000",
|
||||||
TLSAddress: ":9000",
|
TLSCrtPath: "/crt-path",
|
||||||
TLSCrtPath: "/crt-path",
|
TLSKeyPath: "/key-path",
|
||||||
TLSKeyPath: "/key-path",
|
|
||||||
TrustedHeader: "",
|
|
||||||
Server: serverSettings{
|
Server: serverSettings{
|
||||||
ReadTimeout: 10 * time.Second,
|
ReadTimeout: 10 * time.Second,
|
||||||
WriteTimeout: 10 * time.Second,
|
WriteTimeout: 10 * time.Second,
|
||||||
@ -126,19 +114,35 @@ func TestParseFlags(t *testing.T) {
|
|||||||
{
|
{
|
||||||
[]string{
|
[]string{
|
||||||
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path",
|
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path",
|
||||||
"-trusted-header", "header",
|
"-trusted-header", "header", "-trusted-port-header", "port-header",
|
||||||
},
|
},
|
||||||
settings{
|
settings{
|
||||||
GeodbPath: geodbPath{
|
GeodbPath: geodbPath{
|
||||||
City: "/city-path",
|
City: "/city-path",
|
||||||
ASN: "/asn-path",
|
ASN: "/asn-path",
|
||||||
},
|
},
|
||||||
TemplatePath: "",
|
BindAddress: ":8080",
|
||||||
BindAddress: ":8080",
|
TrustedHeader: "header",
|
||||||
TLSAddress: "",
|
TrustedPortHeader: "port-header",
|
||||||
TLSCrtPath: "",
|
Server: serverSettings{
|
||||||
TLSKeyPath: "",
|
ReadTimeout: 10 * time.Second,
|
||||||
TrustedHeader: "header",
|
WriteTimeout: 10 * time.Second,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
[]string{
|
||||||
|
"-geoip2-city", "/city-path", "-geoip2-asn", "/asn-path",
|
||||||
|
"-trusted-header", "header", "-enable-secure-headers",
|
||||||
|
},
|
||||||
|
settings{
|
||||||
|
GeodbPath: geodbPath{
|
||||||
|
City: "/city-path",
|
||||||
|
ASN: "/asn-path",
|
||||||
|
},
|
||||||
|
BindAddress: ":8080",
|
||||||
|
TrustedHeader: "header",
|
||||||
|
EnableSecureHeaders: true,
|
||||||
Server: serverSettings{
|
Server: serverSettings{
|
||||||
ReadTimeout: 10 * time.Second,
|
ReadTimeout: 10 * time.Second,
|
||||||
WriteTimeout: 10 * time.Second,
|
WriteTimeout: 10 * time.Second,
|
||||||
@ -150,7 +154,7 @@ func TestParseFlags(t *testing.T) {
|
|||||||
for _, tt := range flags {
|
for _, tt := range flags {
|
||||||
t.Run(strings.Join(tt.args, " "), func(t *testing.T) {
|
t.Run(strings.Join(tt.args, " "), func(t *testing.T) {
|
||||||
_, err := Setup(tt.args)
|
_, err := Setup(tt.args)
|
||||||
assert.Nil(t, err)
|
require.Nil(t, err)
|
||||||
assert.True(t, reflect.DeepEqual(App, tt.conf))
|
assert.True(t, reflect.DeepEqual(App, tt.conf))
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@ -188,6 +192,6 @@ func TestParseFlagTemplate(t *testing.T) {
|
|||||||
"-template", "/",
|
"-template", "/",
|
||||||
}
|
}
|
||||||
_, err = Setup(flags)
|
_, err = Setup(flags)
|
||||||
assert.Error(t, err)
|
require.Error(t, err)
|
||||||
assert.Contains(t, err.Error(), "must be a file")
|
assert.Contains(t, err.Error(), "must be a file")
|
||||||
}
|
}
|
||||||
|
@ -4,7 +4,6 @@ import (
|
|||||||
"net"
|
"net"
|
||||||
"net/http"
|
"net/http"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"regexp"
|
|
||||||
|
|
||||||
"github.com/dcarrillo/whatismyip/internal/httputils"
|
"github.com/dcarrillo/whatismyip/internal/httputils"
