mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-06 23:56:37 +08:00
fix(admin): stop console Intl errors and log websocket drops
Use raw i18n for push template hints so ICU does not parse
{{placeholders}}. Pass total into the user list record count.
Allow log websocket origins behind the Next rewrite, skip the
proxy on Upgrade, and do not open a socket after unmount.
This commit is contained in:
@@ -14,6 +14,7 @@ import (
|
|||||||
"errors"
|
"errors"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strconv"
|
"strconv"
|
||||||
|
"strings"
|
||||||
|
|
||||||
"github.com/gin-gonic/gin"
|
"github.com/gin-gonic/gin"
|
||||||
"github.com/gorilla/websocket"
|
"github.com/gorilla/websocket"
|
||||||
@@ -179,11 +180,31 @@ func GetLogsAnalytics(c *gin.Context) {
|
|||||||
func getUpgrader() *websocket.Upgrader {
|
func getUpgrader() *websocket.Upgrader {
|
||||||
return &websocket.Upgrader{
|
return &websocket.Upgrader{
|
||||||
CheckOrigin: func(r *http.Request) bool {
|
CheckOrigin: func(r *http.Request) bool {
|
||||||
return service.IsAllowedLogOrigin(r.Context(), r.Header.Get("Origin"), r.Host)
|
return service.IsAllowedLogOrigin(
|
||||||
|
r.Context(),
|
||||||
|
r.Header.Get("Origin"),
|
||||||
|
r.Host,
|
||||||
|
forwardedHosts(r)...,
|
||||||
|
)
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func forwardedHosts(r *http.Request) []string {
|
||||||
|
raw := r.Header.Get("X-Forwarded-Host")
|
||||||
|
if raw == "" {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
parts := strings.Split(raw, ",")
|
||||||
|
hosts := make([]string, 0, len(parts))
|
||||||
|
for _, part := range parts {
|
||||||
|
if h := strings.TrimSpace(part); h != "" {
|
||||||
|
hosts = append(hosts, h)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return hosts
|
||||||
|
}
|
||||||
|
|
||||||
// errNegativeParam 表示查询参数解析出了负数。
|
// errNegativeParam 表示查询参数解析出了负数。
|
||||||
var errNegativeParam = errors.New("parameter must not be negative")
|
var errNegativeParam = errors.New("parameter must not be negative")
|
||||||
|
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ import (
|
|||||||
"Wavelet/plugins/domain/admin/repository"
|
"Wavelet/plugins/domain/admin/repository"
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"net"
|
||||||
"net/url"
|
"net/url"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
@@ -47,18 +48,20 @@ func RobotsTxtBody(ctx context.Context) string {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// IsAllowedLogOrigin reports whether a WebSocket handshake origin may subscribe to logs.
|
// IsAllowedLogOrigin reports whether a WebSocket handshake origin may subscribe to logs.
|
||||||
func IsAllowedLogOrigin(ctx context.Context, origin, host string) bool {
|
// extraHosts are reverse-proxy hosts such as X-Forwarded-Host (the browser origin
|
||||||
|
// when Next.js rewrites /api to the backend).
|
||||||
|
func IsAllowedLogOrigin(ctx context.Context, origin, host string, extraHosts ...string) bool {
|
||||||
if origin == "" {
|
if origin == "" {
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
// 1. 同源检查 (Same-origin check)
|
|
||||||
u, err := url.Parse(origin)
|
u, err := url.Parse(origin)
|
||||||
if err == nil && strings.EqualFold(u.Host, host) {
|
if err == nil {
|
||||||
return true
|
if originMatchesHost(u.Host, host, extraHosts...) {
|
||||||
|
return true
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// 2. 检查配置的允许跨域 Origin (Check allowed origins in system config)
|
|
||||||
sc, cfgErr := repository.GetSystemConfigByKey(ctx, model.ConfigKeyServerAddress)
|
sc, cfgErr := repository.GetSystemConfigByKey(ctx, model.ConfigKeyServerAddress)
|
||||||
if cfgErr != nil || sc.Value == "" {
|
if cfgErr != nil || sc.Value == "" {
|
||||||
return false
|
return false
|
||||||
@@ -73,6 +76,41 @@ func IsAllowedLogOrigin(ctx context.Context, origin, host string) bool {
|
|||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func originMatchesHost(originHost, host string, extraHosts ...string) bool {
|
||||||
|
if originHost == "" {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
if hostMatches(originHost, host) {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
for _, extra := range extraHosts {
|
||||||
|
if hostMatches(originHost, extra) {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
|
func hostMatches(originHost, candidate string) bool {
|
||||||
|
candidate = strings.TrimSpace(candidate)
|
||||||
|
if candidate == "" {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
if strings.EqualFold(originHost, candidate) {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
// Reverse-proxy / local Next rewrite: Origin is :3000, backend Host is :8000.
