mirror of
https://github.com/movie-web/simple-proxy.git
synced 2025-09-13 14:43:26 +00:00
Compare commits
65 Commits
Author | SHA1 | Date | |
---|---|---|---|
|
88b1852a91 | ||
|
8c89f79441 | ||
|
a03e1c1b59 | ||
|
9e5d1a2993 | ||
|
0a553a8b84 | ||
|
9ef1467ee1 | ||
|
ed4d8826ce | ||
|
3e63fe5b61 | ||
|
0500b7caa5 | ||
|
193fcc06f7 | ||
|
eb58298582 | ||
|
655b053fd6 | ||
|
67a7c55a88 | ||
|
37802661ad | ||
|
c0ce4c9e84 | ||
|
3e8d413a87 | ||
|
3678522e20 | ||
|
54b40c1be1 | ||
|
6d27577ca4 | ||
|
f890f59d43 | ||
|
714b91ef8c | ||
|
96dc6d21d1 | ||
|
38556eda4a | ||
|
bd45c86ef5 | ||
|
2583a5126f | ||
|
951042e1f8 | ||
|
56e84a2a3a | ||
|
9ff25a4e61 | ||
|
0e386dc21d | ||
|
1b5a306879 | ||
|
d42c5d6270 | ||
|
e6000b36f0 | ||
|
c2ae6432ae | ||
|
95f0026f5a | ||
|
5a070b4a15 | ||
b18d07a6a5 | |||
293a4c0b81 | |||
c0f50f0410 | |||
3936dd0765 | |||
4d876b3298 | |||
f2f3f2dccd | |||
af1331bcc2 | |||
6e7df4e107 | |||
598d2862f3 | |||
1495f3bb5a | |||
8f4c6eb857 | |||
76fc23d88a | |||
883078fdbc | |||
c5233b7088 | |||
|
23c090fc15 | ||
|
f2d4e523a3 | ||
|
84e91bf422 | ||
|
d4352e7189 | ||
|
c03aaf8e3d | ||
|
256e6307f6 | ||
|
091fc3e36e | ||
|
72cc0f558e | ||
|
cc7c09d199 | ||
|
f9f46cde0b | ||
|
a875f0d335 | ||
|
9f1ebba010 | ||
|
13a4d0c8cc | ||
|
459ad63d04 | ||
|
0cdaeb7161 | ||
|
ec4539f667 |
7
.dockerignore
Normal file
7
.dockerignore
Normal file
@@ -0,0 +1,7 @@
|
|||||||
|
node_modules
|
||||||
|
*.log*
|
||||||
|
.nitro
|
||||||
|
.cache
|
||||||
|
.output
|
||||||
|
.env
|
||||||
|
dist
|
3
.eslintignore
Normal file
3
.eslintignore
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
dist
|
||||||
|
.output
|
||||||
|
node-modules
|
50
.eslintrc.js
Normal file
50
.eslintrc.js
Normal file
@@ -0,0 +1,50 @@
|
|||||||
|
module.exports = {
|
||||||
|
env: {
|
||||||
|
browser: true,
|
||||||
|
},
|
||||||
|
extends: [
|
||||||
|
"plugin:@typescript-eslint/recommended",
|
||||||
|
"plugin:prettier/recommended",
|
||||||
|
],
|
||||||
|
ignorePatterns: ["public/*", "dist/*", "/*.js", "/*.ts"],
|
||||||
|
parser: "@typescript-eslint/parser",
|
||||||
|
parserOptions: {
|
||||||
|
project: "./tsconfig.json",
|
||||||
|
tsconfigRootDir: "./",
|
||||||
|
},
|
||||||
|
settings: {
|
||||||
|
"import/resolver": {
|
||||||
|
typescript: {
|
||||||
|
project: "./tsconfig.json",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
plugins: ["@typescript-eslint", "import", "prettier"],
|
||||||
|
rules: {
|
||||||
|
"no-underscore-dangle": "off",
|
||||||
|
"@typescript-eslint/no-explicit-any": "off",
|
||||||
|
"no-console": "off",
|
||||||
|
"@typescript-eslint/no-this-alias": "off",
|
||||||
|
"import/prefer-default-export": "off",
|
||||||
|
"@typescript-eslint/no-empty-function": "off",
|
||||||
|
"no-shadow": "off",
|
||||||
|
"@typescript-eslint/no-shadow": ["error"],
|
||||||
|
"no-restricted-syntax": "off",
|
||||||
|
"import/no-unresolved": ["error", { ignore: ["^virtual:"] }],
|
||||||
|
"consistent-return": "off",
|
||||||
|
"no-continue": "off",
|
||||||
|
"no-eval": "off",
|
||||||
|
"no-await-in-loop": "off",
|
||||||
|
"no-nested-ternary": "off",
|
||||||
|
"prefer-destructuring": "off",
|
||||||
|
"@typescript-eslint/no-unused-vars": ["warn", { argsIgnorePattern: "^_" }],
|
||||||
|
"import/extensions": [
|
||||||
|
"error",
|
||||||
|
"ignorePackages",
|
||||||
|
{
|
||||||
|
ts: "never",
|
||||||
|
tsx: "never",
|
||||||
|
},
|
||||||
|
]
|
||||||
|
},
|
||||||
|
}
|
@@ -1,18 +0,0 @@
|
|||||||
{
|
|
||||||
"env": {
|
|
||||||
"worker": true,
|
|
||||||
"node": true,
|
|
||||||
"es6": true
|
|
||||||
},
|
|
||||||
"parserOptions": {
|
|
||||||
"ecmaVersion": "latest"
|
|
||||||
},
|
|
||||||
"root": true,
|
|
||||||
"extends": ["eslint:recommended", "plugin:prettier/recommended"],
|
|
||||||
"plugins": [],
|
|
||||||
"ignorePatterns": ["dist"],
|
|
||||||
"rules": {
|
|
||||||
"prettier/prettier": "error",
|
|
||||||
"no-undef": "off"
|
|
||||||
}
|
|
||||||
}
|
|
60
.github/workflows/build_release.yml
vendored
60
.github/workflows/build_release.yml
vendored
@@ -1,60 +0,0 @@
|
|||||||
name: Build Release
