mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-01 14:46:36 +08:00
refactor(config): render routes from zone domains
This commit is contained in:
@@ -89,7 +89,7 @@ func RenderRouteConfig(doc Document, certificateFiles []SupportFile) (string, er
|
||||
for _, route := range doc.Routes {
|
||||
domains := normalizedRouteDomains(route)
|
||||
if len(domains) == 0 {
|
||||
return "", fmt.Errorf("route %s domains are invalid", route.Domain)
|
||||
return "", fmt.Errorf("route %s domains are invalid", route.SiteName)
|
||||
}
|
||||
serverNames := renderServerNames(domains)
|
||||
displayName := resolveRouteSiteName(route)
|
||||
@@ -642,7 +642,7 @@ func resolveRouteSiteName(route Route) string {
|
||||
if domains := normalizedRouteDomains(route); len(domains) > 0 {
|
||||
return domains[0]
|
||||
}
|
||||
return strings.TrimSpace(route.Domain)
|
||||
return ""
|
||||
}
|
||||
|
||||
func buildRouteUpstreamName(route Route) string {
|
||||
@@ -708,24 +708,13 @@ func renderDefaultServerBlock(statusCode int, http3Enabled bool) string {
|
||||
}
|
||||
|
||||
func normalizedRouteDomains(route Route) []string {
|
||||
if len(route.Domains) > 0 {
|
||||
return route.Domains
|
||||
}
|
||||
if strings.TrimSpace(route.Domain) == "" {
|
||||
return nil
|
||||
}
|
||||
return []string{strings.TrimSpace(route.Domain)}
|
||||
return route.Domains
|
||||
}
|
||||
|
||||
func normalizeCertIDs(primaryCertID *uint, certIDs []uint) []uint {
|
||||
candidates := make([]uint, 0, len(certIDs)+1)
|
||||
if primaryCertID != nil && *primaryCertID != 0 {
|
||||
candidates = append(candidates, *primaryCertID)
|
||||
}
|
||||
candidates = append(candidates, certIDs...)
|
||||
seen := make(map[uint]struct{}, len(candidates))
|
||||
normalized := make([]uint, 0, len(candidates))
|
||||
for _, id := range candidates {
|
||||
func certificateIDsFromDomainCertIDs(domainCertIDs []uint) []uint {
|
||||
seen := make(map[uint]struct{}, len(domainCertIDs))
|
||||
normalized := make([]uint, 0, len(domainCertIDs))
|
||||
for _, id := range domainCertIDs {
|
||||
if id == 0 {
|
||||
continue
|
||||
}
|
||||
@@ -738,27 +727,6 @@ func normalizeCertIDs(primaryCertID *uint, certIDs []uint) []uint {
|
||||
return normalized
|
||||
}
|
||||
|
||||
func normalizeDomainCertIDs(domains []string, certIDs []uint, domainCertIDs []uint) []uint {
|
||||
if len(domainCertIDs) > 0 {
|
||||
normalized := make([]uint, len(domainCertIDs))
|
||||
copy(normalized, domainCertIDs)
|
||||
return normalized
|
||||
}
|
||||
if len(certIDs) == 1 {
|
||||
normalized := make([]uint, len(domains))
|
||||
for index := range normalized {
|
||||
normalized[index] = certIDs[0]
|
||||
}
|
||||
return normalized
|
||||
}
|
||||
if len(certIDs) == len(domains) {
|
||||
normalized := make([]uint, len(certIDs))
|
||||
copy(normalized, certIDs)
|
||||
return normalized
|
||||
}
|
||||
return []uint{}
|
||||
}
|
||||
|
||||
func certificatesByID(files []SupportFile) map[uint]string {
|
||||
result := make(map[uint]string)
|
||||
for _, file := range files {
|
||||
|
||||
@@ -34,7 +34,7 @@ func validateRouteCertificates(route Route, displayName string, certIDs []uint,
|
||||
}
|
||||
certPEM, ok := certificates[certID]
|
||||
if !ok {
|
||||
return fmt.Errorf("route %s certificate %d does not exist", route.Domain, certID)
|
||||
return fmt.Errorf("route %s certificate %d does not exist", route.SiteName, certID)
|
||||
}
|
||||
if err := validateCertificateCoverage(certPEM, assignedDomains); err != nil {
|
||||
return fmt.Errorf("site %s certificate validation failed: %w", displayName, err)
|
||||
@@ -105,16 +105,16 @@ func renderProxyRouteHTTPS(
|
||||
|
||||
func renderPagesRoute(builder *strings.Builder, route Route, displayName, serverNames string, certificates map[uint]string, limitConfig routeLimitConfig, powEnabled bool, cfg ConfigSnapshot) error {
|
||||
if route.PagesDeployment == nil {
|
||||
return fmt.Errorf("route %s pages deployment is missing", route.Domain)
|
||||
return fmt.Errorf("route %s pages deployment is missing", route.SiteName)
|
||||
}
|
||||
if !route.EnableHTTPS {
|
||||
