origin_proxy_test.go 8.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331
  1. package ingress
  2. import (
  3. "context"
  4. "crypto/tls"
  5. "fmt"
  6. "net"
  7. "net/http"
  8. "net/http/httptest"
  9. "net/url"
  10. "sync"
  11. "testing"
  12. "github.com/cloudflare/cloudflared/h2mux"
  13. "github.com/cloudflare/cloudflared/websocket"
  14. "github.com/stretchr/testify/assert"
  15. "github.com/stretchr/testify/require"
  16. )
  17. // TestEstablishConnectionResponse ensures each implementation of StreamBasedOriginProxy returns
  18. // the expected response
  19. func assertEstablishConnectionResponse(t *testing.T,
  20. originProxy StreamBasedOriginProxy,
  21. req *http.Request,
  22. expectHeader http.Header,
  23. ) {
  24. _, resp, err := originProxy.EstablishConnection(req)
  25. assert.NoError(t, err)
  26. assert.Equal(t, switchingProtocolText, resp.Status)
  27. assert.Equal(t, http.StatusSwitchingProtocols, resp.StatusCode)
  28. assert.Equal(t, expectHeader, resp.Header)
  29. }
  30. func TestHTTPServiceEstablishConnection(t *testing.T) {
  31. origin := echoWSOrigin(t)
  32. defer origin.Close()
  33. originURL, err := url.Parse(origin.URL)
  34. require.NoError(t, err)
  35. httpService := &httpService{
  36. url: originURL,
  37. hostHeader: origin.URL,
  38. transport: &http.Transport{
  39. TLSClientConfig: &tls.Config{
  40. InsecureSkipVerify: true,
  41. },
  42. },
  43. }
  44. req, err := http.NewRequest(http.MethodGet, origin.URL, nil)
  45. require.NoError(t, err)
  46. req.Header.Set("Sec-Websocket-Key", "dGhlIHNhbXBsZSBub25jZQ==")
  47. req.Header.Set("Test-Cloudflared-Echo", t.Name())
  48. expectHeader := http.Header{
  49. "Connection": {"Upgrade"},
  50. "Sec-Websocket-Accept": {"s3pPLMBiTxaQ9kYGzzhZRbK+xOo="},
  51. "Upgrade": {"websocket"},
  52. "Test-Cloudflared-Echo": {t.Name()},
  53. }
  54. assertEstablishConnectionResponse(t, httpService, req, expectHeader)
  55. }
  56. func TestHelloWorldEstablishConnection(t *testing.T) {
  57. var wg sync.WaitGroup
  58. shutdownC := make(chan struct{})
  59. errC := make(chan error)
  60. helloWorldSerivce := &helloWorld{}
  61. helloWorldSerivce.start(&wg, testLogger, shutdownC, errC, OriginRequestConfig{})
  62. // Scheme and Host of URL will be override by the Scheme and Host of the helloWorld service
  63. req, err := http.NewRequest(http.MethodGet, "https://place-holder/ws", nil)
  64. require.NoError(t, err)
  65. expectHeader := http.Header{
  66. "Connection": {"Upgrade"},
  67. // Accept key when Sec-Websocket-Key is not specified
  68. "Sec-Websocket-Accept": {"Kfh9QIsMVZcl6xEPYxPHzW8SZ8w="},
  69. "Upgrade": {"websocket"},
  70. }
  71. assertEstablishConnectionResponse(t, helloWorldSerivce, req, expectHeader)
  72. close(shutdownC)
  73. }
  74. func TestRawTCPServiceEstablishConnection(t *testing.T) {
  75. originListener, err := net.Listen("tcp", "127.0.0.1:0")
  76. require.NoError(t, err)
  77. listenerClosed := make(chan struct{})
  78. tcpListenRoutine(originListener, listenerClosed)
  79. rawTCPService := &rawTCPService{name: ServiceWarpRouting}
  80. req, err := http.NewRequest(http.MethodGet, fmt.Sprintf("http://%s", originListener.Addr()), nil)
  81. require.NoError(t, err)
  82. assertEstablishConnectionResponse(t, rawTCPService, req, nil)
  83. originListener.Close()
  84. <-listenerClosed
  85. req, err = http.NewRequest(http.MethodGet, fmt.Sprintf("http://%s", originListener.Addr()), nil)