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- master
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
name: Build
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: Checkout code
|
|
||||||
uses: actions/checkout@v2
|
|
||||||
|
|
||||||
- name: Install Node.js
|
|
||||||
uses: actions/setup-node@v1
|
|
||||||
with:
|
|
||||||
node-version: 16
|
|
||||||
|
|
||||||
- name: Install NPM packages
|
|
||||||
run: npm install
|
|
||||||
|
|
||||||
- name: Build project
|
|
||||||
run: npm run build
|
|
||||||
|
|
||||||
- name: Upload production-ready build files
|
|
||||||
uses: actions/upload-artifact@v3
|
|
||||||
with:
|
|
||||||
name: worker.js
|
|
||||||
path: ./dist/worker.js
|
|
||||||
|
|
||||||
- name: Bump version and push tag
|
|
||||||
id: tag_version
|
|
||||||
uses: mathieudutour/github-tag-action@v6.1
|
|
||||||
with:
|
|
||||||
github_token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
|
|
||||||
- name: Create Release
|
|
||||||
id: create_release
|
|
||||||
uses: actions/create-release@v1
|
|
||||||
env:
|
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
with:
|
|
||||||
tag_name: ${{ steps.tag_version.outputs.new_tag }}
|
|
||||||
release_name: Simple Proxy Worker
|
|
||||||
draft: false
|
|
||||||
prerelease: false
|
|
||||||
|
|
||||||
- name: Upload Release Asset
|
|
||||||
id: upload-release-asset
|
|
||||||
uses: actions/upload-release-asset@v1
|
|
||||||
env:
|
|
||||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
with:
|
|
||||||
upload_url: ${{ steps.create_release.outputs.upload_url }}
|
|
||||||
asset_path: ./dist/worker.js
|
|
||||||
asset_name: worker.js
|
|
||||||
asset_content_type: text/javascript
|
|
36
.github/workflows/cloudflare.yml
vendored
Normal file
36
.github/workflows/cloudflare.yml
vendored
Normal file
@@ -0,0 +1,36 @@
|
|||||||
|
name: Deploy Worker
|
||||||
|
|
||||||
|
# this action is for the "deploy to cloudflare" button
|
||||||
|
# repository_dispatch is triggered by CF
|
||||||
|
# secrets should also be made by CF
|
||||||
|
|
||||||
|
on: ["repository_dispatch"]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
timeout-minutes: 60
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v3
|
||||||
|
|
||||||
|
- uses: pnpm/action-setup@v2
|
||||||
|
with:
|
||||||
|
version: latest
|
||||||
|
|
||||||
|
- name: Install Node.js
|
||||||
|
uses: actions/setup-node@v3
|
||||||
|
with:
|
||||||
|
node-version: 18
|
||||||
|
cache: 'pnpm'
|
||||||
|
|
||||||
|
- name: Install packages
|
||||||
|
run: pnpm install --frozen-lockfile
|
||||||
|
|
||||||
|
- name: Build Project
|
||||||
|
run: pnpm build:cloudflare
|
||||||
|
|
||||||
|
- name: Build & Deploy Worker
|
||||||
|
uses: cloudflare/wrangler-action@v3
|
||||||
|
with:
|
||||||
|
apiToken: ${{ secrets.CF_API_TOKEN }}
|
||||||
|
accountId: ${{ secrets.CF_ACCOUNT_ID }}
|
60
.github/workflows/linting.yml
vendored
Normal file
60
.github/workflows/linting.yml
vendored
Normal file
@@ -0,0 +1,60 @@
|
|||||||
|
name: Linting and Testing
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- master
|
||||||
|
- dev
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
linting:
|
||||||
|
name: Run Linters
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
|
- uses: pnpm/action-setup@v2
|
||||||
|
with:
|
||||||
|
version: latest
|
||||||
|
|
||||||
|
- name: Install Node.js
|
||||||
|
uses: actions/setup-node@v3
|
||||||
|
with:
|
||||||
|
node-version: 18
|
||||||
|
cache: 'pnpm'
|
||||||
|
|
||||||
|
- name: Install packages
|
||||||
|
run: pnpm install --frozen-lockfile
|
||||||
|
|
||||||
|
- name: Prepare for linting
|
||||||
|
run: pnpm prepare
|
||||||
|
|
||||||
|
- name: Run ESLint
|
||||||
|
run: pnpm lint
|
||||||
|
|
||||||
|
building:
|
||||||
|
name: Build project
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
|
- uses: pnpm/action-setup@v2
|
||||||
|
with:
|
||||||
|
version: latest
|
||||||
|
|
||||||
|
- name: Install Node.js
|
||||||
|
uses: actions/setup-node@v3
|
||||||
|
with:
|
||||||
|
node-version: 18
|
||||||
|
cache: 'pnpm'
|
||||||
|
|
||||||