|
||||||
"github.com/dcarrillo/whatismyip/internal/setting"
|
"github.com/dcarrillo/whatismyip/internal/setting"
|
||||||
@ -12,8 +11,6 @@ import (
|
|||||||
"github.com/gin-gonic/gin"
|
"github.com/gin-gonic/gin"
|
||||||
)
|
)
|
||||||
|
|
||||||
const userAgentPattern = `curl|wget|libwww-perl|python|ansible-httpget|HTTPie|WindowsPowerShell|http_request|Go-http-client|^$`
|
|
||||||
|
|
||||||
// JSONResponse maps data as json
|
// JSONResponse maps data as json
|
||||||
type JSONResponse struct {
|
type JSONResponse struct {
|
||||||
IP string `json:"ip"`
|
IP string `json:"ip"`
|
||||||
@ -33,27 +30,45 @@ type JSONResponse struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func getRoot(ctx *gin.Context) {
|
func getRoot(ctx *gin.Context) {
|
||||||
reg := regexp.MustCompile(userAgentPattern)
|
switch ctx.NegotiateFormat(gin.MIMEPlain, gin.MIMEHTML, gin.MIMEJSON) {
|
||||||
if reg.Match([]byte(ctx.Request.UserAgent())) {
|
case gin.MIMEHTML:
|
||||||
ctx.String(http.StatusOK, ctx.ClientIP())
|
|
||||||
} else {
|
|
||||||
name := "home"
|
name := "home"
|
||||||
if setting.App.TemplatePath != "" {
|
if setting.App.TemplatePath != "" {
|
||||||
name = filepath.Base(setting.App.TemplatePath)
|
name = filepath.Base(setting.App.TemplatePath)
|
||||||
}
|
}
|
||||||
ctx.HTML(http.StatusOK, name, jsonOutput(ctx))
|
ctx.HTML(http.StatusOK, name, jsonOutput(ctx))
|
||||||
|
case gin.MIMEJSON:
|
||||||
|
getJSON(ctx)
|
||||||
|
default:
|
||||||
|
ctx.String(http.StatusOK, ctx.ClientIP()+"\n")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func getClientPort(ctx *gin.Context) string {
|
||||||
|
var port string
|
||||||
|
if setting.App.TrustedPortHeader == "" {
|
||||||
|
if setting.App.TrustedHeader != "" {
|
||||||
|
port = "unknown"
|
||||||
|
} else {
|
||||||
|
_, port, _ = net.SplitHostPort(ctx.Request.RemoteAddr)
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
port = ctx.GetHeader(setting.App.TrustedPortHeader)
|
||||||
|
if port == "" {
|
||||||
|
port = "unknown"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return port
|
||||||
|
}
|
||||||
|
|
||||||
func getClientPortAsString(ctx *gin.Context) {
|
func getClientPortAsString(ctx *gin.Context) {
|
||||||
_, port, _ := net.SplitHostPort(ctx.Request.RemoteAddr)
|
ctx.String(http.StatusOK, getClientPort(ctx)+"\n")
|
||||||
ctx.String(http.StatusOK, port+"\n")
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func getAllAsString(ctx *gin.Context) {
|
func getAllAsString(ctx *gin.Context) {
|
||||||
output := "IP: " + ctx.ClientIP() + "\n"
|
output := "IP: " + ctx.ClientIP() + "\n"
|
||||||
_, port, _ := net.SplitHostPort(ctx.Request.RemoteAddr)
|
output += "Client Port: " + getClientPort(ctx) + "\n"
|
||||||
output += "Client Port: " + port + "\n"
|
|
||||||
|
|
||||||
r := service.Geo{IP: net.ParseIP(ctx.ClientIP())}
|
r := service.Geo{IP: net.ParseIP(ctx.ClientIP())}
|
||||||
if record := r.LookUpCity(); record != nil {
|
if record := r.LookUpCity(); record != nil {
|
||||||
@ -64,8 +79,8 @@ func getAllAsString(ctx *gin.Context) {
|
|||||||
