tcpforwarding.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496
  1. package service
  2. import (
  3. "context"
  4. "encoding/json"
  5. "fmt"
  6. v1 "github.com/go-nunu/nunu-layout-advanced/api/v1"
  7. "github.com/go-nunu/nunu-layout-advanced/internal/model"
  8. "github.com/go-nunu/nunu-layout-advanced/internal/repository"
  9. "golang.org/x/sync/errgroup"
  10. "maps"
  11. "net"
  12. "sort"
  13. )
  14. type TcpforwardingService interface {
  15. GetTcpforwarding(ctx context.Context, req v1.GetForwardingRequest) (v1.TcpForwardingDataRequest, error)
  16. AddTcpForwarding(ctx context.Context, req *v1.TcpForwardingRequest) error
  17. EditTcpForwarding(ctx context.Context, req *v1.TcpForwardingRequest) error
  18. DeleteTcpForwarding(ctx context.Context, req v1.DeleteTcpForwardingRequest) error
  19. GetTcpForwardingAllIpsByHostId(ctx context.Context, req v1.GetForwardingRequest) ([]v1.TcpForwardingDataRequest, error)
  20. }
  21. func NewTcpforwardingService(
  22. service *Service,
  23. tcpforwardingRepository repository.TcpforwardingRepository,
  24. parser ParserService,
  25. required RequiredService,
  26. crawler CrawlerService,
  27. globalRep repository.GlobalLimitRepository,
  28. hostRep repository.HostRepository,
  29. wafformatter WafFormatterService,
  30. cdn CdnService,
  31. proxy ProxyService,
  32. ) TcpforwardingService {
  33. return &tcpforwardingService{
  34. Service: service,
  35. tcpforwardingRepository: tcpforwardingRepository,
  36. parser: parser,
  37. required: required,
  38. crawler: crawler,
  39. globalRep: globalRep,
  40. hostRep: hostRep,
  41. wafformatter: wafformatter,
  42. cdn: cdn,
  43. proxy: proxy,
  44. }
  45. }
  46. type tcpforwardingService struct {
  47. *Service
  48. tcpforwardingRepository repository.TcpforwardingRepository
  49. parser ParserService
  50. required RequiredService
  51. crawler CrawlerService
  52. globalRep repository.GlobalLimitRepository
  53. hostRep repository.HostRepository
  54. wafformatter WafFormatterService
  55. cdn CdnService
  56. proxy ProxyService
  57. }
  58. func (s *tcpforwardingService) GetTcpforwarding(ctx context.Context, req v1.GetForwardingRequest) (v1.TcpForwardingDataRequest, error) {
  59. var tcpForwarding model.Tcpforwarding
  60. var backend model.TcpForwardingRule
  61. var err error
  62. g, gCtx := errgroup.WithContext(ctx)
  63. g.Go(func() error {
  64. res, e := s.tcpforwardingRepository.GetTcpforwarding(gCtx, int64(req.Id))
  65. if e != nil {
  66. return fmt.Errorf("GetTcpforwarding failed: %w", e)
  67. }
  68. if res != nil {
  69. tcpForwarding = *res
  70. }
  71. return nil
  72. })
  73. g.Go(func() error {
  74. res, e := s.tcpforwardingRepository.GetTcpForwardingIpsByID(gCtx, req.Id)
  75. if e != nil {
  76. return fmt.Errorf("GetTcpforwardingIps failed: %w", e)
  77. }
  78. if res != nil {
  79. backend = *res
  80. }
  81. return nil
  82. })
  83. if err = g.Wait(); err != nil {
  84. return v1.TcpForwardingDataRequest{}, err
  85. }
  86. return v1.TcpForwardingDataRequest{
  87. Id: tcpForwarding.Id,
  88. Port: tcpForwarding.Port,
  89. Comment: tcpForwarding.Comment,
  90. Proxy: tcpForwarding.Proxy,
  91. BackendList: backend.BackendList,
  92. }, nil
  93. }
  94. func (s *tcpforwardingService) buildTcpForwardingModel(req *v1.TcpForwardingDataRequest, ruleId int, require RequireResponse) *model.Tcpforwarding {
  95. return &model.Tcpforwarding{
  96. HostId: require.HostId,
  97. CdnWebId: ruleId,
  98. Port: req.Port,
  99. Comment: req.Comment,
  100. Proxy: req.Proxy,
  101. }
  102. }
  103. func (s *tcpforwardingService) buildTcpRuleModel(reqData *v1.TcpForwardingDataRequest, require RequireResponse, localDbId int, cdnOriginIds map[string]int64) *model.TcpForwardingRule {