|
- name: Install pnpm packages
|
||||||
|
run: pnpm install --frozen-lockfile
|
||||||
|
|
||||||
|
- name: Build Project
|
||||||
|
run: pnpm build
|
42
.github/workflows/linting_testing.yml
vendored
42
.github/workflows/linting_testing.yml
vendored
@@ -1,42 +0,0 @@
|
|||||||
name: Linting and Testing
|
|
||||||
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- master
|
|
||||||
- dev
|
|
||||||
pull_request:
|
|
||||||
types: [opened, reopened, synchronize]
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
linting:
|
|
||||||
name: Run Linters
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: Checkout code
|
|
||||||
uses: actions/checkout@v2
|
|
||||||
|
|
||||||
- name: Install Node.js
|
|
||||||
uses: actions/setup-node@v1
|
|
||||||
with:
|
|
||||||
node-version: 16
|
|
||||||
|
|
||||||
- name: Install NPM packages
|
|
||||||
run: npm install
|
|
||||||
|
|
||||||
- name: Run ESLint Report
|
|
||||||
run: npm run lint:report
|
|
||||||
# continue on error, so it still reports it in the next step
|
|
||||||
continue-on-error: true
|
|
||||||
|
|
||||||
- name: Annotate Code Linting Results
|
|
||||||
uses: ataylorme/eslint-annotate-action@v2
|
|
||||||
with:
|
|
||||||
repo-token: "${{ secrets.GITHUB_TOKEN }}"
|
|
||||||
report-json: "eslint_report.json"
|
|
||||||
|
|
||||||
- name: Build Project
|
|
||||||
run: npm run build
|
|
||||||
|
|
||||||
|
|
55
.github/workflows/publish.yml
vendored
Normal file
55
.github/workflows/publish.yml
vendored
Normal file
@@ -0,0 +1,55 @@
|
|||||||
|
name: Docker Publish
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- master
|
||||||
|
|
||||||
|
env:
|
||||||
|
REGISTRY: ghcr.io
|
||||||
|
IMAGE_NAME: ${{ github.repository }}
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
packages: write
|
||||||
|
id-token: write
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
|
- name: Setup Docker buildx
|
||||||
|
uses: docker/setup-buildx-action@v2
|
||||||
|
|
||||||
|
- name: Get version
|
||||||
|
id: package-version
|
||||||
|
uses: martinbeentjes/npm-get-version-action@main
|
||||||
|
|
||||||
|
- name: Log into registry ${{ env.REGISTRY }}
|
||||||
|
uses: docker/login-action@v2
|
||||||
|
with:
|
||||||
|
registry: ${{ env.REGISTRY }}
|
||||||
|
username: ${{ github.actor }}
|
||||||
|
password: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
|
- name: Extract Docker metadata
|
||||||
|
id: meta
|
||||||
|
uses: docker/metadata-action@v4
|
||||||
|
with:
|
||||||
|
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
|
||||||
|
flavor: |
|
||||||
|
latest=auto
|
||||||
|
tags: |
|
||||||
|
type=semver,pattern={{version}},value=v${{ steps.package-version.outputs.current-version }}
|
||||||
|
|
||||||
|
- name: Build and push Docker image
|
||||||
|
id: build-and-push
|
||||||
|
uses: docker/build-push-action@v4
|
||||||
|
with:
|
||||||
|
push: true
|
||||||
|
context: .
|
||||||
|
labels: ${{ steps.meta.outputs.labels }}
|
||||||
|
tags: ${{ steps.meta.outputs.tags }}
|
81
.github/workflows/release.yml
vendored
Normal file
81
.github/workflows/release.yml
vendored
Normal file
@@ -0,0 +1,81 @@
|
|||||||
|
name: Release
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- master
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
release:
|
||||||
|
name: Release
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v3
|
||||||
|
|
||||||
|
- uses: pnpm/action-setup@v2
|
||||||
|
with:
|
||||||
|
version: latest
|
||||||
|
|
||||||
|
- name: Get version
|
||||||
|
id: package-version
|
||||||
|
uses: martinbeentjes/npm-get-version-action@main
|
||||||
|
|
||||||
|
- name: Install packages
|
||||||
|
run: pnpm install --frozen-lockfile
|
||||||
|
|
||||||
|
- name: Build for cloudflare
|
||||||
|
run: pnpm build:cloudflare && cp ./.output/server/index.mjs ./cloudflare.worker.mjs
|
||||||
|
|
||||||
|
- name: Build for AWS
|
||||||
|
run: pnpm build:aws && cd .output/server && zip -r ../../lambda.zip .
|
||||||
|
|
||||||
|
- name: Build for Node
|
||||||
|
run: pnpm build:node && cd .output/server && zip -r ../../nodejs.zip .
