Compare commits

...
Author SHA1 Message Date
傲世孤尘 5f2d67937d !45 更新测试报告
Merge pull request !45 from NichenFly/dev
2023-11-16 11:53:57 +00:00
= 45f9756b68 去掉一些日志输出 2023-11-16 10:52:11 +08:00
az 0548a9b13e 更新不加密、SM2+AES加密方式的性能对比报告 2023-11-15 20:35:46 +08:00
傲世孤尘 6c2873e453 !44 添加SM2+AES加密与SSL加密的测试报告
Merge pull request !44 from NichenFly/dev
2023-11-15 07:09:44 +00:00
= de243149a9 报告中添加测试代码 2023-11-15 14:57:40 +08:00
= dfb22fa148 添加SM2+AES、SSL的测试内容 2023-11-15 14:53:58 +08:00
= 3b77ecddb9 取消使用hutool的工具进行sm2和aes的加解密 2023-11-15 12:11:22 +08:00
傲世孤尘 5b7962d727 !43 添加配置项sm2-encrypt-enable
Merge pull request !43 from NichenFly/dev
2023-11-15 01:55:49 +00:00
az 9c5ad7aa72 添加配置项目,修改日志信息,不输出公钥信息 2023-11-14 22:04:00 +08:00
傲世孤尘 c7c58a806d !42 解决加密链路解码异常问题
Merge pull request !42 from NichenFly/dev
2023-11-14 13:38:17 +00:00
az 8c14727fba 修复加密过程中的通道编码异常问题 2023-11-14 21:31:08 +08:00
= f2005b3e74 修改参数 2023-11-14 17:04:10 +08:00
= 4569165993 加密算法改为AES 2023-11-10 16:37:30 +08:00
= fc1ba4eb1a Encoder执行完后进行空间释放 2023-11-09 09:00:52 +08:00
傲世孤尘 5a7ac41911 !41 解决加密链路解码异常问题
Merge pull request !41 from NichenFly/dev
2023-11-08 13:23:13 +00:00
az 6c6506c677 解决加密链路解码异常问题 2023-11-08 21:19:29 +08:00
傲世孤尘 4afd300c92 !40 链路使用国密算法对链路进行加密,保证传输过程中信息的机密性
Merge pull request !40 from NichenFly/dev
2023-11-08 06:40:50 +00:00
= 55f85861cf 添加输出信息 2023-11-08 14:08:42 +08:00
= 1698e944ee 修改运行参数 2023-11-08 09:31:39 +08:00
az 8842ae2899 添加非安全判断 2023-11-07 22:33:39 +08:00
= 4eb04e6f0f 修改encoder和decoder适配加密过程 2023-11-07 16:46:18 +08:00
= a16fba4b03 密码协商过程 2023-11-07 15:25:41 +08:00
= 726f38c332 添加SM2、SM4的生成密钥和加解密方法 2023-11-07 10:43:26 +08:00
aoshiguchen 09f934bdd0 更新打包脚本 2023-11-02 17:32:10 +08:00
aoshiguchen d54c4644cf 新增专用于打包复制的配置文件,更新Dockerfile 2023-11-02 17:15:16 +08:00
aoshiguchen 4232be546a 更新Dockerfile 2023-11-02 16:54:29 +08:00
aoshiguchen b5b82e0b80 修正官网客户端配置错误 2023-11-02 16:18:52 +08:00
aoshiguchen 0eaad35379 jdk版本升级为21 2023-11-02 15:56:22 +08:00
aoshiguchen b754dd5456 jdk版本升级为21. 2023-11-02 14:59:49 +08:00
aoshiguchen 035db05e70 jdk版本升级为21 2023-11-02 14:54:24 +08:00
aoshiguchen f7c3e5b76b 新增文章[从Neutrino-Proxy(中微子代理)到Solon Native] 2023-11-02 13:36:33 +08:00
aoshiguchen 85d86e15c2 更新solon版本为2.5.12 2023-11-01 13:41:17 +08:00
aoshiguchen eea06908f9 更新赞赏公示 2023-11-01 11:58:42 +08:00
aoshiguchen 7fc339e6c1 更新todolist 2023-11-01 11:56:57 +08:00
songyinyin 97714e02c5 支持应用中获取当前的版本号 2023-10-31 12:02:44 +08:00
aoshiguchen d8d5cc61ab aot阶段操作数据库逻辑跳过 2023-10-30 18:19:56 +08:00
aoshiguchen 67bcbb4383 .. 2023-10-30 17:17:59 +08:00
aoshiguchen c8207097c1 日志输出内容调整. 2023-10-30 12:40:42 +08:00