  86. require.NoError(t, err)
  87. // Origin not listening for new connection, should return an error
  88. _, resp, err := rawTCPService.EstablishConnection(req)
  89. require.Error(t, err)
  90. require.Nil(t, resp)
  91. }
  92. func TestTCPOverWSServiceEstablishConnection(t *testing.T) {
  93. originListener, err := net.Listen("tcp", "127.0.0.1:0")
  94. require.NoError(t, err)
  95. listenerClosed := make(chan struct{})
  96. tcpListenRoutine(originListener, listenerClosed)
  97. originURL := &url.URL{
  98. Scheme: "tcp",
  99. Host: originListener.Addr().String(),
  100. }
  101. baseReq, err := http.NewRequest(http.MethodGet, "https://place-holder", nil)
  102. require.NoError(t, err)
  103. baseReq.Header.Set("Sec-Websocket-Key", "dGhlIHNhbXBsZSBub25jZQ==")
  104. bastionReq := baseReq.Clone(context.Background())
  105. bastionReq.Header.Set(h2mux.CFJumpDestinationHeader, originListener.Addr().String())
  106. expectHeader := http.Header{
  107. "Connection": {"Upgrade"},
  108. "Sec-Websocket-Accept": {"s3pPLMBiTxaQ9kYGzzhZRbK+xOo="},
  109. "Upgrade": {"websocket"},
  110. }
  111. tests := []struct {
  112. service *tcpOverWSService
  113. req *http.Request
  114. expectErr bool
  115. }{
  116. {
  117. service: newTCPOverWSService(originURL),
  118. req: baseReq,
  119. },
  120. {
  121. service: newBastionService(),
  122. req: bastionReq,
  123. },
  124. {
  125. service: newBastionService(),
  126. req: baseReq,
  127. expectErr: true,
  128. },
  129. }
  130. for _, test := range tests {
  131. if test.expectErr {
  132. _, resp, err := test.service.EstablishConnection(test.req)
  133. assert.Error(t, err)
  134. assert.Nil(t, resp)
  135. } else {
  136. assertEstablishConnectionResponse(t, test.service, test.req, expectHeader)
  137. }
  138. }
  139. originListener.Close()
  140. <-listenerClosed
  141. for _, service := range []*tcpOverWSService{newTCPOverWSService(originURL), newBastionService()} {
  142. // Origin not listening for new connection, should return an error
  143. _, resp, err := service.EstablishConnection(bastionReq)
  144. assert.Error(t, err)
  145. assert.Nil(t, resp)
  146. }
  147. }
  148. func TestBastionDestination(t *testing.T) {
  149. canonicalJumpDestHeader := http.CanonicalHeaderKey(h2mux.CFJumpDestinationHeader)
  150. tests := []struct {
  151. name string
  152. header http.Header
  153. expectedDest string
  154. wantErr bool
  155. }{
  156. {
  157. name: "hostname destination",
  158. header: http.Header{
  159. canonicalJumpDestHeader: []string{"localhost"},
  160. },
  161. expectedDest: "localhost",
  162. },
  163. {
  164. name: "hostname destination with port",
  165. header: http.Header{
  166. canonicalJumpDestHeader: []string{"localhost:9000"},
  167. },
  168. expectedDest: "localhost:9000",
  169. },
  170. {
  171. name: "hostname destination with scheme and port",
  172. header: http.Header{
  173. canonicalJumpDestHeader: []string{"ssh://localhost:9000"},
  174. },
  175. expectedDest: "localhost:9000",
  176. },
  177. {
  178. name: "full hostname url",
  179. header: http.Header{
  180. canonicalJumpDestHeader: []string{"ssh://localhost:9000/metrics"},
  181. },
  182. expectedDest: "localhost:9000",
  183. },
  184. {
  185. name: "hostname destination with port and path",
  186. header: http.Header{
  187. canonicalJumpDestHeader: []string{"localhost:9000/metrics"},
