2018-09-21 15:18:23 +00:00
|
|
|
package carrier
|
|
|
|
|
|
|
|
import (
|
|
|
|
"bytes"
|
|
|
|
"io"
|
|
|
|
"net"
|
|
|
|
"net/http"
|
|
|
|
"net/http/httptest"
|
|
|
|
"sync"
|
|
|
|
"testing"
|
|
|
|
|
|
|
|
ws "github.com/gorilla/websocket"
|
2020-11-25 06:55:13 +00:00
|
|
|
"github.com/rs/zerolog"
|
2018-09-21 15:18:23 +00:00
|
|
|
"github.com/stretchr/testify/assert"
|
|
|
|
)
|
|
|
|
|
|
|
|
const (
|
|
|
|
// example in Sec-Websocket-Key in rfc6455
|
|
|
|
testSecWebsocketKey = "dGhlIHNhbXBsZSBub25jZQ=="
|
|
|
|
)
|
|
|
|
|
|
|
|
type testStreamer struct {
|
|
|
|
buf *bytes.Buffer
|
|
|
|
l sync.RWMutex
|
|
|
|
}
|
|
|
|
|
|
|
|
func newTestStream() *testStreamer {
|
|
|
|
return &testStreamer{buf: new(bytes.Buffer)}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *testStreamer) Read(p []byte) (int, error) {
|
|
|
|
s.l.RLock()
|
|
|
|
defer s.l.RUnlock()
|
|
|
|
return s.buf.Read(p)
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
func (s *testStreamer) Write(p []byte) (int, error) {
|
|
|
|
s.l.Lock()
|
|
|
|
defer s.l.Unlock()
|
|
|
|
return s.buf.Write(p)
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestStartClient(t *testing.T) {
|
|
|
|
message := "Good morning Austin! Time for another sunny day in the great state of Texas."
|
2020-11-25 06:55:13 +00:00
|
|
|
log := zerolog.Nop()
|
2021-02-10 16:19:55 +00:00
|
|
|
wsConn := NewWSConnection(&log)
|
2018-09-21 15:18:23 +00:00
|
|
|
ts := newTestWebSocketServer()
|
|
|
|
defer ts.Close()
|
|
|
|
|
|
|
|
buf := newTestStream()
|
2019-01-23 21:42:10 +00:00
|
|
|
options := &StartOptions{
|
2019-05-22 20:41:21 +00:00
|
|
|
OriginURL: "http://" + ts.Listener.Addr().String(),
|
|
|
|
Headers: nil,
|
2019-01-23 21:42:10 +00:00
|
|
|
}
|
2020-03-31 14:56:22 +00:00
|
|
|
err := StartClient(wsConn, buf, options)
|
2018-09-21 15:18:23 +00:00
|
|
|
assert.NoError(t, err)
|
2020-11-25 06:55:13 +00:00
|
|
|
_, _ = buf.Write([]byte(message))
|
2018-09-21 15:18:23 +00:00
|
|
|
|
|
|
|
readBuffer := make([]byte, len(message))
|
2020-11-25 06:55:13 +00:00
|
|
|
_, _ = buf.Read(readBuffer)
|
2018-09-21 15:18:23 +00:00
|
|
|
assert.Equal(t, message, string(readBuffer))
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestStartServer(t *testing.T) {
|
2019-04-05 06:57:00 +00:00
|
|
|
listener, err := net.Listen("tcp", "localhost:")
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Error starting listener: %v", err)
|
|
|
|
}
|
2018-09-21 15:18:23 +00:00
|
|
|
message := "Good morning Austin! Time for another sunny day in the great state of Texas."