output += geoASNRecordToString(record) + "\n"
|
output += geoASNRecordToString(record) + "\n"
|
||||||
}
|
}
|
||||||
|
|
||||||
h := ctx.Request.Header
|
h := httputils.GetHeadersWithoutTrustedHeaders(ctx)
|
||||||
h["Host"] = []string{ctx.Request.Host}
|
h.Set("Host", ctx.Request.Host)
|
||||||
output += httputils.HeadersToSortedString(h)
|
output += httputils.HeadersToSortedString(h)
|
||||||
|
|
||||||
ctx.String(http.StatusOK, output)
|
ctx.String(http.StatusOK, output)
|
||||||
@ -84,11 +99,10 @@ func jsonOutput(ctx *gin.Context) JSONResponse {
|
|||||||
version = 6
|
version = 6
|
||||||
}
|
}
|
||||||
|
|
||||||
_, port, _ := net.SplitHostPort(ctx.Request.RemoteAddr)
|
|
||||||
return JSONResponse{
|
return JSONResponse{
|
||||||
IP: ctx.ClientIP(),
|
IP: ctx.ClientIP(),
|
||||||
IPVersion: version,
|
IPVersion: version,
|
||||||
ClientPort: port,
|
ClientPort: getClientPort(ctx),
|
||||||
Country: cityRecord.Country.Names["en"],
|
Country: cityRecord.Country.Names["en"],
|
||||||
CountryCode: cityRecord.Country.ISOCode,
|
CountryCode: cityRecord.Country.ISOCode,
|
||||||
City: cityRecord.City.Names["en"],
|
City: cityRecord.City.Names["en"],
|
||||||
@ -99,6 +113,6 @@ func jsonOutput(ctx *gin.Context) JSONResponse {
|
|||||||
ASN: asnRecord.AutonomousSystemNumber,
|
ASN: asnRecord.AutonomousSystemNumber,
|
||||||
ASNOrganization: asnRecord.AutonomousSystemOrganization,
|
ASNOrganization: asnRecord.AutonomousSystemOrganization,
|
||||||
Host: ctx.Request.Host,
|
Host: ctx.Request.Host,
|
||||||
Headers: ctx.Request.Header,
|
Headers: httputils.GetHeadersWithoutTrustedHeaders(ctx),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -6,34 +6,84 @@ import (
|
|||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
|
"github.com/dcarrillo/whatismyip/internal/setting"
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestIP4RootFromCli(t *testing.T) {
|
func TestRootContentType(t *testing.T) {
|
||||||
uas := []string{
|
tests := []struct {
|
||||||
"",
|
name string
|
||||||
"curl",
|
accepted string
|
||||||
"wget",
|
expected string
|
||||||
"libwww-perl",
|
}{
|
||||||
"python",
|
{
|
||||||
"ansible-httpget",
|
name: "Accept wildcard",
|
||||||
"HTTPie",
|
accepted: "*/*",
|
||||||
"WindowsPowerShell",
|
expected: contentType.text,
|
||||||
"http_request",
|
},
|
||||||
"Go-http-client",
|
{
|
||||||
|
name: "Bogus accept",
|
||||||
|
accepted: "bogus/plain",
|
||||||
|
expected: contentType.text,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "Accept plain text",
|
||||||
|
accepted: "text/plain",
|
||||||
|
expected: contentType.text,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "Accept json",
|
||||||
|
accepted: "application/json",
|
||||||
|
expected: contentType.json,
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
req, _ := http.NewRequest("GET", "/", nil)
|
||||||
|
req.Header.Set(trustedHeader, testIP.ipv4)
|
||||||
|
req.Header.Set("Accept", tt.accepted)
|
||||||
|
|
||||||
req, _ := http.NewRequest("GET", "/", nil)
|
w := httptest.NewRecorder()
|
||||||
req.Header.Set("X-Real-IP", testIP.ipv4)
|
app.ServeHTTP(w, req)