  188. },
  189. expectedDest: "localhost:9000",
  190. },
  191. {
  192. name: "ip destination",
  193. header: http.Header{
  194. canonicalJumpDestHeader: []string{"127.0.0.1"},
  195. },
  196. expectedDest: "127.0.0.1",
  197. },
  198. {
  199. name: "ip destination with port",
  200. header: http.Header{
  201. canonicalJumpDestHeader: []string{"127.0.0.1:9000"},
  202. },
  203. expectedDest: "127.0.0.1:9000",
  204. },
  205. {
  206. name: "ip destination with port and path",
  207. header: http.Header{
  208. canonicalJumpDestHeader: []string{"127.0.0.1:9000/metrics"},
  209. },
  210. expectedDest: "127.0.0.1:9000",
  211. },
  212. {
  213. name: "ip destination with schem and port",
  214. header: http.Header{
  215. canonicalJumpDestHeader: []string{"tcp://127.0.0.1:9000"},
  216. },
  217. expectedDest: "127.0.0.1:9000",
  218. },
  219. {
  220. name: "full ip url",
  221. header: http.Header{
  222. canonicalJumpDestHeader: []string{"ssh://127.0.0.1:9000/metrics"},
  223. },
  224. expectedDest: "127.0.0.1:9000",
  225. },
  226. {
  227. name: "no destination",
  228. wantErr: true,
  229. },
  230. }
  231. s := newBastionService()
  232. for _, test := range tests {
  233. r := &http.Request{
  234. Header: test.header,
  235. }
  236. dest, err := s.bastionDest(r)
  237. if test.wantErr {
  238. assert.Error(t, err, "Test %s expects error", test.name)
  239. } else {
  240. assert.NoError(t, err, "Test %s expects no error, got error %v", test.name, err)
  241. assert.Equal(t, test.expectedDest, dest, "Test %s expect dest %s, got %s", test.name, test.expectedDest, dest)
  242. }
  243. }
  244. }
  245. func TestHTTPServiceHostHeaderOverride(t *testing.T) {
  246. cfg := OriginRequestConfig{
  247. HTTPHostHeader: t.Name(),
  248. }
  249. handler := func(w http.ResponseWriter, r *http.Request) {
  250. require.Equal(t, r.Host, t.Name())
  251. if websocket.IsWebSocketUpgrade(r) {
  252. respHeaders := websocket.NewResponseHeader(r)
  253. for k, v := range respHeaders {
  254. w.Header().Set(k, v[0])
  255. }
  256. w.WriteHeader(http.StatusSwitchingProtocols)
  257. return
  258. }
  259. w.Write([]byte("ok"))
  260. }
  261. origin := httptest.NewServer(http.HandlerFunc(handler))
  262. defer origin.Close()
  263. originURL, err := url.Parse(origin.URL)
  264. require.NoError(t, err)
  265. httpService := &httpService{
  266. url: originURL,
  267. }
  268. var wg sync.WaitGroup
  269. shutdownC := make(chan struct{})
  270. errC := make(chan error)
  271. require.NoError(t, httpService.start(&wg, testLogger, shutdownC, errC, cfg))
  272. req, err := http.NewRequest(http.MethodGet, originURL.String(), nil)
  273. require.NoError(t, err)
  274. resp, err := httpService.RoundTrip(req)
  275. require.NoError(t, err)
  276. require.Equal(t, http.StatusOK, resp.StatusCode)
  277. req = req.Clone(context.Background())
  278. _, resp, err = httpService.EstablishConnection(req)
  279. require.NoError(t, err)
  280. require.Equal(t, http.StatusSwitchingProtocols, resp.StatusCode)
  281. }
  282. func tcpListenRoutine(listener net.Listener, closeChan chan struct{}) {
  283. go func() {
  284. for {
  285. conn, err := listener.Accept()
  286. if err != nil {
  287. close(closeChan)
  288. return
  289. }
  290. // Close immediately, this test is not about testing read/write on connection
  291. conn.Close()
  292. }
  293. }()
  294. }