mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-09-29 22:06:38 +08:00
c85373ff47
Result: {"status":"keep","total_issues":8,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_exhaustive":0,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":1,"golint_usestdlibvars":0,"golint_wastedassign":0,"golint_total":8,"golint_test_testifylint":0,"golint_test_thelper":0,"golint_test_usetesting":0,"golint_test_total":0,"golint_vetx_total":0,"eslint_problems":0,"eslint_errors":0,"eslint_warnings":0,"tsc_errors":0,"measure_s":43}
64 lines
1.5 KiB
Go
64 lines
1.5 KiB
Go
// Copyright 2025 linux.do
|
|
// Copyright 2026 Arctel.net
|
|
// SPDX-License-Identifier: Apache-2.0
|
|
|
|
package logs
|
|
|
|
import (
|
|
"net/http"
|
|
"net/url"
|
|
"strconv"
|
|
"strings"
|
|
|
|
"github.com/gorilla/websocket"
|
|
|
|
"github.com/Rain-kl/Wavelet/internal/model"
|
|
"github.com/Rain-kl/Wavelet/internal/repository"
|
|
)
|
|
|
|
// getUpgrader 返回 WebSocket 升级器并执行 Origin 安全检查以防止 CSWSH 攻击
|
|
func getUpgrader() *websocket.Upgrader {
|
|
return &websocket.Upgrader{
|
|
CheckOrigin: func(r *http.Request) bool {
|
|
origin := r.Header.Get("Origin")
|
|
if origin == "" {
|
|
return true
|
|
}
|
|
|
|
// 1. 同源检查 (Same-origin check)
|
|
u, err := url.Parse(origin)
|
|
if err == nil && strings.EqualFold(u.Host, r.Host) {
|
|
return true
|
|
}
|
|
|
|
// 2. 检查配置的允许跨域 Origin (Check allowed origins in system config)
|
|
ctx := r.Context()
|
|
if sc, err := repository.GetSystemConfigByKey(ctx, model.ConfigKeyServerAddress); err == nil && sc.Value != "" {
|
|
originToCheck := strings.TrimRight(strings.TrimSpace(origin), "/")
|
|
allowedOrigins := strings.SplitSeq(sc.Value, ",")
|
|
for allowed := range allowedOrigins {
|
|
allowed = strings.TrimRight(strings.TrimSpace(allowed), "/")
|
|
if allowed != "" && strings.EqualFold(allowed, originToCheck) {
|
|
return true
|
|
}
|
|
}
|
|
}
|
|
return false
|
|
},
|
|
}
|
|
}
|
|
|
|
// parsePositiveInt 解析非负整数字符串
|
|
func parsePositiveInt(s string, result *int) error {
|
|
if s == "" {
|
|
*result = 0
|
|
return nil
|
|
}
|
|
n, err := strconv.Atoi(s)
|
|
if err != nil || n < 0 {
|
|
return err
|
|
}
|
|
*result = n
|
|
return nil
|
|
}
|