  104. return &model.TcpForwardingRule{
  105. Uid: require.Uid,
  106. HostId: require.HostId,
  107. TcpId: localDbId, // 关联到本地数据库的主记录 ID
  108. CdnOriginIds: cdnOriginIds,
  109. BackendList: reqData.BackendList,
  110. }
  111. }
  112. func (s *tcpforwardingService) prepareWafData(ctx context.Context, req *v1.TcpForwardingRequest) (RequireResponse, v1.WebsiteSend, error) {
  113. // 1. 获取必要的全局信息
  114. require, err := s.wafformatter.Require(ctx, v1.GlobalRequire{
  115. HostId: req.HostId,
  116. Uid: req.Uid,
  117. Comment: req.TcpForwardingData.Comment,
  118. })
  119. if err != nil {
  120. return RequireResponse{}, v1.WebsiteSend{}, err
  121. }
  122. if require.GatewayGroupId == 0 || require.Uid == 0 {
  123. return RequireResponse{}, v1.WebsiteSend{}, fmt.Errorf("请先配置实例")
  124. }
  125. var jsonData v1.TypeJSON
  126. jsonData.IsOn = true
  127. for _, v := range require.GatewayIps {
  128. jsonData.Listen = append(jsonData.Listen, v1.Listen{
  129. Protocol: "tcp",
  130. Host: v,
  131. Port: req.TcpForwardingData.Port,
  132. })
  133. }
  134. byteData, err := json.Marshal(jsonData)
  135. if err != nil {
  136. return RequireResponse{}, v1.WebsiteSend{}, err
  137. }
  138. formData := v1.WebsiteSend{
  139. UserId: int64(require.CdnUid),
  140. Type: "tcpProxy",
  141. Name: require.Tag,
  142. Description: req.TcpForwardingData.Comment,
  143. TcpJSON: byteData,
  144. ServerGroupIds: []int64{int64(require.GroupId)},
  145. UserPlanId: int64(require.RuleId),
  146. NodeClusterId: 1,
  147. }
  148. return require, formData, nil
  149. }
  150. func (s *tcpforwardingService) AddTcpForwarding(ctx context.Context, req *v1.TcpForwardingRequest) error {
  151. require, formData, err := s.prepareWafData(ctx, req)
  152. if err != nil {
  153. return err
  154. }
  155. err = s.wafformatter.validateWafPortCount(ctx, require.HostId)
  156. if err != nil {
  157. return err
  158. }
  159. // 验证端口重复
  160. err = s.wafformatter.VerifyPort(ctx, "tcp", req.TcpForwardingData.Port, int64(require.HostId), "")
  161. if err != nil {
  162. return err
  163. }
  164. tcpId, err := s.cdn.CreateWebsite(ctx, formData)
  165. if err != nil {
  166. return err
  167. }
  168. // 添加源站
  169. cdnOriginIds := make(map[string]int64)
  170. for _, v := range req.TcpForwardingData.BackendList{
  171. id, err := s.wafformatter.AddOrigin(ctx, v1.WebJson{
  172. ApiType: "tcp",
  173. BackendList: v,
  174. Comment: req.TcpForwardingData.Comment,
  175. })
  176. if err != nil {
  177. return err
  178. }
  179. cdnOriginIds[v] = id
  180. }
  181. // 添加源站到网站
  182. for _, v := range cdnOriginIds {
  183. err = s.cdn.AddServerOrigin(ctx, tcpId, v)
  184. if err != nil {
  185. return err
  186. }
  187. }
  188. // 开启proxy
  189. if req.TcpForwardingData.Proxy {
  190. err = s.proxy.EditProxy(ctx,tcpId, v1.ProxyProtocolJSON{
  191. IsOn: true,
  192. Version: 1,
  193. })
  194. if err != nil {
  195. return err
  196. }
  197. }
  198. tcpModel := s.buildTcpForwardingModel(&req.TcpForwardingData, int(tcpId), require)
  199. id, err := s.tcpforwardingRepository.AddTcpforwarding(ctx, tcpModel)
  200. if err != nil {
  201. return err
  202. }
  203. TcpRuleModel := s.buildTcpRuleModel(&req.TcpForwardingData, require, id, cdnOriginIds)
  204. if _, err = s.tcpforwardingRepository.AddTcpforwardingIps(ctx, *TcpRuleModel); err != nil {
  205. return err
  206. }
  207. // 异步任务:将源站IP添加到白名单
  208. var ips []string
  209. if req.TcpForwardingData.BackendList != nil {
  210. for _, v := range req.TcpForwardingData.BackendList {
  211. ip, _, err := net.SplitHostPort(v)
  212. if err != nil {
  213. return err
  214. }
  215. ips = append(ips, ip)
  216. }
