mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-08 00:26:37 +08:00
feat(cloudflare): add DNS pointing integration
Implement Cloudflare connection management, pointing groups and members, asynchronous A-record reconciliation, node IP triggers, admin APIs, management pages, migrations, tests, and documentation.
This commit is contained in:
@@ -3,40 +3,10 @@
|
||||
|
||||
package tls
|
||||
|
||||
import (
|
||||
"crypto/sha256"
|
||||
"encoding/hex"
|
||||
"errors"
|
||||
"strings"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/infra/config"
|
||||
"github.com/Rain-kl/Wavelet/pkg/util"
|
||||
)
|
||||
|
||||
const sensitiveValuePrefix = "enc:v1:"
|
||||
|
||||
func sensitiveEncryptionKey() string {
|
||||
if config.Config == nil || strings.TrimSpace(config.Config.App.SessionSecret) == "" {
|
||||
return ""
|
||||
}
|
||||
sum := sha256.Sum256([]byte(config.Config.App.SessionSecret))
|
||||
return hex.EncodeToString(sum[:])
|
||||
}
|
||||
import "github.com/Rain-kl/Wavelet/internal/apps/openflare/credential"
|
||||
|
||||
func sealSensitive(plaintext string) (string, error) {
|
||||
plaintext = strings.TrimSpace(plaintext)
|
||||
if plaintext == "" {
|
||||
return "", nil
|
||||
}
|
||||
key := sensitiveEncryptionKey()
|
||||
if key == "" {
|
||||
return plaintext, nil
|
||||
}
|
||||
encrypted, err := util.Encrypt(key, plaintext)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
return sensitiveValuePrefix + encrypted, nil
|
||||
return credential.Seal(plaintext)
|
||||
}
|
||||
|
||||
// OpenKeyPEM decrypts a stored certificate private key for runtime distribution.
|
||||
@@ -45,16 +15,5 @@ func OpenKeyPEM(stored string) (string, error) {
|
||||
}
|
||||
|
||||
func openSensitive(stored string) (string, error) {
|
||||
stored = strings.TrimSpace(stored)
|
||||
if stored == "" {
|
||||
return "", nil
|
||||
}
|
||||
if !strings.HasPrefix(stored, sensitiveValuePrefix) {
|
||||
return stored, nil
|
||||
}
|
||||
key := sensitiveEncryptionKey()
|
||||
if key == "" {
|
||||
return "", errors.New("cannot decrypt sensitive field without session secret")
|
||||
}
|
||||
return util.Decrypt(key, strings.TrimPrefix(stored, sensitiveValuePrefix))
|
||||
return credential.Open(stored)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user