|
||||||
|
|
||||||
|
- name: Create Release
|
||||||
|
id: create_release
|
||||||
|
uses: actions/create-release@v1
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
with:
|
||||||
|
tag_name: v${{ steps.package-version.outputs.current-version }}
|
||||||
|
release_name: Bot v${{ steps.package-version.outputs.current-version }}
|
||||||
|
draft: false
|
||||||
|
prerelease: false
|
||||||
|
body: |
|
||||||
|
Instead of downloading a package, you can also run it in docker:
|
||||||
|
```sh
|
||||||
|
docker run ghcr.io/movie-web/simple-proxy:${{ steps.package-version.outputs.current-version }}
|
||||||
|
```
|
||||||
|
|
||||||
|
- name: Upload cloudflare build
|
||||||
|
uses: actions/upload-release-asset@v1
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
with:
|
||||||
|
upload_url: ${{ steps.create_release.outputs.upload_url }}
|
||||||
|
asset_path: ./cloudflare.worker.mjs
|
||||||
|
asset_name: simple-proxy-cloudflare.mjs
|
||||||
|
asset_content_type: text/javascript
|
||||||
|
|
||||||
|
- name: Upload AWS build
|
||||||
|
uses: actions/upload-release-asset@v1
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
with:
|
||||||
|
upload_url: ${{ steps.create_release.outputs.upload_url }}
|
||||||
|
asset_path: ./lambda.zip
|
||||||
|
asset_name: simple-proxy-aws-lambda.zip
|
||||||
|
asset_content_type: application/zip
|
||||||
|
|
||||||
|
- name: Upload Node build
|
||||||
|
uses: actions/upload-release-asset@v1
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
with:
|
||||||
|
upload_url: ${{ steps.create_release.outputs.upload_url }}
|
||||||
|
asset_path: ./nodejs.zip
|
||||||
|
asset_name: simple-proxy-nodejs.zip
|
||||||
|
asset_content_type: application/zip
|
7
.gitignore
vendored
7
.gitignore
vendored
@@ -1,2 +1,7 @@
|
|||||||
node_modules
|
node_modules
|
||||||
dist
|
*.log*
|
||||||
|
.nitro
|
||||||
|
.cache
|
||||||
|
.output
|
||||||
|
.env
|
||||||
|
dist
|
5
.vscode/extensions.json
vendored
5
.vscode/extensions.json
vendored
@@ -1,6 +1,3 @@
|
|||||||
{
|
{
|
||||||
"recommendations": [
|
"recommendations": ["dbaeumer.vscode-eslint", "editorconfig.editorconfig"]
|
||||||
"dbaeumer.vscode-eslint",
|
|
||||||
"editorconfig.editorconfig"
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
|
3
.vscode/settings.json
vendored
3
.vscode/settings.json
vendored
@@ -1,4 +1,5 @@
|
|||||||
{
|
{
|
||||||
"editor.formatOnSave": true,
|
"editor.formatOnSave": true,
|
||||||
"editor.defaultFormatter": "dbaeumer.vscode-eslint"
|
"editor.defaultFormatter": "dbaeumer.vscode-eslint",
|
||||||
|
"eslint.format.enable": true
|
||||||
}
|
}
|
||||||
|
20
Dockerfile
Normal file
20
Dockerfile
Normal file
@@ -0,0 +1,20 @@
|
|||||||
|
FROM node:18-alpine as base
|
||||||
|
WORKDIR /app
|
||||||
|
|
||||||
|
# Build layer
|
||||||
|
FROM base as build
|
||||||
|
|
||||||
|
RUN npm i -g pnpm
|
||||||
|
COPY pnpm-lock.yaml package.json ./
|
||||||
|
RUN pnpm install --frozen-lockfile
|
||||||
|
COPY . .
|
||||||
|
RUN pnpm build
|
||||||
|
|
||||||
|
# Production layer
|
||||||
|
FROM base as production
|
||||||
|
|
||||||
|
EXPOSE 3000
|
||||||
|
ENV NODE_ENV=production
|
||||||
|
COPY --from=build /app/.output ./.output
|
||||||
|
|
||||||
|
CMD ["node", ".output/server/index.mjs"]
|
21
README.md
21
README.md
@@ -1,3 +1,20 @@
|
|||||||
# Cloudflare worker proxy
|
# simple-proxy
|
||||||
|
|
||||||
Simple http proxy in a cloudflare worker.
|
Simple reverse proxy to bypass CORS, used by [movie-web](https://movie-web.app).