|
||||||
|
return strings.EqualFold(hostName(originHost), hostName(candidate))
|
||||||
|
}
|
||||||
|
|
||||||
|
func hostName(hostport string) string {
|
||||||
|
h, _, err := net.SplitHostPort(hostport)
|
||||||
|
if err != nil {
|
||||||
|
return hostport
|
||||||
|
}
|
||||||
|
return h
|
||||||
|
}
|
||||||
|
|
||||||
// AccessLogs queries the analytical access log store and decorates rows with user names.
|
// AccessLogs queries the analytical access log store and decorates rows with user names.
|
||||||
func AccessLogs(ctx context.Context, q model.AccessLogQuery) (model.AccessLogsResponse, error) {
|
func AccessLogs(ctx context.Context, q model.AccessLogQuery) (model.AccessLogsResponse, error) {
|
||||||
rc := GetRiskControlService(ctx)
|
rc := GetRiskControlService(ctx)
|
||||||
|
|||||||
@@ -0,0 +1,55 @@
|
|||||||
|
// Copyright 2026 Arctel.net
|
||||||
|
// SPDX-License-Identifier: Apache-2.0
|
||||||
|
|
||||||
|
package service_test
|
||||||
|
|
||||||
|
import (
|
||||||
|
"Wavelet/plugins/domain/admin/service"
|
||||||
|
"context"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestIsAllowedLogOrigin(t *testing.T) {
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
origin string
|
||||||
|
host string
|
||||||
|
extraHosts []string
|
||||||
|
want bool
|
||||||
|
}{
|
||||||
|
{name: "empty origin", origin: "", host: "localhost:8000", want: true},
|
||||||
|
{name: "same host", origin: "http://localhost:8000", host: "localhost:8000", want: true},
|
||||||
|
{name: "same host different case", origin: "http://LocalHost:8000", host: "localhost:8000", want: true},
|
||||||
|
{
|
||||||
|
name: "next rewrite different port same hostname",
|
||||||
|
origin: "http://localhost:3000",
|
||||||
|
host: "localhost:8000",
|
||||||
|
want: true,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "x-forwarded-host matches origin",
|
||||||
|
origin: "http://localhost:3000",
|
||||||
|
host: "backend:8080",
|
||||||
|
extraHosts: []string{"localhost:3000"},
|
||||||
|
want: true,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "unrelated origin",
|
||||||
|
origin: "https://evil.example",
|
||||||
|
host: "localhost:8000",
|
||||||
|
want: false,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
got := service.IsAllowedLogOrigin(ctx, tt.origin, tt.host, tt.extraHosts...)
