2016-02-25 23:14:22 +00:00
|
|
|
/*
|
2024-09-03 13:32:50 +00:00
|
|
|
* Copyright (c) 2015, 2024, Oracle and/or its affiliates. All rights reserved.
|
2016-02-25 23:14:22 +00:00
|
|
|
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
|
|
|
*
|
|
|
|
* This code is free software; you can redistribute it and/or modify it
|
|
|
|
* under the terms of the GNU General Public License version 2 only, as
|
|
|
|
* published by the Free Software Foundation.
|
|
|
|
*
|
|
|
|
* This code is distributed in the hope that it will be useful, but WITHOUT
|
|
|
|
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
|
|
|
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
|
|
|
* version 2 for more details (a copy is included in the LICENSE file that
|
|
|
|
* accompanied this code).
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License version
|
|
|
|
* 2 along with this work; if not, write to the Free Software Foundation,
|
|
|
|
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
|
|
|
|
*
|
|
|
|
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
|
|
|
|
* or visit www.oracle.com if you need additional information or have any
|
|
|
|
* questions.
|
|
|
|
*/
|
|
|
|
|
|
|
|
import java.net.*;
|
|
|
|
import java.io.*;
|
2021-02-24 10:50:35 +00:00
|
|
|
import java.nio.ByteBuffer;
|
|
|
|
import java.nio.channels.ServerSocketChannel;
|
|
|
|
import java.nio.channels.SocketChannel;
|
2016-02-25 23:14:22 +00:00
|
|
|
import java.util.*;
|
|
|
|
import java.security.*;
|
2019-01-29 16:12:12 +00:00
|
|
|
import java.util.concurrent.CopyOnWriteArrayList;
|
2021-02-24 10:50:35 +00:00
|
|
|
|
|
|
|
import static java.nio.charset.StandardCharsets.US_ASCII;
|
2019-01-28 13:51:16 +00:00
|
|
|
import static java.nio.charset.StandardCharsets.UTF_8;
|
2021-02-24 10:50:35 +00:00
|
|
|
import static java.nio.charset.StandardCharsets.ISO_8859_1;
|
2019-01-28 13:51:16 +00:00
|
|
|
import static java.util.Arrays.asList;
|
|
|
|
import static java.util.stream.Collectors.toList;
|
2016-02-25 23:14:22 +00:00
|
|
|
|
|
|
|
/**
|
|
|
|
* A minimal proxy server that supports CONNECT tunneling. It does not do
|
|
|
|
* any header transformations. In future this could be added.
|
|
|
|
* Two threads are created per client connection. So, it's not
|
|
|
|
* intended for large numbers of parallel connections.
|
|
|
|
*/
|
|
|
|
public class ProxyServer extends Thread implements Closeable {
|
|
|
|
|
2021-02-24 10:50:35 +00:00
|
|
|
// could use the test library here - Platform.isWindows(),
|
|
|
|
// but it would force all tests that use ProxyServer to
|
|
|
|
// build it. Let's keep it simple.
|
|
|
|
static final boolean IS_WINDOWS;
|
|
|
|
static {
|
|
|
|
PrivilegedAction<String> action =
|
|
|
|
() -> System.getProperty("os.name", "unknown");
|
|
|
|
String osName = AccessController.doPrivileged(action);
|
|
|
|
IS_WINDOWS = osName.toLowerCase(Locale.ROOT).startsWith("win");
|
|
|
|
}
|
|
|
|
|
|
|
|
public static boolean isWindows() {
|
|
|
|
return IS_WINDOWS;
|
|
|
|
}
|
|
|
|
|
|
|
|
ServerSocketChannel listener;
|
2016-02-25 23:14:22 +00:00
|
|
|
int port;
|
|
|
|
volatile boolean debug;
|
2019-01-28 13:51:16 +00:00
|
|
|
private final Credentials credentials; // may be null
|
|
|
|
|
|
|
|
private static class Credentials {
|
|
|
|
private final String name;
|
|
|
|
private final String password;
|
|
|
|
private Credentials(String name, String password) {
|
|
|
|
this.name = name;
|
|
|
|
this.password = password;
|
|
|
|
}
|
|
|
|
public String name() { return name; }
|
|
|
|
public String password() { return password; }
|
|
|
|
}
|
2016-02-25 23:14:22 +00:00
|
|
|
|
|
|
|
/**
|
|
|
|
* Create proxy on port (zero means don't care). Call getPort()
|
|
|
|
* to get the assigned port.