|
2020-11-25 06:55:13 +00:00
|
|
|
log := zerolog.Nop()
|
2018-09-21 15:18:23 +00:00
|
|
|
shutdownC := make(chan struct{})
|
2021-02-10 16:19:55 +00:00
|
|
|
wsConn := NewWSConnection(&log)
|
2018-09-21 15:18:23 +00:00
|
|
|
ts := newTestWebSocketServer()
|
|
|
|
defer ts.Close()
|
2019-01-23 21:42:10 +00:00
|
|
|
options := &StartOptions{
|
2019-05-22 20:41:21 +00:00
|
|
|
OriginURL: "http://" + ts.Listener.Addr().String(),
|
|
|
|
Headers: nil,
|
2019-01-23 21:42:10 +00:00
|
|
|
}
|
2018-09-21 15:18:23 +00:00
|
|
|
|
|
|
|
go func() {
|
2020-03-31 14:56:22 +00:00
|
|
|
err := Serve(wsConn, listener, shutdownC, options)
|
2018-10-26 20:58:43 +00:00
|
|
|
if err != nil {
|
2021-03-16 14:47:57 +00:00
|
|
|
t.Errorf("Error running server: %v", err)
|
|
|
|
return
|
2018-10-26 20:58:43 +00:00
|
|
|
}
|
2018-09-21 15:18:23 +00:00
|
|
|
}()
|
|
|
|
|
2019-04-05 06:57:00 +00:00
|
|
|
conn, err := net.Dial("tcp", listener.Addr().String())
|
2020-11-25 06:55:13 +00:00
|
|
|
_, _ = conn.Write([]byte(message))
|
2018-09-21 15:18:23 +00:00
|
|
|
|
|
|
|
readBuffer := make([]byte, len(message))
|
2020-11-25 06:55:13 +00:00
|
|
|
_, _ = conn.Read(readBuffer)
|
2018-09-21 15:18:23 +00:00
|
|
|
assert.Equal(t, string(readBuffer), message)
|
|
|
|
}
|
|
|
|
|
2019-06-26 15:48:45 +00:00
|
|
|
func TestIsAccessResponse(t *testing.T) {
|
|
|
|
validLocationHeader := http.Header{}
|
|
|
|
validLocationHeader.Add("location", "https://test.cloudflareaccess.com/cdn-cgi/access/login/blahblah")
|
|
|
|
invalidLocationHeader := http.Header{}
|
|
|
|
invalidLocationHeader.Add("location", "https://google.com")
|
|
|
|
testCases := []struct {
|
|
|
|
Description string
|
|
|
|
In *http.Response
|
|
|
|
ExpectedOut bool
|
|
|
|
}{
|
|
|
|
{"nil response", nil, false},
|
2019-09-19 18:47:08 +00:00
|
|
|
{"redirect with no location", &http.Response{StatusCode: http.StatusFound}, false},
|
2019-06-26 15:48:45 +00:00
|
|
|
{"200 ok", &http.Response{StatusCode: http.StatusOK}, false},
|
2019-09-19 18:47:08 +00:00
|
|
|
{"redirect with location", &http.Response{StatusCode: http.StatusFound, Header: validLocationHeader}, true},
|
|
|
|
{"redirect with invalid location", &http.Response{StatusCode: http.StatusFound, Header: invalidLocationHeader}, false},
|
2019-06-26 15:48:45 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
for i, tc := range testCases {
|
2019-09-19 18:47:08 +00:00
|
|
|
if IsAccessResponse(tc.In) != tc.ExpectedOut {
|
2019-06-26 15:48:45 +00:00
|
|
|
t.Fatalf("Failed case %d -- %s", i, tc.Description)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
|
|
|
|
2018-09-21 15:18:23 +00:00
|
|
|
func newTestWebSocketServer() *httptest.Server {
|
|
|
|
upgrader := ws.Upgrader{
|
|
|
|
ReadBufferSize: 1024,
|
|
|
|
WriteBufferSize: 1024,
|
|
|
|
}
|
|
|
|
|
|
|
|
return httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
|
|
conn, _ := upgrader.Upgrade(w, r, nil)
|
|
|
|
defer conn.Close()
|
|
|
|
for {
|
|
|
|
mt, message, err := conn.ReadMessage()
|
|
|
|
if err != nil {
|
|
|
|
break
|
|
|
|
}
|
|
|
|
|
|
|
|
if err := conn.WriteMessage(mt, []byte(message)); err != nil {
|
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}))
|
|
|
|
}
|
|
|
|
|
|
|
|
func testRequest(t *testing.T, url string, stream io.ReadWriter) *http.Request {
|
|
|
|
req, err := http.NewRequest("GET", url, stream)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("testRequestHeader error")
|
|
|
|
}
|
|
|
|
|
|
|
|
req.Header.Add("Connection", "Upgrade")
|
|
|
|
req.Header.Add("Upgrade", "WebSocket")
|
|
|
|
req.Header.Add("Sec-Websocket-Key", testSecWebsocketKey)
|
|
|
|
req.Header.Add("Sec-Websocket-Protocol", "tunnel-protocol")
|
|
|
|
req.Header.Add("Sec-Websocket-Version", "13")
|
|
|
|
req.Header.Add("User-Agent", "curl/7.59.0")
|
|
|
|
|
|
|
|
return req
|
|
|
|
}
|
2021-03-26 04:04:56 +00:00
|
|
|
|
|
|
|
func TestBastionDestination(t *testing.T) {
|
|
|
|
tests := []struct {
|
|
|
|
name string
|
|
|
|
header http.Header
|
|
|
|
expectedDest string
|
|
|
|
wantErr bool
|
2024-05-09 19:07:59 +00:00
|
|
|
bastionMode bool
|
|
|
|
service string
|
2021-03-26 04:04:56 +00:00
|
|
|
}{
|
|
|
|
{
|
|
|
|
name: "hostname destination",
|
|
|
|
header: http.Header{
|
2024-05-09 19:07:59 +00:00
|
|
|
CFJumpDestinationHeader: []string{"localhost"},
|
2021-03-26 04:04:56 +00:00
|
|
|
