refactor(config): render routes from zone domains

This commit is contained in:
ryan
2026-07-12 15:03:24 +08:00
parent d0536fcdd5
commit d4d9bad74d
18 changed files with 190 additions and 283 deletions
+7 -39
View File
@@ -89,7 +89,7 @@ func RenderRouteConfig(doc Document, certificateFiles []SupportFile) (string, er
for _, route := range doc.Routes {
domains := normalizedRouteDomains(route)
if len(domains) == 0 {
return "", fmt.Errorf("route %s domains are invalid", route.Domain)
return "", fmt.Errorf("route %s domains are invalid", route.SiteName)
}
serverNames := renderServerNames(domains)
displayName := resolveRouteSiteName(route)
@@ -642,7 +642,7 @@ func resolveRouteSiteName(route Route) string {
if domains := normalizedRouteDomains(route); len(domains) > 0 {
return domains[0]
}
return strings.TrimSpace(route.Domain)
return ""
}
func buildRouteUpstreamName(route Route) string {
@@ -708,24 +708,13 @@ func renderDefaultServerBlock(statusCode int, http3Enabled bool) string {
}
func normalizedRouteDomains(route Route) []string {
if len(route.Domains) > 0 {
return route.Domains
}
if strings.TrimSpace(route.Domain) == "" {
return nil
}
return []string{strings.TrimSpace(route.Domain)}
return route.Domains
}
func normalizeCertIDs(primaryCertID *uint, certIDs []uint) []uint {
candidates := make([]uint, 0, len(certIDs)+1)
if primaryCertID != nil && *primaryCertID != 0 {
candidates = append(candidates, *primaryCertID)
}
candidates = append(candidates, certIDs...)
seen := make(map[uint]struct{}, len(candidates))
normalized := make([]uint, 0, len(candidates))
for _, id := range candidates {
func certificateIDsFromDomainCertIDs(domainCertIDs []uint) []uint {
seen := make(map[uint]struct{}, len(domainCertIDs))
normalized := make([]uint, 0, len(domainCertIDs))
for _, id := range domainCertIDs {
if id == 0 {
continue
}
@@ -738,27 +727,6 @@ func normalizeCertIDs(primaryCertID *uint, certIDs []uint) []uint {
return normalized
}
func normalizeDomainCertIDs(domains []string, certIDs []uint, domainCertIDs []uint) []uint {
if len(domainCertIDs) > 0 {
normalized := make([]uint, len(domainCertIDs))
copy(normalized, domainCertIDs)
return normalized
}
if len(certIDs) == 1 {
normalized := make([]uint, len(domains))
for index := range normalized {
normalized[index] = certIDs[0]
}
return normalized
}
if len(certIDs) == len(domains) {
normalized := make([]uint, len(certIDs))
copy(normalized, certIDs)
return normalized
}
return []uint{}
}
func certificatesByID(files []SupportFile) map[uint]string {
result := make(map[uint]string)
for _, file := range files {
+8 -8
View File
@@ -34,7 +34,7 @@ func validateRouteCertificates(route Route, displayName string, certIDs []uint,
}
certPEM, ok := certificates[certID]
if !ok {
return fmt.Errorf("route %s certificate %d does not exist", route.Domain, certID)
return fmt.Errorf("route %s certificate %d does not exist", route.SiteName, certID)
}
if err := validateCertificateCoverage(certPEM, assignedDomains); err != nil {
return fmt.Errorf("site %s certificate validation failed: %w", displayName, err)
@@ -105,16 +105,16 @@ func renderProxyRouteHTTPS(
func renderPagesRoute(builder *strings.Builder, route Route, displayName, serverNames string, certificates map[uint]string, limitConfig routeLimitConfig, powEnabled bool, cfg ConfigSnapshot) error {
if route.PagesDeployment == nil {
return fmt.Errorf("route %s pages deployment is missing", route.Domain)
return fmt.Errorf("route %s pages deployment is missing", route.SiteName)
}
if !route.EnableHTTPS {