|
|
|
|
*/
|
|
|
|
public ProxyServer(Integer port) throws IOException {
|
|
|
|
this(port, false);
|
|
|
|
}
|
|
|
|
|
2019-01-28 13:51:16 +00:00
|
|
|
public ProxyServer(Integer port,
|
|
|
|
Boolean debug,
|
|
|
|
String username,
|
|
|
|
String password)
|
|
|
|
throws IOException
|
|
|
|
{
|
|
|
|
this(port, debug, new Credentials(username, password));
|
|
|
|
}
|
|
|
|
|
|
|
|
public ProxyServer(Integer port,
|
|
|
|
Boolean debug)
|
|
|
|
throws IOException
|
|
|
|
{
|
|
|
|
this(port, debug, null);
|
|
|
|
}
|
|
|
|
|
|
|
|
public ProxyServer(Integer port,
|
|
|
|
Boolean debug,
|
|
|
|
Credentials credentials)
|
|
|
|
throws IOException
|
|
|
|
{
|
2016-02-25 23:14:22 +00:00
|
|
|
this.debug = debug;
|
2021-02-24 10:50:35 +00:00
|
|
|
listener = ServerSocketChannel.open();
|
|
|
|
listener.setOption(StandardSocketOptions.SO_REUSEADDR, false);
|
2018-04-17 08:54:17 -07:00
|
|
|
listener.bind(new InetSocketAddress(InetAddress.getLoopbackAddress(), port));
|
2021-02-24 10:50:35 +00:00
|
|
|
this.port = ((InetSocketAddress)listener.getLocalAddress()).getPort();
|
2019-01-28 13:51:16 +00:00
|
|
|
this.credentials = credentials;
|
2016-02-25 23:14:22 +00:00
|
|
|
setName("ProxyListener");
|
|
|
|
setDaemon(true);
|
2019-01-29 16:12:12 +00:00
|
|
|
connections = new CopyOnWriteArrayList<Connection>();
|
2016-02-25 23:14:22 +00:00
|
|
|
start();
|
|
|
|
}
|
|
|
|
|
2019-01-28 13:51:16 +00:00
|
|
|
public ProxyServer(String s) {
|
|
|
|
credentials = null;
|
2019-01-29 16:12:12 +00:00
|
|
|
connections = new CopyOnWriteArrayList<Connection>();
|
2019-01-28 13:51:16 +00:00
|
|
|
}
|
2016-02-25 23:14:22 +00:00
|
|
|
|
|
|
|
/**
|
|
|
|
* Returns the port number this proxy is listening on
|
|
|
|
*/
|
|
|
|
public int getPort() {
|
|
|
|
return port;
|
|
|
|
}
|
|
|
|
|
2021-02-24 10:50:35 +00:00
|
|
|
public InetSocketAddress getProxyAddress() throws IOException {
|
|
|
|
return (InetSocketAddress)listener.getLocalAddress();
|
|
|
|
}
|
|
|
|
|
2016-02-25 23:14:22 +00:00
|
|
|
/**
|
|
|
|
* Shuts down the proxy, probably aborting any connections
|
|
|
|
* currently open
|
|
|
|
*/
|
|
|
|
public void close() throws IOException {
|
2019-01-29 16:12:12 +00:00
|
|
|
if (debug) System.out.println("Proxy: closing server");
|
2018-05-02 02:36:17 -07:00
|
|
|
done = true;
|
2016-02-25 23:14:22 +00:00
|
|
|
listener.close();
|
|
|
|
for (Connection c : connections) {
|
2018-05-02 02:36:17 -07:00
|
|
|
c.close();
|
2019-01-29 16:12:12 +00:00
|
|
|
c.awaitCompletion();
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-01-29 16:12:12 +00:00
|
|
|
final CopyOnWriteArrayList<Connection> connections;
|
2016-02-25 23:14:22 +00:00
|
|
|
|
|
|
|
volatile boolean done;
|
|
|
|
|
|
|
|
public void run() {
|
|
|
|
if (System.getSecurityManager() == null) {
|
|
|
|
execute();
|
|
|
|
} else {
|
|
|
|
// so calling domain does not need to have socket permission
|
|
|
|
AccessController.doPrivileged(new PrivilegedAction<Void>() {
|
|
|
|
public Void run() {
|
|
|
|
execute();
|
|
|
|
return null;
|
|
|
|
}
|
|
|
|
});
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public void execute() {
|
2019-01-29 16:12:12 +00:00
|
|
|
int id = 0;
|
2016-02-25 23:14:22 +00:00
|
|
|
try {
|
2019-01-29 16:12:12 +00:00
|
|
|
while (!done) {
|
2021-02-24 10:50:35 +00:00
|
|
|
SocketChannel s = listener.accept();
|
2019-01-29 16:12:12 +00:00
|
|
|
id++;
|
|
|
|
Connection c = new Connection(s, id);
|
2016-02-25 23:14:22 +00:00
|
|
|
if (debug)
|
2021-02-24 10:50:35 +00:00
|
|
|
System.out.println("Proxy: accepted new connection: " + c);
