cloudflare/cloudflared

Public

mirrored fromhttps://github.com/cloudflare/cloudflaredAvailable

CodeCommitsIssuesPull requestsActionsInsightsSecurity
2020.6.5

Branches

Tags

  • No tags available.
0Branches0Tags
Go to file
Add file
Code

Clone

HTTPS

Download ZIP

carrier/websocket.go

145lines · modecode

1package carrier
2
3import (
4 "fmt"
5 "io"
6 "net"
7 "net/http"
8 "net/http/httputil"
9
10 "github.com/cloudflare/cloudflared/cmd/cloudflared/token"
11 "github.com/cloudflare/cloudflared/logger"
12 "github.com/cloudflare/cloudflared/socks"
13 cfwebsocket "github.com/cloudflare/cloudflared/websocket"
14 "github.com/gorilla/websocket"
15)
16
17// Websocket is used to carry data via WS binary frames over the tunnel from client to the origin
18// This implements the functions for glider proxy (sock5) and the carrier interface
19type Websocket struct {
20 logger logger.Service
21 isSocks bool
22}
23
24type wsdialer struct {
25 conn *cfwebsocket.Conn
26}
27
28func (d *wsdialer) Dial(address string) (io.ReadWriteCloser, *socks.AddrSpec, error) {
29 local, ok := d.conn.LocalAddr().(*net.TCPAddr)
30 if !ok {
31 return nil, nil, fmt.Errorf("not a tcp connection")
32 }
33
34 addr := socks.AddrSpec{IP: local.IP, Port: local.Port}
35 return d.conn, &addr, nil
36}
37
38// NewWSConnection returns a new connection object
39func NewWSConnection(logger logger.Service, isSocks bool) Connection {
40 return &Websocket{
41 logger: logger,
42 isSocks: isSocks,
43 }
44}
45
46// ServeStream will create a Websocket client stream connection to the edge
47// it blocks and writes the raw data from conn over the tunnel
48func (ws *Websocket) ServeStream(options *StartOptions, conn io.ReadWriter) error {
49 wsConn, err := createWebsocketStream(options, ws.logger)
50 if err != nil {
51 ws.logger.Errorf("failed to connect to %s with error: %s", options.OriginURL, err)
52 return err
53 }
54 defer wsConn.Close()
55
56 if ws.isSocks {
57 dialer := &wsdialer{conn: wsConn}
58 requestHandler := socks.NewRequestHandler(dialer)
59 socksServer := socks.NewConnectionHandler(requestHandler)
60
61 socksServer.Serve(conn)
62 } else {
63 cfwebsocket.Stream(wsConn, conn)
64 }
65 return nil
66}
67
68// StartServer creates a Websocket server to listen for connections.
69// This is used on the origin (tunnel) side to take data from the muxer and send it to the origin
70func (ws *Websocket) StartServer(listener net.Listener, remote string, shutdownC <-chan struct{}) error {
71 return cfwebsocket.StartProxyServer(ws.logger, listener, remote, shutdownC, cfwebsocket.DefaultStreamHandler)
72}
73
74// createWebsocketStream will create a WebSocket connection to stream data over
75// It also handles redirects from Access and will present that flow if
76// the token is not present on the request
77func createWebsocketStream(options *StartOptions, logger logger.Service) (*cfwebsocket.Conn, error) {
78 req, err := http.NewRequest(http.MethodGet, options.OriginURL, nil)
79 if err != nil {
80 return nil, err
81 }
82 req.Header = options.Headers
83
84 dump, err := httputil.DumpRequest(req, false)
85 logger.Debugf("Websocket request: %s", string(dump))
86
87 wsConn, resp, err := cfwebsocket.ClientConnect(req, nil)
88 defer closeRespBody(resp)
89 if err != nil && IsAccessResponse(resp) {
90 wsConn, err = createAccessAuthenticatedStream(options, logger)
91 if err != nil {
92 return nil, err
93 }
94 } else if err != nil {
95 return nil, err
96 }
97
98 return &cfwebsocket.Conn{Conn: wsConn}, nil
99}
100
101// createAccessAuthenticatedStream will try load a token from storage and make
102// a connection with the token set on the request. If it still get redirect,
103// this probably means the token in storage is invalid (expired/revoked). If that
104// happens it deletes the token and runs the connection again, so the user can
105// login again and generate a new one.
106func createAccessAuthenticatedStream(options *StartOptions, logger logger.Service) (*websocket.Conn, error) {
107 wsConn, resp, err := createAccessWebSocketStream(options, logger)
108 defer closeRespBody(resp)
109 if err == nil {
110 return wsConn, nil
111 }
112
113 if !IsAccessResponse(resp) {
114 return nil, err
115 }
116
117 // Access Token is invalid for some reason. Go through regen flow
118 originReq, err := http.NewRequest(http.MethodGet, options.OriginURL, nil)
119 if err != nil {
120 return nil, err
121 }
122 if err := token.RemoveTokenIfExists(originReq.URL); err != nil {
123 return nil, err
124 }
125 wsConn, resp, err = createAccessWebSocketStream(options, logger)
126 defer closeRespBody(resp)
127 if err != nil {
128 return nil, err
129 }
130
131 return wsConn, nil
132}
133
134// createAccessWebSocketStream builds an Access request and makes a connection
135func createAccessWebSocketStream(options *StartOptions, logger logger.Service) (*websocket.Conn, *http.Response, error) {
136 req, err := BuildAccessRequest(options, logger)
137 if err != nil {
138 return nil, nil, err
139 }
140
141 dump, err := httputil.DumpRequest(req, false)
142 logger.Debugf("Access Websocket request: %s", string(dump))
143
144 return cfwebsocket.ClientConnect(req, nil)
145}
146