songyinyin 8a89786a41 原生编译:增加三方包 高版本jdk 反射的支持 2023-10-29 21:43:29 +08:00
songyinyin c9b501f334 打包时把 lombok 排除掉 2023-10-29 21:40:57 +08:00
aoshiguchen e90bc0f10a 修正官网错别字 2023-10-28 10:47:03 +08:00
aoshiguchen 66d98711bf 更新官网使用须知 2023-10-28 10:42:12 +08:00
aoshiguchen de0ac5b500 更新公众号官宣文章. 2023-10-27 23:32:15 +08:00
aoshiguchen 1dffa1d921 更新官网文档. 2023-10-27 23:24:13 +08:00
aoshiguchen 42dedf03e1 升级solon版本. 2023-10-27 21:12:02 +08:00
aoshiguchen f1ebc47f51 服务端、客户端native编译打包脚本调整 2023-10-27 18:12:29 +08:00
aoshiguchen 4ca43572a0 服务端、客户端编译打包脚本调整 2023-10-27 17:36:44 +08:00
aoshiguchen 116f3d7b36 workflow去掉mac构建 2023-10-27 15:52:07 +08:00
aoshiguchen 265699c3dc aot阶段放开数据库初始化 2023-10-27 15:30:47 +08:00
63 changed files with 1411 additions and 483 deletions
+9 -6
View File
@@ -1,7 +1,7 @@
name: Build linux and mac native image
on:
workflow_dispatch:
workflow_dispatch:
push:
tags:
- 'v*'
@@ -12,7 +12,8 @@ jobs:
fail-fast: false
matrix:
# see: https://docs.github.com/zh/actions/using-jobs/choosing-the-runner-for-a-job
os: ['ubuntu-20.04', 'macos-12']
# os: ['ubuntu-20.04', 'macos-12']
os: ['ubuntu-20.04']
name: build - ${{ matrix.os }}
runs-on: ${{ matrix.os }}
# https://github.com/softprops/action-gh-release/issues/236#issuecomment-1150530128
@@ -29,12 +30,12 @@ jobs:
run: |
cd neutrino-proxy-admin
npm install
npm run build:docker
npm run build:docker·
cp -rf ./dist/ ./../neutrino-proxy-server/src/main/resources/static/
- name: GitHub Action for GraalVM JDK 17
uses: graalvm/setup-graalvm@v1
with:
java-version: '17.0.7' # for a specific JDK 17; or '17' for the latest JDK 17
java-version: '21.0.1' # for a specific JDK 17; or '17' for the latest JDK 17
distribution: 'graalvm' # New 'distribution' option
github-token: ${{ secrets.GITHUB_TOKEN }}
- name: Cache local Maven repository
@@ -47,10 +48,11 @@ jobs:
- name: Build with Maven (neutrino-proxy-server)
run: |
mvn clean install -pl neutrino-proxy-core -am -DskipTests --no-transfer-progress
cd neutrino-proxy-server
cd neutrino-proxy-server
mvn clean native:compile -P native --file pom.xml --no-transfer-progress
chmod +x target/neutrino-proxy-server
cp target/neutrino-proxy-server ./../neutrino-proxy-server-${{ github.ref_name }}
cp target/classes/app-copy.yml ./../neutrino-proxy-server-${{ github.ref_name }}/app.yml
- name: Archive zip (neutrino-proxy-server)
uses: thedoctor0/zip-release@master
with:
@@ -64,6 +66,7 @@ jobs:
mvn clean native:compile -P native --file pom.xml --no-transfer-progress
chmod +x target/neutrino-proxy-client
cp target/neutrino-proxy-client ./../neutrino-proxy-client-${{ github.ref_name }}