|
||||||
|
Read the docs at https://docs.movie-web.app/proxy
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### features:
|
||||||
|
- Deployable on many platforms - thanks to nitro
|
||||||
|
- header rewrites - read and write protected headers
|
||||||
|
- bypass CORS - always allows browser to send requests through it
|
||||||
|
- secure it with turnstile - prevent bots from using your proxy
|
||||||
|
|
||||||
|
> [!WARNING]
|
||||||
|
> Turnstile integration only works properly with cloudflare workers as platform
|
||||||
|
|
||||||
|
### supported platforms:
|
||||||
|
- cloudflare workers
|
||||||
|
- AWS lambda
|
||||||
|
- nodejs
|
||||||
|
10
nitro.config.ts
Normal file
10
nitro.config.ts
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
import { join } from "path";
|
||||||
|
|
||||||
|
//https://nitro.unjs.io/config
|
||||||
|
export default defineNitroConfig({
|
||||||
|
noPublicDir: true,
|
||||||
|
srcDir: "./src",
|
||||||
|
alias: {
|
||||||
|
"@": join(__dirname, "src")
|
||||||
|
}
|
||||||
|
});
|
3090
package-lock.json
generated
3090
package-lock.json
generated
File diff suppressed because it is too large
Load Diff
33
package.json
33
package.json
@@ -1,18 +1,31 @@
|
|||||||
{
|
{
|
||||||
"name": "simple-proxy",
|
"name": "simple-proxy",
|
||||||
"private": true,
|
"private": true,
|
||||||
"version": "1.0.0",
|
"version": "2.1.0",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"build": "vite build",
|
"prepare": "nitropack prepare",
|
||||||
"lint": "eslint --ext .js src/",
|
"dev": "nitropack dev",
|
||||||
"lint:fix": "eslint --fix --ext .js src/",
|
"build": "nitropack build",
|
||||||
"lint:report": "eslint --ext .js --output-file eslint_report.json --format json src/"
|
"build:cloudflare": "NITRO_PRESET=cloudflare npm run build",
|
||||||
|
"build:aws": "NITRO_PRESET=aws_lambda npm run build",
|
||||||
|
"build:node": "NITRO_PRESET=node-server npm run build",
|
||||||
|
"start": "node .output/server/index.mjs",
|
||||||
|
"lint": "eslint --ext .ts src/",
|
||||||
|
"lint:fix": "eslint --fix --ext .ts src/",
|
||||||
|
"preinstall": "npx only-allow pnpm"
|
||||||
|
},
|
||||||
|
"dependencies": {
|
||||||
|
"@tsndr/cloudflare-worker-jwt": "^2.3.2",
|
||||||
|
"h3": "^1.8.1",
|
||||||
|
"nitropack": "latest"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"eslint": "^8.30.0",
|
"@typescript-eslint/eslint-plugin": "^6.7.0",
|
||||||
"eslint-config-prettier": "^8.5.0",
|
"@typescript-eslint/parser": "^6.7.0",
|
||||||
"eslint-plugin-prettier": "^4.2.1",
|
"eslint": "^8.48.0",
|
||||||
"vite": "^4.0.0",
|
"eslint-config-airbnb-base": "^15.0.0",
|
||||||
"vite-plugin-eslint": "^1.8.1"
|
"eslint-config-prettier": "^9.0.0",
|
||||||
|
"eslint-import-resolver-typescript": "^3.6.0",
|
||||||
|
"eslint-plugin-prettier": "^5.0.0"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
4041
pnpm-lock.yaml
generated
Normal file
4041
pnpm-lock.yaml
generated
Normal file
File diff suppressed because it is too large
Load Diff
140
src/main.js
140
src/main.js
@@ -1,140 +0,0 @@
|
|||||||
const corsHeaders = {
|
|
||||||
'Access-Control-Allow-Origin': '*',
|
|
||||||
'Access-Control-Allow-Methods': 'GET,HEAD,POST,OPTIONS',
|
|
||||||
'Access-Control-Max-Age': '86400',
|
|
||||||
};
|
|
||||||
|
|
||||||
async function handleRequest(request, destinationUrl, iteration = 0) {
|
|
||||||
console.log(
|
|
||||||
`PROXYING ${destinationUrl}${
|
|
||||||
iteration ? ' ON ITERATION ' + iteration : ''
|
|
||||||
}`,
|
|
||||||
);
|
|
||||||
|
|
||||||
// Rewrite request to point to API url. This also makes the request mutable
|
|
||||||
// so we can add the correct Origin header to make the API server think
|
|
||||||
// that this request isn't cross-site.
|
|
||||||
request = new Request(destinationUrl, request);
|
|
||||||
request.headers.set('Origin', new URL(destinationUrl).origin);
|
|
||||||
|
|
||||||
// Set PHPSESSID cookie
|
|
||||||
if (request.headers.get('PHPSESSID')) {
|
|
||||||
request.headers.set(
|
|
||||||
'Cookie',
|
|
||||||
`PHPSESSID=${request.headers.get('PHPSESSID')};`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Set User Agent
|
|
||||||
request.headers.set(
|
|
||||||
'User-Agent',
|
|
||||||
' Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0',
|
|
||||||
);
|
|
||||||
|
|
||||||
let response = await fetch(request);
|
|
||||||
|
|
||||||
if (
|
|
||||||
(response.status === 302 || response.status === 301) &&
|
|
||||||
response.headers.get('location')
|
|
||||||
) {
|
|
||||||
if (iteration > 5) {
|
|
||||||
event.respondWith(
|
|
||||||
new Response('418 Too many redirects', {
|
|
||||||
status: 418,
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
return await handleRequest(
|
|
||||||