|
||||||
|
|
||||||
for _, ua := range uas {
|
assert.Equal(t, 200, w.Code)
|
||||||
req.Header.Set("User-Agent", ua)
|
assert.Equal(t, tt.expected, w.Header().Get("Content-Type"))
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
func TestGetIP(t *testing.T) {
|
||||||
app.ServeHTTP(w, req)
|
expected := testIP.ipv4 + "\n"
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
accepted string
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "No browser",
|
||||||
|
accepted: "*/*",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "Bogus accept",
|
||||||
|
accepted: "bogus/plain",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "Plain accept",
|
||||||
|
accepted: "text/plain",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
req, _ := http.NewRequest("GET", "/", nil)
|
||||||
|
req.Header.Set(trustedHeader, testIP.ipv4)
|
||||||
|
req.Header.Set("Accept", tt.accepted)
|
||||||
|
|
||||||
assert.Equal(t, 200, w.Code)
|
w := httptest.NewRecorder()
|
||||||
assert.Equal(t, testIP.ipv4, w.Body.String())
|
app.ServeHTTP(w, req)
|
||||||
|
|
||||||
|
assert.Equal(t, 200, w.Code)
|
||||||
|
assert.Equal(t, expected, w.Body.String())
|
||||||
|
assert.Equal(t, contentType.text, w.Header().Get("Content-Type"))
|
||||||
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -48,16 +98,76 @@ func TestHost(t *testing.T) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func TestClientPort(t *testing.T) {
|
func TestClientPort(t *testing.T) {
|
||||||
req, _ := http.NewRequest("GET", "/client-port", nil)
|
type args struct {
|
||||||
req.RemoteAddr = net.JoinHostPort(testIP.ipv4, "1000")
|
params []string
|
||||||
req.Header.Set("X-Real-IP", testIP.ipv4)
|
headers map[string][]string
|
||||||
|
}
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
args args
|
||||||
|
expected string
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "No trusted headers set",
|
||||||
|
expected: "1000\n",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "Trusted header only set",
|
||||||
|
args: args{
|
||||||
|
params: []string{
|
||||||
|
"-geoip2-city", "city",
|
||||||
|
"-geoip2-asn", "asn",
|
||||||
|
"-trusted-header", trustedHeader,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
expected: "unknown\n",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "Trusted and port header set but not included in headers",
|
||||||
|
args: args{
|
||||||
|
params: []string{
|
||||||
|
"-geoip2-city", "city",
|
||||||
|
"-geoip2-asn", "asn",
|
||||||
|
"-trusted-header", trustedHeader,
|
||||||
|
"-trusted-port-header", trustedPortHeader,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
expected: "unknown\n",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "Trusted and port header set and included in headers",
|
||||||
|
args: args{
|
||||||
|
params: []string{
|
||||||
|
"-geoip2-city", "city",
|
||||||
|
"-geoip2-asn", "asn",
|
||||||
|
"-trusted-header", trustedHeader,
|
||||||
|
"-trusted-port-header", trustedPortHeader,
|
||||||
|
},
|
||||||
|
headers: map[string][]string{
|
||||||
|
trustedHeader: {testIP.ipv4},
|
||||||
|
