~bigbes/shroud

ref: 3804bcf465a4eb00d1f03720316d0a176b0b97fb shroud/internal/api/router.go -rw-r--r-- 4.8 KiB
3804bcf4 — Eugene Blikh feat(vless): add VLESS+REALITY transport support 2 months ago
                                                                                
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
package api

import (
	"encoding/base64"
	"encoding/json"
	"fmt"
	"log/slog"
	"net/http"

	"sourcecraft.dev/bigbes/shroud/internal/awgserver"
	"sourcecraft.dev/bigbes/shroud/internal/config"
	"sourcecraft.dev/bigbes/shroud/internal/metrics"
	"sourcecraft.dev/bigbes/shroud/internal/ssserver"
	"sourcecraft.dev/bigbes/shroud/internal/store"
	"sourcecraft.dev/bigbes/shroud/internal/vless"
)

type Handler struct {
	store       store.Store
	ssServer    *ssserver.Server
	awgServer   *awgserver.Server
	awgConfig   *config.AmneziaWGConfig
	vlessServer *vless.Server
	tracker     *metrics.TransferTracker
	version     string
	logger      *slog.Logger
}

func NewHandler(s store.Store, ss *ssserver.Server, awg *awgserver.Server, awgCfg *config.AmneziaWGConfig, vl *vless.Server, tracker *metrics.TransferTracker, version string, logger *slog.Logger) *Handler {
	return &Handler{
		store:       s,
		ssServer:    ss,
		awgServer:   awg,
		awgConfig:   awgCfg,
		vlessServer: vl,
		tracker:     tracker,
		version:     version,
		logger:      logger,
	}
}

// NewRouter creates an HTTP mux with all API routes under the given secret prefix.
func NewRouter(secret string, h *Handler) http.Handler {
	mux := http.NewServeMux()
	prefix := "/" + secret

	// Server endpoints.
	mux.HandleFunc("GET "+prefix+"/server", h.getServer)
	mux.HandleFunc("PUT "+prefix+"/name", h.renameServer)

	// Access key endpoints.
	mux.HandleFunc("GET "+prefix+"/access-keys", h.listAccessKeys)
	mux.HandleFunc("POST "+prefix+"/access-keys", h.createAccessKey)
	mux.HandleFunc("GET "+prefix+"/access-keys/{id}", h.getAccessKey)
	mux.HandleFunc("PUT "+prefix+"/access-keys/{id}", h.createAccessKeyWithID)
	mux.HandleFunc("DELETE "+prefix+"/access-keys/{id}", h.deleteAccessKey)
	mux.HandleFunc("PUT "+prefix+"/access-keys/{id}/name", h.renameAccessKey)

	// Data limit endpoints.
	mux.HandleFunc("PUT "+prefix+"/access-keys/{id}/data-limit", h.setKeyDataLimit)
	mux.HandleFunc("DELETE "+prefix+"/access-keys/{id}/data-limit", h.removeKeyDataLimit)
	mux.HandleFunc("PUT "+prefix+"/server/access-key-data-limit", h.setDefaultDataLimit)
	mux.HandleFunc("DELETE "+prefix+"/server/access-key-data-limit", h.removeDefaultDataLimit)

	// Port and hostname.
	mux.HandleFunc("PUT "+prefix+"/server/port-for-new-access-keys", h.setDefaultPort)
	mux.HandleFunc("PUT "+prefix+"/server/hostname-for-access-keys", h.setHostname)

	// AmneziaWG client config download.
	mux.HandleFunc("GET "+prefix+"/access-keys/{id}/awg-config", h.getAWGConfig)
	// Outline Smart Dialer config (AWG as fallback transport).
	mux.HandleFunc("GET "+prefix+"/access-keys/{id}/outline-config", h.getOutlineConfig)

	// Metrics endpoints.
	mux.HandleFunc("GET "+prefix+"/metrics/enabled", h.getMetricsEnabled)
	mux.HandleFunc("PUT "+prefix+"/metrics/enabled", h.setMetricsEnabled)
	mux.HandleFunc("GET "+prefix+"/metrics/transfer", h.getTransferMetrics)

	return corsMiddleware(mux)
}

func corsMiddleware(next http.Handler) http.Handler {
	return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
		w.Header().Set("Access-Control-Allow-Origin", "*")
		w.Header().Set("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, OPTIONS")
		w.Header().Set("Access-Control-Allow-Headers", "Content-Type")
		if r.Method == http.MethodOptions {
			w.WriteHeader(http.StatusNoContent)
			return
		}
		next.ServeHTTP(w, r)
	})
}

func (h *Handler) syncKeys() error {
	keys := h.store.ListKeys()
	if h.ssServer != nil {
		if err := h.ssServer.SyncKeys(keys); err != nil {
			return err
		}
	}
	if h.awgServer != nil {
		if err := h.awgServer.SyncKeys(keys); err != nil {
			return err
		}
	}
	if h.vlessServer != nil {
		if err := h.vlessServer.SyncKeys(keys); err != nil {
			return err
		}
	}
	return nil
}

func (h *Handler) accessURL(key store.AccessKey) string {
	srv := h.store.GetServer()
	hostname := srv.Hostname
	if hostname == "" {
		hostname = "localhost"
	}
	// SIP002 URI format: ss://base64(method:password)@host:port#tag
	cred := base64.URLEncoding.WithPadding(base64.NoPadding).EncodeToString(
		[]byte(fmt.Sprintf("%s:%s", key.Method, key.Password)),
	)
	return fmt.Sprintf("ss://%s@%s:%d#%s", cred, hostname, key.Port, key.Name)
}

// awgHostname resolves the hostname for AWG client endpoints.
// Uses awg.hostname if set; falls back to serverHostname when muxer is enabled;
// falls back to "localhost" if still empty.
func (h *Handler) awgHostname(serverHostname string) string {
	hostname := h.awgConfig.AWGHostname(serverHostname)
	if hostname == "" {
		hostname = "localhost"
	}
	return hostname
}

func writeJSON(w http.ResponseWriter, status int, v any) {
	w.Header().Set("Content-Type", "application/json")
	w.WriteHeader(status)
	json.NewEncoder(w).Encode(v)
}

func writeError(w http.ResponseWriter, status int, msg string) {
	http.Error(w, msg, status)
}

func readJSON(r *http.Request, v any) error {
	defer r.Body.Close()
	return json.NewDecoder(r.Body).Decode(v)
}