|
2016-02-25 23:14:22 +00:00
|
|
|
connections.add(c);
|
2019-01-29 16:12:12 +00:00
|
|
|
c.init();
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
|
|
|
} catch(Throwable e) {
|
|
|
|
if (debug && !done) {
|
2019-01-29 16:12:12 +00:00
|
|
|
System.out.println("Proxy: Fatal error, listener got " + e);
|
2016-02-25 23:14:22 +00:00
|
|
|
e.printStackTrace();
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Transparently forward everything, once we know what the destination is
|
|
|
|
*/
|
|
|
|
class Connection {
|
|
|
|
|
2019-01-29 16:12:12 +00:00
|
|
|
private final int id;
|
2021-02-24 10:50:35 +00:00
|
|
|
SocketChannel clientSocket, serverSocket;
|
2016-02-25 23:14:22 +00:00
|
|
|
Thread out, in;
|
|
|
|
volatile InputStream clientIn, serverIn;
|
|
|
|
volatile OutputStream clientOut, serverOut;
|
|
|
|
|
2024-09-03 13:32:50 +00:00
|
|
|
boolean proxyInClosed; // only accessed from synchronized block
|
|
|
|
boolean proxyOutClosed; // only accessed from synchronized block
|
|
|
|
|
2016-02-25 23:14:22 +00:00
|
|
|
final static int CR = 13;
|
|
|
|
final static int LF = 10;
|
|
|
|
|
2021-02-24 10:50:35 +00:00
|
|
|
Connection(SocketChannel s, int id) throws IOException {
|
2019-01-29 16:12:12 +00:00
|
|
|
this.id = id;
|
2016-02-25 23:14:22 +00:00
|
|
|
this.clientSocket= s;
|
2021-02-24 10:50:35 +00:00
|
|
|
this.clientIn = new BufferedInputStream(s.socket().getInputStream());
|
|
|
|
this.clientOut = s.socket().getOutputStream();
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
byte[] readHeaders(InputStream is) throws IOException {
|
|
|
|
byte[] outbuffer = new byte[8000];
|
|
|
|
int crlfcount = 0;
|
|
|
|
int bytecount = 0;
|
|
|
|
int c;
|
|
|
|
while ((c=is.read()) != -1 && bytecount < outbuffer.length) {
|
|
|
|
outbuffer[bytecount++] = (byte)c;
|
|
|
|
if (debug) System.out.write(c);
|
|
|
|
// were looking for CRLFCRLF sequence
|
|
|
|
if (c == CR || c == LF) {
|
|
|
|
switch(crlfcount) {
|
|
|
|
case 0:
|
|
|
|
if (c == CR) crlfcount ++;
|
|
|
|
break;
|
|
|
|
case 1:
|
|
|
|
if (c == LF) crlfcount ++;
|
|
|
|
break;
|
|
|
|
case 2:
|
|
|
|
if (c == CR) crlfcount ++;
|
|
|
|
break;
|
|
|
|
case 3:
|
|
|
|
if (c == LF) crlfcount ++;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
crlfcount = 0;
|
|
|
|
}
|
|
|
|
if (crlfcount == 4) {
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
byte[] ret = new byte[bytecount];
|
|
|
|
System.arraycopy(outbuffer, 0, ret, 0, bytecount);
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
boolean running() {
|
|
|
|
return out.isAlive() || in.isAlive();
|
|
|
|
}
|
|
|
|
|
2018-05-02 02:36:17 -07:00
|
|
|
private volatile boolean closing;
|
|
|
|
public synchronized void close() throws IOException {
|
|
|
|
closing = true;
|
2019-01-29 16:12:12 +00:00
|
|
|
if (debug)
|
|
|
|
System.out.println("Proxy: closing connection {" + this + "}");
|
|
|
|
if (serverSocket != null)
|
|
|
|
serverSocket.close();
|
|
|
|
if (clientSocket != null)
|
|
|
|
clientSocket.close();
|
|
|
|
}
|
|
|
|
|
|
|
|
public void awaitCompletion() {
|
|
|
|
try {
|
|
|
|
if (in != null)
|
|
|
|
in.join();
|
|
|
|
if (out!= null)
|
|
|
|
out.join();
|
|
|
|
} catch (InterruptedException e) { }
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
int findCRLF(byte[] b) {
|
|
|
|
for (int i=0; i<b.length-1; i++) {
|
|
|
|
if (b[i] == CR && b[i+1] == LF) {
|
|
|
|
return i;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2019-01-28 13:51:16 +00:00
|
|
|
// Checks credentials in the request against those allowable by the proxy.
