traefik/pkg/provider/acme/challenge_http.go

133 lines
3.1 KiB
Go
Raw Normal View History

2018-03-05 20:54:04 +01:00
package acme
import (
2018-11-14 10:18:03 +01:00
"context"
"errors"
"fmt"
2018-07-03 12:44:04 +02:00
"net"
"net/http"
"net/url"
"regexp"
"sync"
2018-03-05 20:54:04 +01:00
"time"
2020-09-04 10:52:03 +02:00
"github.com/go-acme/lego/v4/challenge/http01"
"github.com/traefik/traefik/v2/pkg/log"
2018-03-05 20:54:04 +01:00
)
// ChallengeHTTP HTTP challenge provider implements challenge.Provider.
type ChallengeHTTP struct {
httpChallenges map[string]map[string][]byte
lock sync.RWMutex
}
2018-07-03 12:44:04 +02:00
// NewChallengeHTTP creates a new ChallengeHTTP.
func NewChallengeHTTP() *ChallengeHTTP {
return &ChallengeHTTP{
httpChallenges: make(map[string]map[string][]byte),
}
2018-07-03 12:44:04 +02:00
}
2018-11-14 10:18:03 +01:00
// Present presents a challenge to obtain new ACME certificate.
func (c *ChallengeHTTP) Present(domain, token, keyAuth string) error {
c.lock.Lock()
defer c.lock.Unlock()
if _, ok := c.httpChallenges[token]; !ok {
c.httpChallenges[token] = map[string][]byte{}
}
c.httpChallenges[token][domain] = []byte(keyAuth)
return nil
2018-07-03 12:44:04 +02:00
}
2018-03-05 20:54:04 +01:00
2018-11-14 10:18:03 +01:00
// CleanUp cleans the challenges when certificate is obtained.
func (c *ChallengeHTTP) CleanUp(domain, token, _ string) error {
c.lock.Lock()
defer c.lock.Unlock()
if c.httpChallenges == nil && len(c.httpChallenges) == 0 {
return nil
}
if _, ok := c.httpChallenges[token]; ok {
delete(c.httpChallenges[token], domain)
if len(c.httpChallenges[token]) == 0 {
delete(c.httpChallenges, token)
}
}
return nil
2018-03-05 20:54:04 +01:00
}
2018-11-14 10:18:03 +01:00
// Timeout calculates the maximum of time allowed to resolved an ACME challenge.
func (c *ChallengeHTTP) Timeout() (timeout, interval time.Duration) {
2018-07-03 12:44:04 +02:00
return 60 * time.Second, 5 * time.Second
}
func (c *ChallengeHTTP) ServeHTTP(rw http.ResponseWriter, req *http.Request) {
ctx := log.With(req.Context(), log.Str(log.ProviderName, "acme"))
logger := log.FromContext(ctx)
token, err := getPathParam(req.URL)
if err != nil {
logger.Errorf("Unable to get token: %v.", err)
rw.WriteHeader(http.StatusNotFound)
return
}
if token != "" {
domain, _, err := net.SplitHostPort(req.Host)
if err != nil {
logger.Debugf("Unable to split host and port: %v. Fallback to request host.", err)
domain = req.Host
}
tokenValue := c.getTokenValue(ctx, token, domain)
if len(tokenValue) > 0 {
rw.WriteHeader(http.StatusOK)
_, err = rw.Write(tokenValue)
if err != nil {
logger.Errorf("Unable to write token: %v", err)
2018-07-03 12:44:04 +02:00
}
return
}
}
rw.WriteHeader(http.StatusNotFound)
2018-03-05 20:54:04 +01:00
}
2018-11-14 10:18:03 +01:00
func (c *ChallengeHTTP) getTokenValue(ctx context.Context, token, domain string) []byte {
2018-11-14 10:18:03 +01:00
logger := log.FromContext(ctx)
2022-01-27 10:58:04 +01:00
logger.Debugf("Retrieving the ACME challenge for %s (token %q)...", domain, token)
2018-11-14 10:18:03 +01:00
c.lock.RLock()
defer c.lock.RUnlock()
if _, ok := c.httpChallenges[token]; !ok {
logger.Errorf("Cannot retrieve the ACME challenge for %s (token %q)", domain, token)
return nil
2018-11-14 10:18:03 +01:00
}
result, ok := c.httpChallenges[token][domain]
if !ok {
logger.Errorf("Cannot retrieve the ACME challenge for %s (token %q)", domain, token)
return nil
2018-11-14 10:18:03 +01:00
}
return result
}
func getPathParam(uri *url.URL) (string, error) {
exp := regexp.MustCompile(fmt.Sprintf(`^%s([^/]+)/?$`, http01.ChallengePath("")))
parts := exp.FindStringSubmatch(uri.Path)
if len(parts) != 2 {
return "", errors.New("missing token")
}
return parts[1], nil
}