trustedPortHeader: {"1001"},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
expected: "1001\n",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
for _, tt := range tests {
|
||||||
app.ServeHTTP(w, req)
|
_, _ = setting.Setup(tt.args.params)
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
req, _ := http.NewRequest("GET", "/client-port", nil)
|
||||||
|
req.RemoteAddr = net.JoinHostPort(testIP.ipv4, "1000")
|
||||||
|
req.Header = tt.args.headers
|
||||||
|
|
||||||
assert.Equal(t, 200, w.Code)
|
w := httptest.NewRecorder()
|
||||||
assert.Equal(t, contentType.text, w.Header().Get("Content-Type"))
|
app.ServeHTTP(w, req)
|
||||||
assert.Equal(t, "1000\n", w.Body.String())
|
|
||||||
|
assert.Equal(t, 200, w.Code)
|
||||||
|
assert.Equal(t, contentType.text, w.Header().Get("Content-Type"))
|
||||||
|
assert.Equal(t, tt.expected, w.Body.String())
|
||||||
|
t.Log(w.Header())
|
||||||
|
})
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestNotFound(t *testing.T) {
|
func TestNotFound(t *testing.T) {
|
||||||
@ -71,36 +181,59 @@ func TestNotFound(t *testing.T) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func TestJSON(t *testing.T) {
|
func TestJSON(t *testing.T) {
|
||||||
expectedIPv4 := `{"client_port":"1000","ip":"81.2.69.192","ip_version":4,"country":"United Kingdom","country_code":"GB","city":"London","latitude":51.5142,"longitude":-0.0931,"postal_code":"","time_zone":"Europe/London","asn":0,"asn_organization":"","host":"test","headers":{"X-Real-Ip":["81.2.69.192"]}}`
|
_, _ = setting.Setup(
|
||||||
expectedIPv6 := `{"asn":3352, "asn_organization":"TELEFONICA DE ESPANA", "city":"", "client_port":"1000", "country":"", "country_code":"", "headers":{"X-Real-Ip":["2a02:9000::1"]}, "host":"test", "ip":"2a02:9000::1", "ip_version":6, "latitude":0, "longitude":0, "postal_code":"", "time_zone":""}`
|
[]string{
|
||||||
|
"-geoip2-city", "city",
|
||||||
|
"-geoip2-asn", "asn",
|
||||||
|
"-trusted-header", trustedHeader,
|
||||||
|
"-trusted-port-header", trustedPortHeader,
|
||||||
|
},
|
||||||
|
)
|
||||||
|
|
||||||
req, _ := http.NewRequest("GET", "/json", nil)
|
type args struct {
|
||||||
req.RemoteAddr = net.JoinHostPort(testIP.ipv4, "1000")
|
ip string
|
||||||
req.Host = "test"
|
}
|
||||||
req.Header.Set("X-Real-IP", testIP.ipv4)
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
args args
|
||||||
|
expected string
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "IPv4",
|
||||||
|
args: args{
|
||||||
|
ip: testIP.ipv4,
|
||||||
|
},
|
||||||
|
expected: jsonIPv4,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "IPv6",
|
||||||
|
args: args{
|
||||||
|
ip: testIP.ipv6,
|
||||||
|
},
|
||||||
|
expected: jsonIPv6,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
req, _ := http.NewRequest("GET", "/json", nil)
|
||||||
|
req.RemoteAddr = net.JoinHostPort(tt.args.ip, "1000")
|
||||||
|
req.Host = "test"
|
||||||
|
req.Header.Set(trustedHeader, tt.args.ip)
|
||||||
|
req.Header.Set(trustedPortHeader, "1001")
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
w := httptest.NewRecorder()
|
||||||
app.ServeHTTP(w, req)