|
|
|
|
private boolean authorized(Credentials credentials,
|
|
|
|
List<String> requestHeaders) {
|
|
|
|
List<String> authorization = requestHeaders.stream()
|
|
|
|
.filter(n -> n.toLowerCase(Locale.US).startsWith("proxy-authorization"))
|
|
|
|
.collect(toList());
|
|
|
|
|
|
|
|
if (authorization.isEmpty())
|
|
|
|
return false;
|
|
|
|
|
|
|
|
if (authorization.size() != 1) {
|
|
|
|
throw new IllegalStateException("Authorization unexpected count:" + authorization);
|
|
|
|
}
|
|
|
|
String value = authorization.get(0).substring("proxy-authorization".length()).trim();
|
|
|
|
if (!value.startsWith(":"))
|
|
|
|
throw new IllegalStateException("Authorization malformed: " + value);
|
|
|
|
value = value.substring(1).trim();
|
|
|
|
|
|
|
|
if (!value.startsWith("Basic "))
|
|
|
|
throw new IllegalStateException("Authorization not Basic: " + value);
|
|
|
|
|
|
|
|
value = value.substring("Basic ".length());
|
|
|
|
String values = new String(Base64.getDecoder().decode(value), UTF_8);
|
|
|
|
int sep = values.indexOf(':');
|
|
|
|
if (sep < 1) {
|
|
|
|
throw new IllegalStateException("Authorization no colon: " + values);
|
|
|
|
}
|
|
|
|
String name = values.substring(0, sep);
|
|
|
|
String password = values.substring(sep + 1);
|
|
|
|
|
|
|
|
if (name.equals(credentials.name()) && password.equals(credentials.password()))
|
|
|
|
return true;
|
|
|
|
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2016-02-25 23:14:22 +00:00
|
|
|
public void init() {
|
|
|
|
try {
|
2019-01-28 13:51:16 +00:00
|
|
|
byte[] buf;
|
2021-02-24 10:50:35 +00:00
|
|
|
String host;
|
|
|
|
List<String> headers;
|
|
|
|
boolean authorized = false;
|
2019-01-28 13:51:16 +00:00
|
|
|
while (true) {
|
|
|
|
buf = readHeaders(clientIn);
|
|
|
|
if (findCRLF(buf) == -1) {
|
2019-01-29 16:12:12 +00:00
|
|
|
if (debug)
|
|
|
|
System.out.println("Proxy: no CRLF closing, buf contains:["
|
2021-02-24 10:50:35 +00:00
|
|
|
+ new String(buf, ISO_8859_1) + "]" );
|
2019-01-28 13:51:16 +00:00
|
|
|
close();
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2021-02-24 10:50:35 +00:00
|
|
|
headers = asList(new String(buf, ISO_8859_1).split("\r\n"));
|
|
|
|
host = findFirst(headers, "host");
|
2019-01-28 13:51:16 +00:00
|
|
|
// check authorization credentials, if required by the server
|
2021-02-24 10:50:35 +00:00
|
|
|
if (credentials != null) {
|
|
|
|
if (!authorized(credentials, headers)) {
|
2022-12-20 11:06:36 +00:00
|
|
|
boolean shouldClose = shouldCloseAfter407(headers);
|
|
|
|
var closestr = shouldClose ? "Connection: close\r\n" : "";
|
2021-02-24 10:50:35 +00:00
|
|
|
String resp = "HTTP/1.1 407 Proxy Authentication Required\r\n" +
|
2022-12-20 11:06:36 +00:00
|
|
|
"Content-Length: 0\r\n" + closestr +
|
2021-02-24 10:50:35 +00:00
|
|
|
"Proxy-Authenticate: Basic realm=\"proxy realm\"\r\n\r\n";
|
|
|
|
clientSocket.setOption(StandardSocketOptions.TCP_NODELAY, true);
|
|
|
|
clientSocket.setOption(StandardSocketOptions.SO_LINGER, 2);
|
|
|
|
var buffer = ByteBuffer.wrap(resp.getBytes(ISO_8859_1));
|
|
|
|
clientSocket.write(buffer);
|
|
|
|
if (debug) {
|
|
|
|
var linger = clientSocket.getOption(StandardSocketOptions.SO_LINGER);
|
|
|
|
var nodelay = clientSocket.getOption(StandardSocketOptions.TCP_NODELAY);
|
|
|
|
System.out.printf("Proxy: unauthorized; 407 sent (%s/%s), linger: %s, nodelay: %s%n",
|
|
|
|
buffer.position(), buffer.position() + buffer.remaining(), linger, nodelay);
|
|
|
|
}
|
2022-12-20 11:06:36 +00:00