builder.WriteString(renderHTTPPagesServer(serverNames, displayName, route.PagesDeployment, limitConfig, powEnabled, route.BasicAuthEnabled, route.BasicAuthUsername, route.BasicAuthPassword))
|
||||
return nil
|
||||
}
|
||||
certIDs := normalizeCertIDs(route.CertID, route.CertIDs)
|
||||
domainCertIDs := normalizeDomainCertIDs(normalizedRouteDomains(route), certIDs, route.DomainCertIDs)
|
||||
certIDs := certificateIDsFromDomainCertIDs(route.DomainCertIDs)
|
||||
domainCertIDs := route.DomainCertIDs
|
||||
if len(certIDs) == 0 {
|
||||
return fmt.Errorf("路由 %s 未配置证书", route.Domain)
|
||||
return fmt.Errorf("路由 %s 未配置证书", route.SiteName)
|
||||
}
|
||||
partition := partitionRouteDomainsByCert(normalizedRouteDomains(route), certIDs, domainCertIDs)
|
||||
if err := validateRouteCertificates(route, displayName, certIDs, partition, certificates); err != nil {
|
||||
@@ -137,10 +137,10 @@ func renderProxyRoute(builder *strings.Builder, route Route, displayName, server
|
||||
builder.WriteString(renderHTTPProxyServer(serverNames, displayName, route.OriginURL, route.OriginHost, route.CustomHeaders, cacheConfig, limitConfig, upstreamConfig, powEnabled, route.BasicAuthEnabled, route.BasicAuthUsername, route.BasicAuthPassword, cfg))
|
||||
return nil
|
||||
}
|
||||
certIDs := normalizeCertIDs(route.CertID, route.CertIDs)
|
||||
domainCertIDs := normalizeDomainCertIDs(normalizedRouteDomains(route), certIDs, route.DomainCertIDs)
|
||||
certIDs := certificateIDsFromDomainCertIDs(route.DomainCertIDs)
|
||||
domainCertIDs := route.DomainCertIDs
|
||||
if len(certIDs) == 0 {
|
||||
return fmt.Errorf("路由 %s 未配置证书", route.Domain)
|
||||
return fmt.Errorf("路由 %s 未配置证书", route.SiteName)
|
||||
}
|
||||
partition := partitionRouteDomainsByCert(normalizedRouteDomains(route), certIDs, domainCertIDs)
|
||||
if err := validateRouteCertificates(route, displayName, certIDs, partition, certificates); err != nil {
|
||||
|
||||
@@ -9,8 +9,8 @@ import (
|
||||
func TestRenderWAFConfigIncludesAllRouteSiteNames(t *testing.T) {
|
||||
doc := Document{
|
||||
Routes: []Route{
|
||||
{ID: 1, SiteName: "", Domain: "Example.COM", Domains: []string{"example.com", "www.example.com"}},
|
||||
{ID: 2, SiteName: "named-site", Domain: "other.example.com"},
|
||||
{ID: 1, SiteName: "example.com", Domains: []string{"example.com", "www.example.com"}},
|
||||
{ID: 2, SiteName: "named-site", Domains: []string{"other.example.com"}},
|
||||
},
|
||||
WAF: WAFDocument{
|
||||
RuleGroups: []WAFRuleGroup{
|
||||
@@ -293,7 +293,8 @@ func TestRenderRouteConfigPagesWithoutSPAFallbackServesRoot(t *testing.T) {
|
||||
Routes: []Route{
|
||||
{
|
||||
ID: 1,
|
||||
Domain: "speedtest.example.com",
|
||||
SiteName: "speedtest.example.com",
|
||||
Domains: []string{"speedtest.example.com"},
|
||||
UpstreamType: "pages",
|
||||
EnableHTTPS: false,
|
||||
PagesDeployment: &PagesDeployment{
|
||||
@@ -325,7 +326,8 @@ func TestRenderRouteConfigPagesWithSPAFallbackServesRoot(t *testing.T) {
|
||||
Routes: []Route{
|
||||
{
|
||||
ID: 1,
|
||||
Domain: "speedtest.example.com",
|
||||
SiteName: "speedtest.example.com",
|
||||
Domains: []string{"speedtest.example.com"},
|
||||
UpstreamType: "pages",
|
||||
EnableHTTPS: false,
|
||||
PagesDeployment: &PagesDeployment{
|
||||
|
||||
@@ -135,15 +135,12 @@ func DefaultPoWConfig() PoWConfig {
|
||||
type Route struct {
|
||||
ID uint `json:"id,omitempty"`
|
||||
SiteName string `json:"site_name,omitempty"`
|
||||
Domain string `json:"domain"`
|
||||
Domains []string `json:"domains,omitempty"`
|
||||
OriginURL string `json:"origin_url"`
|
||||
OriginHost string `json:"origin_host,omitempty"`
|
||||
Upstreams []string `json:"upstreams,omitempty"`
|
||||
Enabled bool `json:"enabled"`
|
||||
EnableHTTPS bool `json:"enable_https"`
|
||||
CertID *uint `json:"cert_id,omitempty"`
|
||||
CertIDs []uint `json:"cert_ids,omitempty"`
|
||||
DomainCertIDs []uint `json:"domain_cert_ids,omitempty"`
|
||||
RedirectHTTP bool `json:"redirect_http"`
|
||||
LimitConnPerServer int `json:"limit_conn_per_server,omitempty"`
|
||||
|
||||
Reference in New Issue
Block a user