builder.WriteString(renderHTTPPagesServer(serverNames, displayName, route.PagesDeployment, limitConfig, powEnabled, route.BasicAuthEnabled, route.BasicAuthUsername, route.BasicAuthPassword))
return nil
}
certIDs := normalizeCertIDs(route.CertID, route.CertIDs)
domainCertIDs := normalizeDomainCertIDs(normalizedRouteDomains(route), certIDs, route.DomainCertIDs)
certIDs := certificateIDsFromDomainCertIDs(route.DomainCertIDs)
domainCertIDs := route.DomainCertIDs
if len(certIDs) == 0 {
return fmt.Errorf("路由 %s 未配置证书", route.Domain)
return fmt.Errorf("路由 %s 未配置证书", route.SiteName)
}
partition := partitionRouteDomainsByCert(normalizedRouteDomains(route), certIDs, domainCertIDs)
if err := validateRouteCertificates(route, displayName, certIDs, partition, certificates); err != nil {
@@ -137,10 +137,10 @@ func renderProxyRoute(builder *strings.Builder, route Route, displayName, server
builder.WriteString(renderHTTPProxyServer(serverNames, displayName, route.OriginURL, route.OriginHost, route.CustomHeaders, cacheConfig, limitConfig, upstreamConfig, powEnabled, route.BasicAuthEnabled, route.BasicAuthUsername, route.BasicAuthPassword, cfg))
return nil
}
certIDs := normalizeCertIDs(route.CertID, route.CertIDs)
domainCertIDs := normalizeDomainCertIDs(normalizedRouteDomains(route), certIDs, route.DomainCertIDs)
certIDs := certificateIDsFromDomainCertIDs(route.DomainCertIDs)
domainCertIDs := route.DomainCertIDs
if len(certIDs) == 0 {
return fmt.Errorf("路由 %s 未配置证书", route.Domain)
return fmt.Errorf("路由 %s 未配置证书", route.SiteName)
}
partition := partitionRouteDomainsByCert(normalizedRouteDomains(route), certIDs, domainCertIDs)
if err := validateRouteCertificates(route, displayName, certIDs, partition, certificates); err != nil {
+6 -4
View File
@@ -9,8 +9,8 @@ import (
func TestRenderWAFConfigIncludesAllRouteSiteNames(t *testing.T) {
doc := Document{
Routes: []Route{
{ID: 1, SiteName: "", Domain: "Example.COM", Domains: []string{"example.com", "www.example.com"}},
{ID: 2, SiteName: "named-site", Domain: "other.example.com"},
{ID: 1, SiteName: "example.com", Domains: []string{"example.com", "www.example.com"}},
{ID: 2, SiteName: "named-site", Domains: []string{"other.example.com"}},
},
WAF: WAFDocument{
RuleGroups: []WAFRuleGroup{
@@ -293,7 +293,8 @@ func TestRenderRouteConfigPagesWithoutSPAFallbackServesRoot(t *testing.T) {
Routes: []Route{
{
ID: 1,
Domain: "speedtest.example.com",
SiteName: "speedtest.example.com",
Domains: []string{"speedtest.example.com"},
UpstreamType: "pages",
EnableHTTPS: false,
PagesDeployment: &PagesDeployment{
@@ -325,7 +326,8 @@ func TestRenderRouteConfigPagesWithSPAFallbackServesRoot(t *testing.T) {
Routes: []Route{
{
ID: 1,
Domain: "speedtest.example.com",
SiteName: "speedtest.example.com",
Domains: []string{"speedtest.example.com"},
UpstreamType: "pages",
EnableHTTPS: false,
PagesDeployment: &PagesDeployment{
-3
View File
@@ -135,15 +135,12 @@ func DefaultPoWConfig() PoWConfig {
type Route struct {
ID uint `json:"id,omitempty"`
SiteName string `json:"site_name,omitempty"`
Domain string `json:"domain"`
Domains []string `json:"domains,omitempty"`
OriginURL string `json:"origin_url"`
OriginHost string `json:"origin_host,omitempty"`
Upstreams []string `json:"upstreams,omitempty"`
Enabled bool `json:"enabled"`
EnableHTTPS bool `json:"enable_https"`
CertID *uint `json:"cert_id,omitempty"`
CertIDs []uint `json:"cert_ids,omitempty"`
DomainCertIDs []uint `json:"domain_cert_ids,omitempty"`
RedirectHTTP bool `json:"redirect_http"`
LimitConnPerServer int `json:"limit_conn_per_server,omitempty"`