|
||||||
|
if got != tt.want {
|
||||||
|
t.Errorf("IsAllowedLogOrigin(%q, %q, %v) = %v, want %v",
|
||||||
|
tt.origin, tt.host, tt.extraHosts, got, tt.want)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -252,10 +252,16 @@ export function AppLogs() {
|
|||||||
|
|
||||||
// ---- Initialize ------------------------------------------------------
|
// ---- Initialize ------------------------------------------------------
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
loadHistory(0).then(() => connectWs());
|
let cancelled = false;
|
||||||
|
loadHistory(0).then(() => {
|
||||||
|
if (cancelled) return;
|
||||||
|
connectWs();
|
||||||
|
});
|
||||||
return () => {
|
return () => {
|
||||||
wsRef.current?.close();
|
cancelled = true;
|
||||||
|
const ws = wsRef.current;
|
||||||
wsRef.current = null;
|
wsRef.current = null;
|
||||||
|
ws?.close();
|
||||||
};
|
};
|
||||||
// eslint-disable-next-line react-hooks/exhaustive-deps
|
// eslint-disable-next-line react-hooks/exhaustive-deps
|
||||||
}, []);
|
}, []);
|
||||||
|
|||||||
@@ -713,8 +713,8 @@ export function EventsTab() {
|
|||||||
</Label>
|
</Label>
|
||||||
<span className='text-[10px] text-muted-foreground font-mono flex items-center'>
|
<span className='text-[10px] text-muted-foreground font-mono flex items-center'>
|
||||||
{newEventType === 'task'
|
{newEventType === 'task'
|
||||||
? t('taskTemplateVars')
|
? t.raw('taskTemplateVars')
|
||||||
: t('eventTemplateVars')}
|
: t.raw('eventTemplateVars')}
|
||||||
</span>
|
</span>
|
||||||
</div>
|
</div>
|
||||||
<Textarea
|
<Textarea
|
||||||
@@ -893,8 +893,8 @@ export function EventsTab() {
|
|||||||
</Label>
|
</Label>
|
||||||
<span className='text-[10px] text-muted-foreground font-mono flex items-center'>
|
<span className='text-[10px] text-muted-foreground font-mono flex items-center'>
|
||||||
{selectedEvent.task_type
|
{selectedEvent.task_type
|
||||||
? t('taskTemplateVars')
|
? t.raw('taskTemplateVars')
|
||||||
: t('eventTemplateVars')}
|
: t.raw('eventTemplateVars')}
|
||||||
</span>
|
</span>
|
||||||
</div>
|
</div>
|
||||||
<Textarea
|
<Textarea
|
||||||
|
|||||||
@@ -218,7 +218,7 @@ export function UserFilterBar() {
|
|||||||
|
|
||||||
<div className='flex items-center gap-1.5 self-end lg:self-auto'>
|
<div className='flex items-center gap-1.5 self-end lg:self-auto'>
|
||||||
<span className='text-[10px] text-muted-foreground whitespace-nowrap'>
|
<span className='text-[10px] text-muted-foreground whitespace-nowrap'>
|
||||||
{t('totalRecords', { count: total })}
|
{t('totalRecords', { total })}
|
||||||
</span>
|
</span>
|
||||||
<div className='flex items-center border border-dashed rounded-md shadow-none'>
|
<div className='flex items-center border border-dashed rounded-md shadow-none'>
|
||||||
<Button
|
<Button
|
||||||
|
|||||||
+7
-2
@@ -81,6 +81,11 @@ export function proxy(request: NextRequest) {
|
|||||||
process.env.WAVELET_SESSION_COOKIE_NAME || 'wavelet_session_id';
|
process.env.WAVELET_SESSION_COOKIE_NAME || 'wavelet_session_id';
|
||||||
const sessionCookie = request.cookies.get(sessionCookieName);
|
const sessionCookie = request.cookies.get(sessionCookieName);
|
||||||
|
|
||||||
|
// WebSocket upgrades must pass through to rewrites untouched.
|
||||||
|
if (request.headers.get('upgrade')?.toLowerCase() === 'websocket') {
|
||||||
|
return NextResponse.next();
|
||||||
|
}
|
||||||
|
|
||||||
/* API 请求:速率限制后放行 */
|
/* API 请求:速率限制后放行 */
|
||||||
if (pathname.startsWith('/api/')) {
|
if (pathname.startsWith('/api/')) {
|
||||||
const rateLimitEnabled = process.env.WAVELET_RATE_LIMIT_ENABLED === 'true';
|
const rateLimitEnabled = process.env.WAVELET_RATE_LIMIT_ENABLED === 'true';
|
||||||
@@ -136,7 +141,7 @@ export function proxy(request: NextRequest) {
|
|||||||
|
|
||||||
export const config = {
|
export const config = {
|
||||||
matcher: [
|
matcher: [
|
||||||
'/api/:path*',
|
'/api/((?!v1/admin/logs/ws).*)',
|
||||||
'/((?!_next|favicon.ico|robots.txt|sitemap.xml|.*\\.(?:jpg|jpeg|gif|png|svg|ico|webp)).*)',
|
'/((?!_next|favicon.ico|robots.txt|sitemap.xml|api/v1/admin/logs/ws|.*\\.(?:jpg|jpeg|gif|png|svg|ico|webp)).*)',
|
||||||
],
|
],
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user