|
|
|
if (shouldClose) {
|
2021-02-24 10:50:35 +00:00
|
|
|
closeConnection();
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
authorized = true;
|
|
|
|
break;
|
2019-01-28 13:51:16 +00:00
|
|
|
} else {
|
|
|
|
break;
|
|
|
|
}
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
2019-01-28 13:51:16 +00:00
|
|
|
|
|
|
|
int p = findCRLF(buf);
|
2021-02-24 10:50:35 +00:00
|
|
|
String cmd = new String(buf, 0, p, ISO_8859_1);
|
2016-02-25 23:14:22 +00:00
|
|
|
String[] params = cmd.split(" ");
|
2019-01-28 13:51:16 +00:00
|
|
|
|
2016-02-25 23:14:22 +00:00
|
|
|
if (params[0].equals("CONNECT")) {
|
|
|
|
doTunnel(params[1]);
|
|
|
|
} else {
|
2021-02-24 10:50:35 +00:00
|
|
|
// TODO:
|
|
|
|
// this does not really work as it should: it also establishes
|
|
|
|
// a tunnel (proxyCommon). So it works as long as the client only
|
|
|
|
// sends a single plain request through the proxy - as all
|
|
|
|
// other requests would otherwise be tunneled to the
|
|
|
|
// server identified in the first request.
|
|
|
|
// It seems enough for our purpose for now, though.
|
|
|
|
// Fixing this would imply dealing with Content-Length, Transfer-Encoding,
|
|
|
|
// etc, both when writing to and reading from the server.
|
|
|
|
doProxy(params[1], cmd, headers, host, authorized);
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
2017-12-06 11:11:59 -08:00
|
|
|
} catch (Throwable e) {
|
2016-02-25 23:14:22 +00:00
|
|
|
if (debug) {
|
2019-01-29 16:12:12 +00:00
|
|
|
System.out.println("Proxy: " + e);
|
|
|
|
e.printStackTrace();
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
|
|
|
try {close(); } catch (IOException e1) {}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-02-24 10:50:35 +00:00
|
|
|
String findFirst(List<String> headers, String key) {
|
|
|
|
var h = key.toLowerCase(Locale.ROOT) + ": ";
|
|
|
|
return headers.stream()
|
|
|
|
.filter((s) -> s.toLowerCase(Locale.ROOT).startsWith(h))
|
|
|
|
.findFirst()
|
|
|
|
.map((s) -> s.substring(h.length()))
|
|
|
|
.map(String::trim)
|
|
|
|
.orElse(null);
|
|
|
|
}
|
|
|
|
|
|
|
|
private long drain(SocketChannel socket) throws IOException {
|
|
|
|
boolean isBlocking = socket.isBlocking();
|
|
|
|
if (isBlocking) {
|
|
|
|
socket.configureBlocking(false);
|
|
|
|
}
|
|
|
|
try {
|
|
|
|
ByteBuffer buffer = ByteBuffer.allocate(1024);
|
|
|
|
int read;
|
|
|
|
long drained = 0;
|
|
|
|
while ((read = socket.read(buffer)) > 0) {
|
|
|
|
drained += read;
|
|
|
|
buffer.position(0);
|
|
|
|
buffer.limit(buffer.capacity());
|
|
|
|
}
|
|
|
|
return drained;
|
|
|
|
} finally {
|
|
|
|
if (isBlocking) {
|
|
|
|
socket.configureBlocking(true);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void closeConnection() throws IOException {
|
|
|
|
if (debug) {
|
|
|
|
var linger = clientSocket.getOption(StandardSocketOptions.SO_LINGER);
|
|
|
|
var nodelay = clientSocket.getOption(StandardSocketOptions.TCP_NODELAY);
|
|
|
|
System.out.printf("Proxy: closing connection id=%s, linger: %s, nodelay: %s%n",
|
|
|
|
id, linger, nodelay);
|
|
|
|
}
|
|
|
|
long drained = drain(clientSocket);
|
|
|
|
if (debug) {
|
|
|
|
System.out.printf("Proxy: drained: %s%n", drained);
|
|
|
|
}
|
|
|
|
clientSocket.shutdownOutput();
|
|
|
|
try {
|
|
|
|
// On windows, we additionally need to delay before
|
|
|
|
// closing the socket. Otherwise we get a reset on the
|
|
|
|
// client side (The connection was aborted by a software
|
|
|
|
// on the host machine).