  217. go s.wafformatter.PublishIpWhitelistTask(ips, "add","","white")
  218. }
  219. return nil
  220. }
  221. func (s *tcpforwardingService) EditTcpForwarding(ctx context.Context, req *v1.TcpForwardingRequest) error {
  222. require, formData, err := s.prepareWafData(ctx, req)
  223. if err != nil {
  224. return err
  225. }
  226. oldData, err := s.tcpforwardingRepository.GetTcpforwarding(ctx, int64(req.TcpForwardingData.Id))
  227. if err != nil {
  228. return err
  229. }
  230. // 验证端口重复
  231. if oldData.Port != req.TcpForwardingData.Port {
  232. err = s.wafformatter.VerifyPort(ctx, "tcp", req.TcpForwardingData.Port, int64(require.HostId), "")
  233. if err != nil {
  234. return err
  235. }
  236. }
  237. //修改网站端口
  238. if oldData.Port != req.TcpForwardingData.Port {
  239. err = s.cdn.EditServerType(ctx, v1.EditWebsite{
  240. Id: int64(oldData.CdnWebId),
  241. TypeJSON: formData.TcpJSON,
  242. }, "tcp")
  243. if err != nil {
  244. return err
  245. }
  246. }
  247. //修改网站名字
  248. if oldData.Comment != req.TcpForwardingData.Comment {
  249. nodeId, err := s.globalRep.GetNodeId(ctx, oldData.CdnWebId)
  250. err = s.cdn.EditServerBasic(ctx, int64(oldData.CdnWebId), require.Tag, nodeId)
  251. if err != nil {
  252. return err
  253. }
  254. }
  255. //修改Proxy
  256. if oldData.Proxy != req.TcpForwardingData.Proxy {
  257. err = s.proxy.EditProxy(ctx, int64(oldData.CdnWebId), v1.ProxyProtocolJSON{
  258. IsOn: req.TcpForwardingData.Proxy,
  259. Version: 1,
  260. })
  261. if err != nil {
  262. return err
  263. }
  264. }
  265. // 异步任务:将IP添加到白名单
  266. ipData, err := s.tcpforwardingRepository.GetTcpForwardingIpsByID(ctx, req.TcpForwardingData.Id)
  267. if err != nil {
  268. return err
  269. }
  270. addedIps, removedIps, err := s.wafformatter.WashEditWafIp(ctx,req.TcpForwardingData.BackendList, ipData.BackendList)
  271. if err != nil {
  272. return err
  273. }
  274. if len(addedIps) > 0 {
  275. go s.wafformatter.PublishIpWhitelistTask(addedIps, "add","","white")
  276. }
  277. if len(removedIps) > 0 {
  278. ipsToDelist, err := s.wafformatter.WashDelIps(ctx, removedIps)
  279. if err != nil {
  280. return err
  281. }
  282. // 4. 如果有需要处理的IP,则批量发布一次任务
  283. if len(ipsToDelist) > 0 {
  284. go s.wafformatter.PublishIpWhitelistTask(ipsToDelist, "del", "0", "white")
  285. }
  286. }
  287. //修改源站
  288. addOrigins, delOrigins := s.wafformatter.findIpDifferences(ipData.BackendList, req.TcpForwardingData.BackendList)
  289. addedIds := make(map[string]int64)
  290. for _, v := range addOrigins {
  291. id, err := s.wafformatter.AddOrigin(ctx,v1.WebJson{
  292. ApiType: "tcp",
  293. BackendList: v,
  294. Comment: req.TcpForwardingData.Comment,
  295. })
  296. if err != nil {
  297. return err
  298. }
  299. addedIds[v] = id
  300. }
  301. for _, v := range addedIds {
  302. err = s.cdn.AddServerOrigin(ctx, int64(oldData.CdnWebId), v)
  303. if err != nil {
  304. return err
  305. }
  306. }
  307. maps.Copy(ipData.CdnOriginIds, addedIds)
  308. for k, v := range ipData.CdnOriginIds {
  309. for _, ip := range delOrigins {
  310. if k == ip {
  311. err = s.cdn.DelServerOrigin(ctx, int64(oldData.CdnWebId), v)
  312. if err != nil {
  313. return err
  314. }
  315. delete(ipData.CdnOriginIds, k)
  316. }
  317. }
  318. }
  319. tcpModel := s.buildTcpForwardingModel(&req.TcpForwardingData,oldData.CdnWebId, require)
  320. tcpModel.Id = req.TcpForwardingData.Id
  321. if err = s.tcpforwardingRepository.EditTcpforwarding(ctx, tcpModel); err != nil {
  322. return err
  323. }
  324. TcpRuleModel := s.buildTcpRuleModel(&req.TcpForwardingData, require, req.TcpForwardingData.Id, ipData.CdnOriginIds)
  325. if err = s.tcpforwardingRepository.EditTcpforwardingIps(ctx, *TcpRuleModel); err != nil {
