Documentation
¶
Index ¶
- Variables
- func Connect(cfg ConnectConfig) fh.HandlerFunc
- func Gateway(routes map[string]Config) fh.HandlerFunc
- func New(cfg Config) fh.HandlerFunc
- func VerifyIntegrity(resp *http.Response, expectedHash string, maxBody int64) error
- func WithSRI(cfg SRIConfig) func(fh.Ctx, *http.Response) error
- type Config
- type ConnectConfig
- type SRIConfig
Constants ¶
This section is empty.
Variables ¶
View Source
var ErrBodyTooLarge = errors.New("proxy: response body exceeds SRI verification limit")
View Source
var ErrIntegrityMismatch = errors.New("proxy: subresource integrity check failed")
Functions ¶
func Connect ¶
func Connect(cfg ConnectConfig) fh.HandlerFunc
Connect returns a handler for HTTP/1.1 CONNECT requests. It establishes a raw TCP tunnel only after AllowTarget approves the authority.
func New ¶
func New(cfg Config) fh.HandlerFunc
func VerifyIntegrity ¶
Types ¶
type Config ¶
type Config struct {
Target string
StripPrefix string
AddPrefix string
Timeout time.Duration
Director func(*http.Request)
ErrorHandler func(fh.Ctx, error) error
// DisableSSRFGuard turns off the default block on proxying to well-known
// cloud metadata endpoints (169.254.169.254, 169.254.170.2,
// fd00:ec2::254). No legitimate reverse-proxy target is ever a metadata
// endpoint, so this guard is on by default; disable only if this proxy
// is intentionally used as a metadata sidecar.
DisableSSRFGuard bool
// DeniedCIDRs additionally blocks proxying to targets whose resolved IP
// falls within any of these networks (e.g. "127.0.0.0/8", "10.0.0.0/8").
// Opt-in: many legitimate proxy targets are private-network services, so
// nothing beyond the metadata guard is blocked unless configured here.
DeniedCIDRs []string
}
type ConnectConfig ¶
type ConnectConfig struct {
// AllowTarget authorizes the requested host:port. A nil function rejects all
// targets so applications must opt in to outbound tunneling explicitly.
AllowTarget func(string) bool
Timeout time.Duration
}
ConnectConfig controls a forward HTTP CONNECT tunnel.
Click to show internal directories.
Click to hide internal directories.