|
|
|
|
// Delay 500ms before actually closing the socket
|
|
|
|
if (isWindows()) Thread.sleep(500);
|
|
|
|
} catch (InterruptedException x) {
|
|
|
|
// OK
|
|
|
|
}
|
|
|
|
clientSocket.shutdownInput();
|
|
|
|
close();
|
|
|
|
}
|
|
|
|
|
|
|
|
// If the client sends a request body we will need to close the connection
|
|
|
|
// otherwise, we can keep it open.
|
|
|
|
private boolean shouldCloseAfter407(List<String> headers) throws IOException {
|
2022-12-20 11:06:36 +00:00
|
|
|
var cmdline = headers.get(0);
|
|
|
|
int m = cmdline.indexOf(' ');
|
|
|
|
var method = (m > 0) ? cmdline.substring(0, m) : null;
|
|
|
|
var nobody = List.of("GET", "HEAD");
|
|
|
|
|
2021-02-24 10:50:35 +00:00
|
|
|
var te = findFirst(headers, "transfer-encoding");
|
|
|
|
if (te != null) {
|
|
|
|
// processing transfer encoding not implemented
|
|
|
|
if (debug) {
|
|
|
|
System.out.println("Proxy: transfer-encoding with 407, closing connection");
|
|
|
|
}
|
|
|
|
return true; // should close
|
|
|
|
}
|
|
|
|
var cl = findFirst(headers, "content-length");
|
|
|
|
int n = -1;
|
2022-12-20 11:06:36 +00:00
|
|
|
if (cl == null) {
|
|
|
|
if (nobody.contains(method)) {
|
|
|
|
n = 0;
|
|
|
|
System.out.printf("Proxy: no content length for %s, assuming 0%n", method);
|
|
|
|
} else {
|
|
|
|
System.out.printf("Proxy: no content-length for %s, closing connection%n", method);
|
|
|
|
return true;
|
2021-02-24 10:50:35 +00:00
|
|
|
}
|
2022-12-20 11:06:36 +00:00
|
|
|
} else {
|
|
|
|
try {
|
|
|
|
n = Integer.parseInt(cl);
|
|
|
|
if (debug) {
|
|
|
|
System.out.printf("Proxy: content-length: %d%n", n);
|
|
|
|
}
|
|
|
|
} catch (NumberFormatException x) {
|
|
|
|
if (debug) {
|
|
|
|
System.out.println("Proxy: bad content-length, closing connection");
|
|
|
|
System.out.println("Proxy: \tcontent-length: " + cl);
|
|
|
|
System.out.println("Proxy: \theaders: " + headers);
|
|
|
|
System.out.println("Proxy: \t" + x);
|
|
|
|
}
|
|
|
|
return true; // should close
|
2021-02-24 10:50:35 +00:00
|
|
|
}
|
|
|
|
}
|
2022-12-20 11:06:36 +00:00
|
|
|
if (n > 0) {
|
2021-02-24 10:50:35 +00:00
|
|
|
if (debug) {
|
|
|
|
System.out.println("Proxy: request body with 407, closing connection");
|
|
|
|
}
|
|
|
|
return true; // should close
|
|
|
|
}
|
2022-12-20 11:06:36 +00:00
|
|
|
if (n == 0) {
|
2021-02-24 10:50:35 +00:00
|
|
|
var available = clientIn.available();
|
|
|
|
var drained = drain(clientSocket);
|
|
|
|
if (drained > 0 || available > 0) {
|
|
|
|
if (debug) {
|
|
|
|
System.out.printf("Proxy: unexpected bytes (%d) with 407, closing connection%n",
|
|
|
|
drained + available);
|
|
|
|
}
|
|
|
|
return true; // should close
|
|
|
|
}
|
|
|
|
// can keep open: CL=0 or no CL and GET or HEAD
|
|
|
|
return false;
|
|
|
|
} else {
|
|
|
|
if (debug) {
|
|
|
|
System.out.println("Proxy: possible body with 407, closing connection");
|
|
|
|
}
|
|
|
|
return true; // should close
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void doProxy(String dest, String cmdLine, List<String> headers, String host, boolean authorized)
|
2016-02-25 23:14:22 +00:00
|
|
|
throws IOException
|
|
|
|
{
|
|
|
|
try {
|
|
|
|
URI uri = new URI(dest);
|
|
|
|
if (!uri.isAbsolute()) {
|
2021-02-24 10:50:35 +00:00
|
|
|
if (host == null) {
|
|
|
|