request,
|
|
||||||
response.headers.get('location'),
|
|
||||||
iteration + 1,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Recreate the response so we can modify the headers
|
|
||||||
response = new Response(response.body, response);
|
|
||||||
|
|
||||||
// Set CORS headers
|
|
||||||
response.headers.set('Access-Control-Allow-Origin', '*');
|
|
||||||
response.headers.set('Access-Control-Expose-Headers', '*');
|
|
||||||
|
|
||||||
// Get and set PHPSESSID cookie
|
|
||||||
const cookies = response.headers.get('Set-Cookie');
|
|
||||||
if (cookies && cookies.includes('PHPSESSID') && cookies.includes(';')) {
|
|
||||||
let phpsessid = cookies.slice(cookies.search('PHPSESSID') + 10);
|
|
||||||
phpsessid = phpsessid.slice(0, phpsessid.search(';'));
|
|
||||||
response.headers.set('PHPSESSID', phpsessid);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Append to/Add Vary header so browser will cache response correctly
|
|
||||||
response.headers.append('Vary', 'Origin');
|
|
||||||
|
|
||||||
return response;
|
|
||||||
}
|
|
||||||
|
|
||||||
function handleOptions(request) {
|
|
||||||
// Make sure the necessary headers are present
|
|
||||||
// for this to be a valid pre-flight request
|
|
||||||
let headers = request.headers;
|
|
||||||
|
|
||||||
if (
|
|
||||||
headers.get('Origin') !== null &&
|
|
||||||
headers.get('Access-Control-Request-Method') !== null &&
|
|
||||||
headers.get('Access-Control-Request-Headers') !== null
|
|
||||||
) {
|
|
||||||
return new Response(null, {
|
|
||||||
headers: {
|
|
||||||
...corsHeaders,
|
|
||||||
// Allow all future content Request headers to go back to browser
|
|
||||||
// such as Authorization (Bearer) or X-Client-Name-Version
|
|
||||||
'Access-Control-Allow-Headers': request.headers.get(
|
|
||||||
'Access-Control-Request-Headers',
|
|
||||||
),
|
|
||||||
},
|
|
||||||
});
|
|
||||||
} else {
|
|
||||||
// Handle standard OPTIONS request
|
|
||||||
return new Response(null, {
|
|
||||||
headers: {
|
|
||||||
Allow: 'GET, HEAD, POST, OPTIONS',
|
|
||||||
},
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
addEventListener('fetch', (event) => {
|
|
||||||
const request = event.request;
|
|
||||||
const url = new URL(request.url);
|
|
||||||
const destinationUrl = url.searchParams.get('destination');
|
|
||||||
|
|
||||||
console.log(`HTTP ${request.method} - ${request.url}`);
|
|
||||||
|
|
||||||
if (request.method === 'OPTIONS') {
|
|
||||||
// Handle CORS preflight requests
|
|
||||||
event.respondWith(handleOptions(request));
|
|
||||||
} else if (!destinationUrl) {
|
|
||||||
event.respondWith(
|
|
||||||
new Response('200 OK', {
|
|
||||||
status: 200,
|
|
||||||
headers: {
|
|
||||||
Allow: 'GET, HEAD, POST, OPTIONS',
|
|
||||||
'Access-Control-Allow-Origin': '*',
|
|
||||||
},
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
} else if (
|
|
||||||
request.method === 'GET' ||
|
|
||||||
request.method === 'HEAD' ||
|
|
||||||
request.method === 'POST'
|
|
||||||
) {
|
|
||||||
// Handle request
|
|
||||||
event.respondWith(handleRequest(request, destinationUrl));
|
|
||||||
} else {
|
|
||||||
event.respondWith(
|
|
||||||
new Response('404 Not Found', {
|
|
||||||
status: 404,
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
});
|
|
55
src/routes/index.ts
Normal file
55
src/routes/index.ts
Normal file
@@ -0,0 +1,55 @@
|
|||||||
|
import { getBodyBuffer } from '@/utils/body';
|
||||||
|
import {
|
||||||
|
getProxyHeaders,
|
||||||
|
getAfterResponseHeaders,
|
||||||
|
cleanupHeadersBeforeProxy,
|
||||||
|
} from '@/utils/headers';
|
||||||
|
import {
|
||||||
|
createTokenIfNeeded,
|
||||||
|
isAllowedToMakeRequest,
|
||||||
|
setTokenHeader,
|
||||||
|
} from '@/utils/turnstile';
|
||||||
|
|
||||||
|
export default defineEventHandler(async (event) => {
|
||||||
|
// handle cors, if applicable
|
||||||
|
if (isPreflightRequest(event)) return handleCors(event, {});
|
||||||
|
|
||||||
|
// parse destination URL
|
||||||
|
const destination = getQuery<{ destination?: string }>(event).destination;
|
||||||
|
if (!destination)
|
||||||
|
return await sendJson({
|
||||||
|
event,
|
||||||
|
status: 200,
|
||||||
|
data: {
|
||||||
|
message: 'Proxy is working as expected',
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!(await isAllowedToMakeRequest(event)))
|
||||||
|
return await sendJson({
|
||||||
|
event,
|
||||||
|
status: 401,
|
||||||
|
data: {
|
||||||
|
error: 'Invalid or missing token',
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
// read body
|
||||||
|
const body = await getBodyBuffer(event);
|
||||||
|
const token = await createTokenIfNeeded(event);
|
||||||
|
|
||||||
|
// proxy
|
||||||
|
cleanupHeadersBeforeProxy(event);
|
