mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-10 17:26:38 +08:00
[优化] 增强流量可观测性,添加请求长度和字节发送字段;更新支持文件权限设置
This commit is contained in:
@@ -6,6 +6,7 @@ import (
|
||||
"encoding/hex"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io/fs"
|
||||
"log/slog"
|
||||
"os"
|
||||
"os/exec"
|
||||
@@ -529,7 +530,7 @@ func (m *Manager) restore(state *backupState) error {
|
||||
if err := os.MkdirAll(filepath.Dir(targetPath), 0o755); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := os.WriteFile(targetPath, []byte(file.Content), 0o600); err != nil {
|
||||
if err := os.WriteFile(targetPath, []byte(file.Content), supportFileMode(file.Path)); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
@@ -554,7 +555,7 @@ func (m *Manager) writeSupportFiles(supportFiles []protocol.SupportFile) error {
|
||||
if err := os.MkdirAll(filepath.Dir(targetPath), 0o755); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := os.WriteFile(targetPath, []byte(file.Content), 0o600); err != nil {
|
||||
if err := os.WriteFile(targetPath, []byte(file.Content), supportFileMode(file.Path)); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
@@ -628,6 +629,17 @@ func (m *Manager) supportFileTargetPath(relativePath string) (string, error) {
|
||||
return targetPath, nil
|
||||
}
|
||||
|
||||
func supportFileMode(relativePath string) fs.FileMode {
|
||||
switch strings.ToLower(filepath.Ext(strings.TrimSpace(relativePath))) {
|
||||
case ".lua", ".crt", ".pem":
|
||||
return 0o644
|
||||
case ".key":
|
||||
return 0o600
|
||||
default:
|
||||
return 0o644
|
||||
}
|
||||
}
|
||||
|
||||
func (m *Manager) renderRouteConfig(content string) string {
|
||||
if m.NginxSupportDir == "" {
|
||||
return content
|
||||
|
||||
@@ -497,6 +497,64 @@ func TestManagerApplyWritesSupportFilesAndReplacesPlaceholder(t *testing.T) {
|
||||
if string(certData) != "cert-data" {
|
||||
t.Fatalf("unexpected cert file content: %s", string(certData))
|
||||
}
|
||||
luaInfo, err := os.Stat(filepath.Join(manager.SupportDir, "observability", "log.lua"))
|
||||
if err == nil {
|
||||
t.Fatalf("expected no lua file in this test, got %v", luaInfo)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSupportFileMode(t *testing.T) {
|
||||
testCases := []struct {
|
||||
path string
|
||||
want os.FileMode
|
||||
}{
|
||||
{path: "observability/log.lua", want: 0o644},
|
||||
{path: "1.crt", want: 0o644},
|
||||
{path: "1.pem", want: 0o644},
|
||||
{path: "1.key", want: 0o600},
|
||||
{path: "misc.txt", want: 0o644},
|
||||
}
|
||||
|
||||
for _, testCase := range testCases {
|
||||
if got := supportFileMode(testCase.path); got != testCase.want {
|
||||
t.Fatalf("unexpected mode for %s: got %o want %o", testCase.path, got, testCase.want)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestManagerApplyWritesLuaSupportFilesReadable(t *testing.T) {
|
||||
tempDir := t.TempDir()
|
||||
manager := &Manager{
|
||||
MainConfigPath: filepath.Join(tempDir, "nginx.conf"),
|
||||
RouteConfigPath: filepath.Join(tempDir, "routes.conf"),
|
||||
SupportDir: filepath.Join(tempDir, "support"),
|
||||
NginxSupportDir: "/etc/nginx/atsflare-support",
|
||||
Executor: &fakeExecutor{},
|
||||
}
|
||||
|
||||
err := manager.Apply(context.Background(), "main", "route", []protocol.SupportFile{
|
||||
{Path: "observability/log.lua", Content: "return"},
|
||||
{Path: "1.key", Content: "secret"},
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("Apply failed: %v", err)
|
||||
}
|
||||
|
||||
luaInfo, err := os.Stat(filepath.Join(manager.SupportDir, "observability", "log.lua"))
|
||||
if err != nil {
|
||||
t.Fatalf("failed to stat lua file: %v", err)
|
||||
}
|
||||
if luaInfo.Mode().Perm() != 0o644 {
|
||||
t.Fatalf("unexpected lua mode: %o", luaInfo.Mode().Perm())
|
||||
}
|
||||
|
||||
keyInfo, err := os.Stat(filepath.Join(manager.SupportDir, "1.key"))
|
||||
if err != nil {
|
||||
t.Fatalf("failed to stat key file: %v", err)
|
||||
}
|
||||
if keyInfo.Mode().Perm() != 0o600 {
|
||||
t.Fatalf("unexpected key mode: %o", keyInfo.Mode().Perm())
|
||||
}
|
||||
}
|
||||
|
||||
func TestManagerRollbackRestoresSupportFiles(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user