throw new IOException("request URI not absolute");
|
|
|
|
} else {
|
|
|
|
uri = new URI("http://" + host + dest);
|
|
|
|
}
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
2021-02-24 10:50:35 +00:00
|
|
|
if (debug) System.out.printf("Proxy: uri=%s%n", uri);
|
2016-02-25 23:14:22 +00:00
|
|
|
dest = uri.getAuthority();
|
|
|
|
// now extract the path from the URI and recreate the cmd line
|
|
|
|
int sp = cmdLine.indexOf(' ');
|
|
|
|
String method = cmdLine.substring(0, sp);
|
|
|
|
cmdLine = method + " " + uri.getPath() + " HTTP/1.1";
|
|
|
|
|
|
|
|
commonInit(dest, 80);
|
2018-05-02 02:36:17 -07:00
|
|
|
OutputStream sout;
|
|
|
|
synchronized (this) {
|
|
|
|
if (closing) return;
|
|
|
|
sout = serverOut;
|
|
|
|
}
|
|
|
|
// might fail if we're closing but we don't care.
|
2021-02-24 10:50:35 +00:00
|
|
|
byte[] CRLF = new byte[] { (byte) '\r', (byte) '\n'};
|
|
|
|
sout.write(cmdLine.getBytes(ISO_8859_1));
|
|
|
|
sout.write(CRLF);
|
|
|
|
if (debug) System.out.printf("Proxy Forwarding: %s%n", cmdLine);
|
|
|
|
for (int l=1; l<headers.size(); l++) {
|
|
|
|
var s = headers.get(l);
|
|
|
|
if (!authorized || !s.toLowerCase(Locale.ROOT).startsWith("proxy-authorization")) {
|
|
|
|
sout.write(s.getBytes(ISO_8859_1));
|
|
|
|
sout.write(CRLF);
|
|
|
|
if (debug) System.out.printf("Proxy Forwarding: %s%n", s);
|
|
|
|
} else {
|
|
|
|
if (debug) System.out.printf("Proxy Skipping: %s%n", s);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
sout.write(CRLF);
|
|
|
|
if (debug) System.out.printf("Proxy Forwarding: %n");
|
|
|
|
|
|
|
|
// This will now establish a tunnel :-(
|
|
|
|
proxyCommon(debug);
|
2016-02-25 23:14:22 +00:00
|
|
|
|
|
|
|
} catch (URISyntaxException e) {
|
|
|
|
throw new IOException(e);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-05-02 02:36:17 -07:00
|
|
|
synchronized void commonInit(String dest, int defaultPort) throws IOException {
|
|
|
|
if (closing) return;
|
2016-02-25 23:14:22 +00:00
|
|
|
int port;
|
|
|
|
String[] hostport = dest.split(":");
|
|
|
|
if (hostport.length == 1) {
|
|
|
|
port = defaultPort;
|
|
|
|
} else {
|
|
|
|
port = Integer.parseInt(hostport[1]);
|
|
|
|
}
|
2019-01-29 16:12:12 +00:00
|
|
|
if (debug)
|
|
|
|
System.out.printf("Proxy: connecting to (%s/%d)\n", hostport[0], port);
|
2021-02-24 10:50:35 +00:00
|
|
|
serverSocket = SocketChannel.open();
|
|
|
|
serverSocket.connect(new InetSocketAddress(hostport[0], port));
|
|
|
|
serverOut = serverSocket.socket().getOutputStream();
|
2016-02-25 23:14:22 +00:00
|
|
|
|
2021-02-24 10:50:35 +00:00
|
|
|
serverIn = new BufferedInputStream(serverSocket.socket().getInputStream());
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
|
|
|
|
2021-02-24 10:50:35 +00:00
|
|
|
synchronized void proxyCommon(boolean log) throws IOException {
|
2018-05-02 02:36:17 -07:00
|
|
|
if (closing) return;
|
2016-02-25 23:14:22 +00:00
|
|
|
out = new Thread(() -> {
|
|
|
|
try {
|
|
|
|
byte[] bb = new byte[8000];
|
|
|
|
int n;
|
2021-02-24 10:50:35 +00:00
|
|
|
int body = 0;
|
2016-02-25 23:14:22 +00:00
|
|
|
while ((n = clientIn.read(bb)) != -1) {
|
|
|
|
serverOut.write(bb, 0, n);
|
2021-02-24 10:50:35 +00:00
|
|
|
body += n;
|
|
|
|
if (log)
|
|
|
|
System.out.printf("Proxy Forwarding [request body]: total %d%n", body);
