mirror of
https://github.com/yusing/godoxy.git
synced 2025-06-01 09:32:35 +02:00

Some checks are pending
Docker Image CI (socket-proxy) / build (push) Waiting to run
* refactor: simplify io code and make utils module independent * fix(docker): agent and socket-proxy docker event flushing with modified reverse proxy handler * refactor: remove unused code * refactor: remove the use of logging module in most code * refactor: streamline domain mismatch check in certState function * tweak: use ecdsa p-256 for autocert * fix(tests): update health check tests for invalid host and add case for port in host * feat(acme): custom acme directory * refactor: code refactor and improved context and error handling * tweak: optimize memory usage under load * fix(oidc): restore old user matching behavior * docs: add ChatGPT assistant to README --------- Co-authored-by: yusing <yusing@6uo.me>
43 lines
968 B
Go
43 lines
968 B
Go
package server
|
|
|
|
import (
|
|
"crypto/tls"
|
|
"crypto/x509"
|
|
"fmt"
|
|
"net/http"
|
|
|
|
"github.com/rs/zerolog/log"
|
|
"github.com/yusing/go-proxy/agent/pkg/env"
|
|
"github.com/yusing/go-proxy/agent/pkg/handler"
|
|
"github.com/yusing/go-proxy/internal/net/gphttp/server"
|
|
"github.com/yusing/go-proxy/internal/task"
|
|
)
|
|
|
|
type Options struct {
|
|
CACert, ServerCert *tls.Certificate
|
|
Port int
|
|
}
|
|
|
|
func StartAgentServer(parent task.Parent, opt Options) {
|
|
caCertPool := x509.NewCertPool()
|
|
caCertPool.AddCert(opt.CACert.Leaf)
|
|
|
|
// Configure TLS
|
|
tlsConfig := &tls.Config{
|
|
Certificates: []tls.Certificate{*opt.ServerCert},
|
|
ClientCAs: caCertPool,
|
|
ClientAuth: tls.RequireAndVerifyClientCert,
|
|
}
|
|
|
|
if env.AgentSkipClientCertCheck {
|
|
tlsConfig.ClientAuth = tls.NoClientCert
|
|
}
|
|
|
|
agentServer := &http.Server{
|
|
Addr: fmt.Sprintf(":%d", opt.Port),
|
|
Handler: handler.NewAgentHandler(),
|
|
TLSConfig: tlsConfig,
|
|
}
|
|
|
|
server.Start(parent, agentServer, nil, &log.Logger)
|
|
}
|