feat: replace cert_dir with support_dir in agent and server configurations

- Updated README.md to reflect the new support_dir for auxiliary files.
- Refactored agent main.go to use support_dir instead of cert_dir.
- Modified config.go to replace cert_dir with support_dir and added legacy support.
- Adjusted config tests to validate support_dir usage.
- Changed nginx manager to utilize support_dir for file paths.
- Updated server configuration to use support_dir for SSL certificates.
- Revised documentation to clarify the new configuration parameters.
- Enhanced security checks for support file paths to prevent traversal attacks.
This commit is contained in:
ryan
2026-03-14 17:16:54 +08:00
parent bdfa80f214
commit 4be44733e8
11 changed files with 159 additions and 143 deletions
+3 -3
View File
@@ -115,7 +115,7 @@ type configBundle struct {
}
const (
nginxCertDirPlaceholder = "__ATSF_CERT_DIR__"
nginxSupportDirPlaceholder = "__ATSF_SUPPORT_DIR__"
nginxRouteConfigPlaceholder = "__ATSF_ROUTE_CONFIG__"
nginxAccessLogPlaceholder = "__ATSF_ACCESS_LOG__"
nginxLuaDirPlaceholder = "__ATSF_LUA_DIR__"
@@ -751,8 +751,8 @@ func renderHTTPRedirectServer(domain string) string {
}
func renderHTTPSServer(domain string, originURL string, certificateID uint, customHeaders []ProxyRouteCustomHeaderInput) string {
certPath := fmt.Sprintf("%s/%s", nginxCertDirPlaceholder, certificateCertFileName(certificateID))
keyPath := fmt.Sprintf("%s/%s", nginxCertDirPlaceholder, certificateKeyFileName(certificateID))
certPath := fmt.Sprintf("%s/%s", nginxSupportDirPlaceholder, certificateCertFileName(certificateID))
keyPath := fmt.Sprintf("%s/%s", nginxSupportDirPlaceholder, certificateKeyFileName(certificateID))
return fmt.Sprintf("server {\n listen 443 ssl;\n server_name %s;\n ssl_certificate %s;\n ssl_certificate_key %s;\n\n location / {\n%s proxy_pass %s;\n }\n}\n\n", domain, certPath, keyPath, renderProxyHeaderBlock(customHeaders), originURL)
}
+2 -2
View File
@@ -69,8 +69,8 @@ func TestCreateTLSCertificateAndRenderHTTPSConfig(t *testing.T) {
if !strings.Contains(result.Version.RenderedConfig, "return 301 https://$host$request_uri;") {
t.Fatal("expected rendered config to include http redirect")
}
if !strings.Contains(result.Version.RenderedConfig, "__ATSF_CERT_DIR__/") {
t.Fatal("expected rendered config to keep certificate dir placeholder")
if !strings.Contains(result.Version.RenderedConfig, "__ATSF_SUPPORT_DIR__/") {
t.Fatal("expected rendered config to keep support dir placeholder for certificates")
}
if !strings.Contains(result.Version.SupportFilesJSON, ".crt") || !strings.Contains(result.Version.SupportFilesJSON, ".key") {
t.Fatal("expected support files to contain certificate and key")