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
2024-09-03 13:32:50 +00:00
|
|
|
closeClientIn();
|
2016-02-25 23:14:22 +00:00
|
|
|
} catch (IOException e) {
|
2019-01-29 16:12:12 +00:00
|
|
|
if (!closing && debug) {
|
|
|
|
System.out.println("Proxy: " + e);
|
|
|
|
e.printStackTrace();
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
});
|
|
|
|
in = new Thread(() -> {
|
|
|
|
try {
|
|
|
|
byte[] bb = new byte[8000];
|
|
|
|
int n;
|
2021-02-24 10:50:35 +00:00
|
|
|
int resp = 0;
|
2016-02-25 23:14:22 +00:00
|
|
|
while ((n = serverIn.read(bb)) != -1) {
|
|
|
|
clientOut.write(bb, 0, n);
|
2021-02-24 10:50:35 +00:00
|
|
|
resp += n;
|
|
|
|
if (log) System.out.printf("Proxy Forwarding [response]: %s%n", new String(bb, 0, n, UTF_8));
|
|
|
|
if (log) System.out.printf("Proxy Forwarding [response]: total %d%n", resp);
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
2024-09-03 13:32:50 +00:00
|
|
|
closeClientOut();
|
2016-02-25 23:14:22 +00:00
|
|
|
} catch (IOException e) {
|
2019-01-29 16:12:12 +00:00
|
|
|
if (!closing && debug) {
|
|
|
|
System.out.println("Proxy: " + e);
|
2016-02-25 23:14:22 +00:00
|
|
|
e.printStackTrace();
|
|
|
|
}
|
|
|
|
}
|
|
|
|
});
|
|
|
|
out.setName("Proxy-outbound");
|
|
|
|
out.setDaemon(true);
|
|
|
|
in.setDaemon(true);
|
|
|
|
in.setName("Proxy-inbound");
|
|
|
|
out.start();
|
|
|
|
in.start();
|
|
|
|
}
|
|
|
|
|
|
|
|
void doTunnel(String dest) throws IOException {
|
2018-05-02 02:36:17 -07:00
|
|
|
if (closing) return; // no need to go further.
|
2016-02-25 23:14:22 +00:00
|
|
|
commonInit(dest, 443);
|
2018-05-02 02:36:17 -07:00
|
|
|
// might fail if we're closing, but we don't care.
|
2016-02-25 23:14:22 +00:00
|
|
|
clientOut.write("HTTP/1.1 200 OK\r\n\r\n".getBytes());
|
2021-02-24 10:50:35 +00:00
|
|
|
proxyCommon(false);
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
2019-01-29 16:12:12 +00:00
|
|
|
|
2024-09-03 13:32:50 +00:00
|
|
|
synchronized void closeClientIn() throws IOException {
|
|
|
|
closing = true;
|
|
|
|
proxyInClosed = true;
|
|
|
|
clientSocket.shutdownInput();
|
|
|
|
serverSocket.shutdownOutput();
|
|
|
|
if (proxyOutClosed) {
|
|
|
|
serverSocket.close();
|
|
|
|
clientSocket.close();
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
synchronized void closeClientOut() throws IOException {
|
|
|
|
closing = true;
|
|
|
|
proxyOutClosed = true;
|
|
|
|
serverSocket.shutdownInput();
|
|
|
|
clientSocket.shutdownOutput();
|
|
|
|
if (proxyInClosed) {
|
|
|
|
serverSocket.close();
|
|
|
|
clientSocket.close();
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-01-29 16:12:12 +00:00
|
|
|
@Override
|
|
|
|
public String toString() {
|
|
|
|
return "Proxy connection " + id + ", client sock:" + clientSocket;
|
|
|
|
}
|
2016-02-25 23:14:22 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
public static void main(String[] args) throws Exception {
|
|
|
|
int port = Integer.parseInt(args[0]);
|
|
|
|
boolean debug = args.length > 1 && args[1].equals("-debug");
|
|
|
|
System.out.println("Debugging : " + debug);
|
|
|
|
ProxyServer ps = new ProxyServer(port, debug);
|
|
|
|
System.out.println("Proxy server listening on port " + ps.getPort());
|
|
|
|
while (true) {
|
|
|
|
Thread.sleep(5000);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|