  326. return err
  327. }
  328. return nil
  329. }
  330. func (s *tcpforwardingService) DeleteTcpForwarding(ctx context.Context, req v1.DeleteTcpForwardingRequest) error {
  331. for _, Id := range req.Ids {
  332. oldData, err := s.tcpforwardingRepository.GetTcpforwarding(ctx, int64(Id))
  333. if err != nil {
  334. return err
  335. }
  336. err = s.cdn.DelServer(ctx, int64(oldData.CdnWebId))
  337. if err != nil {
  338. return err
  339. }
  340. // 删除白名单
  341. var ips []string
  342. ipData, err := s.tcpforwardingRepository.GetTcpForwardingIpsByID(ctx, Id)
  343. if err != nil {
  344. return err
  345. }
  346. ips, err = s.wafformatter.WashDeleteWafIp(ctx, ipData.BackendList)
  347. if err != nil {
  348. return err
  349. }
  350. if len(ips) > 0 {
  351. ipsToDelist, err := s.wafformatter.WashDelIps(ctx, ips)
  352. if err != nil {
  353. return err
  354. }
  355. // 4. 如果有需要处理的IP,则批量发布一次任务
  356. if len(ipsToDelist) > 0 {
  357. go s.wafformatter.PublishIpWhitelistTask(ipsToDelist, "del", "0", "white")
  358. }
  359. }
  360. if err = s.tcpforwardingRepository.DeleteTcpforwarding(ctx, int64(Id)); err != nil {
  361. return err
  362. }
  363. if err = s.tcpforwardingRepository.DeleteTcpForwardingIpsById(ctx, Id); err != nil {
  364. return err
  365. }
  366. }
  367. return nil
  368. }
  369. func (s *tcpforwardingService) GetTcpForwardingAllIpsByHostId(ctx context.Context, req v1.GetForwardingRequest) ([]v1.TcpForwardingDataRequest, error) {
  370. type CombinedResult struct {
  371. Id int
  372. Forwarding *model.Tcpforwarding
  373. BackendRule *model.TcpForwardingRule
  374. Err error // 如果此ID的处理出错,则携带错误
  375. }
  376. g,gCtx := errgroup.WithContext(ctx)
  377. ids, err := s.tcpforwardingRepository.GetTcpForwardingAllIdsByID(gCtx, req.HostId)
  378. if err != nil {
  379. return nil, fmt.Errorf("GetTcpForwardingAllIds failed: %w", err)
  380. }
  381. if len(ids) == 0 {
  382. return nil, nil
  383. }
  384. resChan := make(chan CombinedResult, len(ids))
  385. g.Go(func() error {
  386. for _, idVal := range ids {
  387. currentID := idVal
  388. g.Go(func() error {
  389. var wf *model.Tcpforwarding
  390. var bk *model.TcpForwardingRule
  391. var localErr error
  392. wf, localErr = s.tcpforwardingRepository.GetTcpforwarding(gCtx, int64(currentID))
  393. if localErr != nil {
  394. resChan <- CombinedResult{Id: currentID, Err: localErr}
  395. return localErr
  396. }
  397. bk, localErr = s.tcpforwardingRepository.GetTcpForwardingIpsByID(gCtx, currentID)
  398. if localErr != nil {
  399. resChan <- CombinedResult{Id: currentID, Err: localErr}
  400. return localErr
  401. }
  402. resChan <- CombinedResult{Id: currentID, Forwarding: wf, BackendRule: bk}
  403. return nil
  404. })
  405. }
  406. return nil
  407. })
  408. groupErr := g.Wait()
  409. close(resChan)
  410. if groupErr != nil {
  411. return nil, groupErr
  412. }
  413. res := make([]v1.TcpForwardingDataRequest, 0, len(ids))
  414. for r := range resChan {
  415. if r.Err != nil {
  416. return nil, fmt.Errorf("received error from goroutine for ID %d: %w", r.Id, r.Err)
  417. }
  418. if r.Forwarding == nil {
  419. return nil,fmt.Errorf("received nil forwarding from goroutine for ID %d", r.Id)
  420. }
  421. dataReq := v1.TcpForwardingDataRequest{
  422. Id: r.Forwarding.Id,
  423. Port: r.Forwarding.Port,
  424. Comment: r.Forwarding.Comment,
  425. Proxy: r.Forwarding.Proxy,
  426. }
  427. if r.BackendRule != nil {
  428. dataReq.BackendList = r.BackendRule.BackendList
  429. }
  430. res = append(res, dataReq)
  431. }
  432. sort.Slice(res, func(i, j int) bool {
  433. return res[i].Id > res[j].Id
  434. })
  435. return res, nil
  436. }