||||||
|
await proxyRequest(event, destination, {
|
||||||
|
fetchOptions: {
|
||||||
|
redirect: 'follow',
|
||||||
|
headers: getProxyHeaders(event.headers),
|
||||||
|
body,
|
||||||
|
},
|
||||||
|
onResponse(outputEvent, response) {
|
||||||
|
const headers = getAfterResponseHeaders(response.headers, response.url);
|
||||||
|
setResponseHeaders(outputEvent, headers);
|
||||||
|
if (token) setTokenHeader(event, token);
|
||||||
|
},
|
||||||
|
});
|
||||||
|
});
|
13
src/utils/body.ts
Normal file
13
src/utils/body.ts
Normal file
@@ -0,0 +1,13 @@
|
|||||||
|
import { H3Event } from 'h3';
|
||||||
|
|
||||||
|
export function hasBody(event: H3Event) {
|
||||||
|
const method = event.method.toUpperCase();
|
||||||
|
return ['PUT', 'POST', 'PATCH', 'DELETE'].includes(method);
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function getBodyBuffer(
|
||||||
|
event: H3Event,
|
||||||
|
): Promise<Buffer | undefined> {
|
||||||
|
if (!hasBody(event)) return;
|
||||||
|
return await readRawBody(event, false);
|
||||||
|
}
|
73
src/utils/headers.ts
Normal file
73
src/utils/headers.ts
Normal file
@@ -0,0 +1,73 @@
|
|||||||
|
import { H3Event } from 'h3';
|
||||||
|
|
||||||
|
const blacklistedHeaders = [
|
||||||
|
'cf-connecting-ip',
|
||||||
|
'cf-worker',
|
||||||
|
'cf-ray',
|
||||||
|
'cf-visitor',
|
||||||
|
'cf-ew-via',
|
||||||
|
'x-forwarded-for',
|
||||||
|
'x-forwarded-host',
|
||||||
|
'x-forwarded-proto',
|
||||||
|
'forwarded',
|
||||||
|
'x-real-ip',
|
||||||
|
];
|
||||||
|
|
||||||
|
function copyHeader(
|
||||||
|
headers: Headers,
|
||||||
|
outputHeaders: Headers,
|
||||||
|
inputKey: string,
|
||||||
|
outputKey: string,
|
||||||
|
) {
|
||||||
|
if (headers.has(inputKey))
|
||||||
|
outputHeaders.set(outputKey, headers.get(inputKey) ?? '');
|
||||||
|
}
|
||||||
|
|
||||||
|
export function getProxyHeaders(headers: Headers): Headers {
|
||||||
|
const output = new Headers();
|
||||||
|
|
||||||
|
const headerMap: Record<string, string> = {
|
||||||
|
'X-Cookie': 'Cookie',
|
||||||
|
'X-Referer': 'Referer',
|
||||||
|
'X-Origin': 'Origin',
|
||||||
|
};
|
||||||
|
Object.entries(headerMap).forEach((entry) => {
|
||||||
|
copyHeader(headers, output, entry[0], entry[1]);
|
||||||
|
});
|
||||||
|
|
||||||
|
output.set(
|
||||||
|
'User-Agent',
|
||||||
|
'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0',
|
||||||
|
);
|
||||||
|
|
||||||
|
return output;
|
||||||
|
}
|
||||||
|
|
||||||
|
export function getAfterResponseHeaders(
|
||||||
|
headers: Headers,
|
||||||
|
finalUrl: string,
|
||||||
|
): Record<string, string> {
|
||||||
|
const output: Record<string, string> = {};
|
||||||
|
|
||||||
|
if (headers.has('Set-Cookie'))
|
||||||
|
output['X-Set-Cookie'] = headers.get('Set-Cookie') ?? '';
|
||||||
|
|
||||||
|
return {
|
||||||
|
'Access-Control-Allow-Origin': '*',
|
||||||
|
'Access-Control-Expose-Headers': '*',
|
||||||
|
Vary: 'Origin',
|
||||||
|
'X-Final-Destination': finalUrl,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
export function removeHeadersFromEvent(event: H3Event, key: string) {
|
||||||
|
const normalizedKey = key.toLowerCase();
|
||||||
|
if (event.node.req.headers[normalizedKey])
|
||||||
|
delete event.node.req.headers[normalizedKey];
|
||||||
|
}
|
||||||
|
|
||||||
|
export function cleanupHeadersBeforeProxy(event: H3Event) {
|
||||||
|
blacklistedHeaders.forEach((key) => {
|
||||||
|
removeHeadersFromEvent(event, key);
|
||||||
|
});
|
||||||
|
}
|
10
src/utils/ip.ts
Normal file
10
src/utils/ip.ts
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
import { EventHandlerRequest, H3Event } from 'h3';
|
||||||
|
|
||||||
|
export function getIp(event: H3Event<EventHandlerRequest>) {
|
||||||
|
const value = getHeader(event, 'CF-Connecting-IP');
|
||||||
|
if (!value)
|
||||||
|
throw new Error(
|
||||||
|
'Ip header not found, turnstile only works on cloudflare workers',
|
||||||
|
);
|
||||||
|
return value;
|
||||||
|
}
|
10
src/utils/sending.ts
Normal file
10
src/utils/sending.ts
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
import { H3Event, EventHandlerRequest } from 'h3';
|
||||||
|
|
||||||
|
export async function sendJson(ops: {
|
||||||
|
event: H3Event<EventHandlerRequest>;
|
||||||
|
data: Record<string, any>;
|
||||||
|
status?: number;
|
||||||
|
}) {
|
||||||
|
setResponseStatus(ops.event, ops.status ?? 200);
|
||||||
|
await send(ops.event, JSON.stringify(ops.data, null, 2), 'application/json');
|
||||||
|
}
|
87
src/utils/turnstile.ts
Normal file
87
src/utils/turnstile.ts
Normal file
@@ -0,0 +1,87 @@
|
|||||||
|
import { H3Event, EventHandlerRequest } from 'h3';
|
||||||
|
import jsonwebtoken from '@tsndr/cloudflare-worker-jwt';
|
||||||
|