|
app.ServeHTTP(w, req)
|
||||||
|
|
||||||
assert.Equal(t, 200, w.Code)
|
assert.Equal(t, 200, w.Code)
|
||||||
assert.Equal(t, contentType.json, w.Header().Get("Content-Type"))
|
assert.Equal(t, contentType.json, w.Header().Get("Content-Type"))
|
||||||
assert.JSONEq(t, expectedIPv4, w.Body.String())
|
assert.JSONEq(t, tt.expected, w.Body.String())
|
||||||
|
})
|
||||||
req.RemoteAddr = net.JoinHostPort(testIP.ipv6, "1000")
|
}
|
||||||
req.Host = "test"
|
|
||||||
req.Header.Set("X-Real-IP", testIP.ipv6)
|
|
||||||
|
|
||||||
w = httptest.NewRecorder()
|
|
||||||
app.ServeHTTP(w, req)
|
|
||||||
|
|
||||||
assert.Equal(t, 200, w.Code)
|
|
||||||
assert.Equal(t, contentType.json, w.Header().Get("Content-Type"))
|
|
||||||
assert.JSONEq(t, expectedIPv6, w.Body.String())
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestAll(t *testing.T) {
|
func TestAll(t *testing.T) {
|
||||||
expected := `IP: 81.2.69.192
|
expected := `IP: 81.2.69.192
|
||||||
Client Port: 1000
|
Client Port: 1001
|
||||||
City: London
|
City: London
|
||||||
Country: United Kingdom
|
Country: United Kingdom
|
||||||
Country Code: GB
|
Country Code: GB
|
||||||
@ -114,13 +247,21 @@ ASN Organization:
|
|||||||
|
|
||||||
Header1: one
|
Header1: one
|
||||||
Host: test
|
Host: test
|
||||||
X-Real-Ip: 81.2.69.192
|
|
||||||
`
|
`
|
||||||
|
_, _ = setting.Setup(
|
||||||
|
[]string{
|
||||||
|
"-geoip2-city", "city",
|
||||||
|
"-geoip2-asn", "asn",
|
||||||
|
"-trusted-header", trustedHeader,
|
||||||
|
"-trusted-port-header", trustedPortHeader,
|
||||||
|
},
|
||||||
|
)
|
||||||
|
|
||||||
req, _ := http.NewRequest("GET", "/all", nil)
|
req, _ := http.NewRequest("GET", "/all", nil)
|
||||||
req.RemoteAddr = net.JoinHostPort(testIP.ipv4, "1000")
|
req.RemoteAddr = net.JoinHostPort(testIP.ipv4, "1000")
|
||||||
req.Host = "test"
|
req.Host = "test"
|
||||||
req.Header.Set("X-Real-IP", testIP.ipv4)
|
req.Header.Set(trustedHeader, testIP.ipv4)
|
||||||
|
req.Header.Set(trustedPortHeader, "1001")
|
||||||
req.Header.Set("Header1", "one")
|
req.Header.Set("Header1", "one")
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
w := httptest.NewRecorder()
|
||||||
|
@ -10,15 +10,17 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
func getHeadersAsSortedString(ctx *gin.Context) {
|
func getHeadersAsSortedString(ctx *gin.Context) {
|
||||||
h := ctx.Request.Header
|
h := httputils.GetHeadersWithoutTrustedHeaders(ctx)
|
||||||
h["Host"] = []string{ctx.Request.Host}
|
h.Set("Host", ctx.Request.Host)
|
||||||
|
|
||||||
ctx.String(http.StatusOK, httputils.HeadersToSortedString(h))
|
ctx.String(http.StatusOK, httputils.HeadersToSortedString(h))
|
||||||
}
|
}
|
||||||
|
|
||||||
func getHeaderAsString(ctx *gin.Context) {
|
func getHeaderAsString(ctx *gin.Context) {
|
||||||
|
headers := httputils.GetHeadersWithoutTrustedHeaders(ctx)
|
||||||
|
|
||||||
h := ctx.Params.ByName("header")
|
h := ctx.Params.ByName("header")
|
||||||
if v := ctx.GetHeader(h); v != "" {
|
if v := headers.Get(ctx.Params.ByName("header")); v != "" {
|
||||||
ctx.String(http.StatusOK, template.HTMLEscapeString(v))