},
|
|
|
|
expectedDest: "localhost",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "hostname destination with port",
|
|
|
|
header: http.Header{
|
2024-05-09 19:07:59 +00:00
|
|
|
CFJumpDestinationHeader: []string{"localhost:9000"},
|
2021-03-26 04:04:56 +00:00
|
|
|
},
|
|
|
|
expectedDest: "localhost:9000",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "hostname destination with scheme and port",
|
|
|
|
header: http.Header{
|
2024-05-09 19:07:59 +00:00
|
|
|
CFJumpDestinationHeader: []string{"ssh://localhost:9000"},
|
2021-03-26 04:04:56 +00:00
|
|
|
},
|
|
|
|
expectedDest: "localhost:9000",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "full hostname url",
|
|
|
|
header: http.Header{
|
2024-05-09 19:07:59 +00:00
|
|
|
CFJumpDestinationHeader: []string{"ssh://localhost:9000/metrics"},
|
2021-03-26 04:04:56 +00:00
|
|
|
},
|
|
|
|
expectedDest: "localhost:9000",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "hostname destination with port and path",
|
|
|
|
header: http.Header{
|
2024-05-09 19:07:59 +00:00
|
|
|
CFJumpDestinationHeader: []string{"localhost:9000/metrics"},
|
2021-03-26 04:04:56 +00:00
|
|
|
},
|
|
|
|
expectedDest: "localhost:9000",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "ip destination",
|
|
|
|
header: http.Header{
|
2024-05-09 19:07:59 +00:00
|
|
|
CFJumpDestinationHeader: []string{"127.0.0.1"},
|
2021-03-26 04:04:56 +00:00
|
|
|
},
|
|
|
|
expectedDest: "127.0.0.1",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "ip destination with port",
|
|
|
|
header: http.Header{
|
2024-05-09 19:07:59 +00:00
|
|
|
CFJumpDestinationHeader: []string{"127.0.0.1:9000"},
|
2021-03-26 04:04:56 +00:00
|
|
|
},
|
|
|
|
expectedDest: "127.0.0.1:9000",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "ip destination with port and path",
|
|
|
|
header: http.Header{
|
2024-05-09 19:07:59 +00:00
|
|
|
CFJumpDestinationHeader: []string{"127.0.0.1:9000/metrics"},
|
2021-03-26 04:04:56 +00:00
|
|
|
},
|
|
|
|
expectedDest: "127.0.0.1:9000",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "ip destination with schem and port",
|
|
|
|
header: http.Header{
|
2024-05-09 19:07:59 +00:00
|
|
|
CFJumpDestinationHeader: []string{"tcp://127.0.0.1:9000"},
|
2021-03-26 04:04:56 +00:00
|
|
|
},
|
|
|
|
expectedDest: "127.0.0.1:9000",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "full ip url",
|
|
|
|
header: http.Header{
|
2024-05-09 19:07:59 +00:00
|
|
|
CFJumpDestinationHeader: []string{"ssh://127.0.0.1:9000/metrics"},
|
|
|
|
},
|
|
|
|
expectedDest: "127.0.0.1:9000",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "full ip url with bastion mode",
|
|
|
|
header: http.Header{
|
|
|
|
CFJumpDestinationHeader: []string{"ssh://127.0.0.1:9000/metrics"},
|
|
|
|
},
|
|
|
|
bastionMode: true,
|
|
|
|
service: "ssh://127.0.0.1:9002/metrics",
|
|
|
|
expectedDest: "127.0.0.1:9002",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "ip destination with port and path with bastion mode",
|
|
|
|
header: http.Header{
|
|
|
|
CFJumpDestinationHeader: []string{"127.0.0.1:9000/metrics"},
|
|
|
|
},
|
|
|
|
bastionMode: true,
|
|
|
|
service: "127.0.0.1:9002/metrics",
|
|
|
|
expectedDest: "127.0.0.1:9002",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "ip destination with port and path without bastion mode",
|
|
|
|
header: http.Header{
|
|
|
|
CFJumpDestinationHeader: []string{"127.0.0.1:9000/metrics"},
|
2021-03-26 04:04:56 +00:00
|
|
|
},
|
2024-05-09 19:07:59 +00:00
|
|
|
bastionMode: false,
|
|
|
|
service: "127.0.0.1:9002/metrics",
|
2021-03-26 04:04:56 +00:00
|
|
|
expectedDest: "127.0.0.1:9000",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "no destination",
|
|
|
|
wantErr: true,
|
|
|
|
},
|
|
|
|
}
|
|
|
|
for _, test := range tests {
|
|
|
|
r := &http.Request{
|
|
|
|
Header: test.header,
|
|
|
|
}
|
2024-05-09 19:07:59 +00:00
|
|
|
dest, err := ResolveBastionDest(r, test.bastionMode, test.service)
|
2021-03-26 04:04:56 +00:00
|
|
|
if test.wantErr {
|
|
|
|
assert.Error(t, err, "Test %s expects error", test.name)
|
|
|
|
} else {
|
|
|
|
assert.NoError(t, err, "Test %s expects no error, got error %v", test.name, err)
|
|
|
|
assert.Equal(t, test.expectedDest, dest, "Test %s expect dest %s, got %s", test.name, test.expectedDest, dest)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|