import { getIp } from '@/utils/ip';
|
||||||
|
|
||||||
|
const turnstileSecret = process.env.TURNSTILE_SECRET ?? null;
|
||||||
|
const jwtSecret = process.env.JWT_SECRET ?? null;
|
||||||
|
|
||||||
|
const tokenHeader = 'X-Token';
|
||||||
|
const jwtPrefix = 'jwt|';
|
||||||
|
const turnstilePrefix = 'turnstile|';
|
||||||
|
|
||||||
|
export function isTurnstileEnabled() {
|
||||||
|
return !!turnstileSecret && !!jwtSecret;
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function makeToken(ip: string) {
|
||||||
|
if (!jwtSecret) throw new Error('Cannot make token without a secret');
|
||||||
|
return await jsonwebtoken.sign(
|
||||||
|
{
|
||||||
|
ip,
|
||||||
|
exp: Math.floor(Date.now() / 1000) + 60 * 10, // 10 Minutes
|
||||||
|
},
|
||||||
|
jwtSecret,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
export function setTokenHeader(
|
||||||
|
event: H3Event<EventHandlerRequest>,
|
||||||
|
token: string,
|
||||||
|
) {
|
||||||
|
setHeader(event, tokenHeader, token);
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function createTokenIfNeeded(
|
||||||
|
event: H3Event<EventHandlerRequest>,
|
||||||
|
): Promise<null | string> {
|
||||||
|
if (!isTurnstileEnabled()) return null;
|
||||||
|
if (!jwtSecret) return null;
|
||||||
|
const token = event.headers.get(tokenHeader);
|
||||||
|
if (!token) return null;
|
||||||
|
if (!token.startsWith(turnstilePrefix)) return null;
|
||||||
|
|
||||||
|
return await makeToken(getIp(event));
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function isAllowedToMakeRequest(
|
||||||
|
event: H3Event<EventHandlerRequest>,
|
||||||
|
) {
|
||||||
|
if (!isTurnstileEnabled()) return true;
|
||||||
|
|
||||||
|
const token = event.headers.get(tokenHeader);
|
||||||
|
if (!token) return false;
|
||||||
|
if (!jwtSecret || !turnstileSecret) return false;
|
||||||
|
|
||||||
|
if (token.startsWith(jwtPrefix)) {
|
||||||
|
const jwtToken = token.slice(jwtPrefix.length);
|
||||||
|
const isValid = await jsonwebtoken.verify(jwtToken, jwtSecret, {
|
||||||
|
algorithm: 'HS256',
|
||||||
|
});
|
||||||
|
if (!isValid) return false;
|
||||||
|
const jwtBody = jsonwebtoken.decode<{ ip: string }>(jwtToken);
|
||||||
|
if (!jwtBody.payload) return false;
|
||||||
|
if (getIp(event) !== jwtBody.payload.ip) return false;
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (token.startsWith(turnstilePrefix)) {
|
||||||
|
const turnstileToken = token.slice(turnstilePrefix.length);
|
||||||
|
const formData = new FormData();
|
||||||
|
formData.append('secret', turnstileSecret);
|
||||||
|
formData.append('response', turnstileToken);
|
||||||
|
formData.append('remoteip', getIp(event));
|
||||||
|
|
||||||
|
const result = await fetch(
|
||||||
|
'https://challenges.cloudflare.com/turnstile/v0/siteverify',
|
||||||
|
{
|
||||||
|
body: formData,
|
||||||
|
method: 'POST',
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
const outcome: { success: boolean } = await result.json();
|
||||||
|
return outcome.success;
|
||||||
|
}
|
||||||
|
|
||||||
|
return false;
|
||||||
|
}
|
23
tsconfig.json
Normal file
23
tsconfig.json
Normal file
@@ -0,0 +1,23 @@
|
|||||||
|
{
|
||||||
|
"compilerOptions": {
|
||||||
|
"target": "ES2020",
|
||||||
|
"lib": ["dom", "dom.iterable", "esnext"],
|
||||||
|
"allowJs": true,
|
||||||
|
"skipLibCheck": true,
|
||||||
|
"esModuleInterop": true,
|
||||||
|
"allowSyntheticDefaultImports": true,
|
||||||
|
"strict": true,
|
||||||
|
"forceConsistentCasingInFileNames": true,
|
||||||
|
"noFallthroughCasesInSwitch": true,
|
||||||
|
"module": "esnext",
|
||||||
|
"moduleResolution": "node",
|
||||||
|
"resolveJsonModule": true,
|
||||||
|
"isolatedModules": true,
|
||||||
|
"noEmit": true,
|
||||||
|
"baseUrl": "./src",
|
||||||
|
"paths": {
|
||||||
|
"@/*": ["./*"]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"extends": "./.nitro/types/tsconfig.json"
|
||||||
|
}
|
@@ -1,16 +0,0 @@
|
|||||||
const path = require('path');
|
|
||||||
const { defineConfig } = require('vite');
|
|
||||||
const { default: eslint } = require('vite-plugin-eslint');
|
|
||||||
|
|
||||||
module.exports = defineConfig({
|
|
||||||
plugins: [eslint()],
|
|
||||||
build: {
|
|
||||||
minify: false,
|
|
||||||
lib: {
|
|
||||||
entry: path.resolve(__dirname, 'src/main.js'),
|
|
||||||
name: 'worker',
|
|
||||||
formats: ['es'],
|
|
||||||
fileName: () => `worker.js`,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
});
|
|
4
wrangler.toml
Normal file
4
wrangler.toml
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
name = "simple-proxy"
|
||||||
|
main = "./.output/server/index.mjs"
|
||||||
|
workers_dev = true
|
||||||
|
compatibility_date = "2022-09-10"
|
Reference in New Issue
Block a user