|
ctx.String(http.StatusOK, template.HTMLEscapeString(v))
|
||||||
} else if strings.ToLower(h) == "host" {
|
} else if strings.ToLower(h) == "host" {
|
||||||
ctx.String(http.StatusOK, template.HTMLEscapeString(ctx.Request.Host))
|
ctx.String(http.StatusOK, template.HTMLEscapeString(ctx.Request.Host))
|
||||||
|
@ -5,6 +5,7 @@ import (
|
|||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
|
"github.com/dcarrillo/whatismyip/internal/setting"
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
)
|
)
|
||||||
|
|
||||||
@ -26,13 +27,20 @@ Header2: value22
|
|||||||
Header3: value3
|
Header3: value3
|
||||||
Host:
|
Host:
|
||||||
`
|
`
|
||||||
|
_, _ = setting.Setup([]string{
|
||||||
|
"-geoip2-city", "city",
|
||||||
|
"-geoip2-asn", "asn",
|
||||||
|
"-trusted-header", trustedHeader,
|
||||||
|
"-trusted-port-header", trustedPortHeader,
|
||||||
|
})
|
||||||
req, _ := http.NewRequest("GET", "/headers", nil)
|
req, _ := http.NewRequest("GET", "/headers", nil)
|
||||||
req.Header = map[string][]string{
|
req.Header = map[string][]string{
|
||||||
"Header1": {"value1"},
|
"Header1": {"value1"},
|
||||||
"Header2": {"value21", "value22"},
|
"Header2": {"value21", "value22"},
|
||||||
"Header3": {"value3"},
|
"Header3": {"value3"},
|
||||||
}
|
}
|
||||||
|
req.Header.Set(trustedHeader, "1.1.1.1")
|
||||||
|
req.Header.Set(trustedPortHeader, "1025")
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
w := httptest.NewRecorder()
|
||||||
app.ServeHTTP(w, req)
|
app.ServeHTTP(w, req)
|
||||||
|
@ -16,6 +16,7 @@ type testIPs struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
type contentTypes struct {
|
type contentTypes struct {
|
||||||
|
html string
|
||||||
text string
|
text string
|
||||||
json string
|
json string
|
||||||
}
|
}
|
||||||
@ -29,12 +30,16 @@ var (
|
|||||||
ipv6ASN: "2a02:a800::1",
|
ipv6ASN: "2a02:a800::1",
|
||||||
}
|
}
|
||||||
contentType = contentTypes{
|
contentType = contentTypes{
|
||||||
|
html: "content-type: text/html; charset=utf-8",
|
||||||
text: "text/plain; charset=utf-8",
|
text: "text/plain; charset=utf-8",
|
||||||
json: "application/json; charset=utf-8",
|
json: "application/json; charset=utf-8",
|
||||||
}
|
}
|
||||||
|
jsonIPv4 = `{"client_port":"1001","ip":"81.2.69.192","ip_version":4,"country":"United Kingdom","country_code":"GB","city":"London","latitude":51.5142,"longitude":-0.0931,"postal_code":"","time_zone":"Europe/London","asn":0,"asn_organization":"","host":"test", "headers": {}}`
|
||||||
|
jsonIPv6 = `{"asn":3352, "asn_organization":"TELEFONICA DE ESPANA", "city":"", "client_port":"1001", "country":"", "country_code":"", "host":"test", "ip":"2a02:9000::1", "ip_version":6, "latitude":0, "longitude":0, "postal_code":"", "time_zone":"", "headers": {}}`
|
||||||
)
|
)
|
||||||
|
|
||||||
const trustedHeader = "X-Real-IP"
|
const trustedHeader = "X-Real-IP"
|
||||||
|
const trustedPortHeader = "X-Real-Port"
|
||||||
|
|
||||||
func TestMain(m *testing.M) {
|
func TestMain(m *testing.M) {
|
||||||
app = gin.Default()
|
app = gin.Default()
|
||||||
|
Reference in New Issue
Block a user