cp target/classes/app-copy.yml ./../neutrino-proxy-client-${{ github.ref_name }}/app.yml
- name: Archive zip (neutrino-proxy-client)
uses: thedoctor0/zip-release@master
with:
@@ -81,4 +84,4 @@ jobs:
neutrino-proxy-server-${{ matrix.os }}-${{ github.ref_name }}.zip
neutrino-proxy-client-${{ matrix.os }}-${{ github.ref_name }}.zip
prerelease: true
token: ${{ secrets.GITHUB_TOKEN }}
token: ${{ secrets.GITHUB_TOKEN }}
+3 -3
View File
@@ -1,7 +1,7 @@
name: Build windows native image
on:
workflow_dispatch:
workflow_dispatch:
push:
tags:
- 'v*'
@@ -34,7 +34,7 @@ jobs:
- name: GitHub Action for GraalVM JDK 17
uses: graalvm/setup-graalvm@v1
with:
java-version: '17.0.7' # for a specific JDK 17; or '17' for the latest JDK 17
java-version: '21.0.1' # for a specific JDK 17; or '17' for the latest JDK 17
distribution: 'graalvm' # New 'distribution' option
github-token: ${{ secrets.GITHUB_TOKEN }}
- name: Cache local Maven repository
@@ -81,4 +81,4 @@ jobs:
neutrino-proxy-server-${{ matrix.os }}-${{ github.ref_name }}.zip
neutrino-proxy-client-${{ matrix.os }}-${{ github.ref_name }}.zip
prerelease: true
token: ${{ secrets.GITHUB_TOKEN }}
token: ${{ secrets.GITHUB_TOKEN }}
-52
View File
@@ -1,52 +0,0 @@
# 基础
- [x] 服务端编译、启动成功
- [x] 客户端编译、启动成功
- [x] 配置
- [x] 启动参数
- [x] 外部配置文件
- [x] 环境变量
- [x] 日志
- [x] 控制台输出
- [x] debug启动有netty错误日志
- [x] 文件输出
- [x] 修改日志级别
- [x] 心跳日志
- [x] 传输报文日志
- [x] 连接
- [x] 隧道SSL连接
- [x] 隧道非SSL连接
- [x] 隧道SSL连接自定义证书
# 服务端管理后台
- [x] 登录成功
- [x] 首页统计
- [x] 代理配置
- [x] license管理
- [x] 端口映射
- [x] 系统管理
- [x] 用户管理
- [x] 端口分组管理
- [x] 端口池管理
- [x] 协议管理
- [x] 调度管理
- [x] 报表管理
- [x] 用户流量报表
- [x] License流量报表
- [x] 用户流量月度明细
- [x] License流量月度明细
- [x] 日志管理
- [x] 调度日志
- [x] 登录日志
- [x] 客户端连接日志
# 客户端
- [x] 重连机制
# 代理
- [x] TCP代理
- [x] HTTP(S)代理
- [x] 端口访问
- [x] HTTP域名访问
- [x] HTTPS域名访问
- [x] UDP代理
+5 -2
View File
@@ -25,8 +25,8 @@
- 9、原生部署:支持编译为原生可执行文件,更低部署门槛、更少内存占用
- 10、采用最为宽松的MIT协议,免去你的后顾之忧
## 更新内容
- solon版本升级为`2.5.11`
## 本次更新内容
- solon版本升级为`2.5.12-M1`
- jdk版本升级为17
- 支持原生编译改造
- 默认支持的数据库由sqlite改为h2
@@ -40,6 +40,9 @@
- 配置文件做了较大调整,请参照官网使用须知中的`服务端配置``客户端配置`进行更新
## 运行示例
#### 本地原生启动截图
<img src="./run1.png" width="100%"/>
#### 管理后台首页
<img src="./home.png" width="100%"/>
Binary file not shown.

After

Width:  |  Height:  |  Size: 2.3 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 458 KiB

+86
View File
@@ -0,0 +1,86 @@
# 从Neutrino-Proxy(中微子代理)到Solon Native
## Neutrino-Proxy(中微子代理)是啥
#### 项目简介
- [中微子代理(neutrino-proxy)](https://gitee.com/asgc/neutrino-proxy) 是一款基于netty的内网穿透神器。该项目采用最为宽松的MIT协议,因此您可以对它进行复制、修改、传播并用于任何个人或商业行为。
- 市面上基于内网穿透的常见产品有:花生壳、TeamView、cpolar等。
- 常见的使用场景:
- 本地开发调试第三方回调
- 本地开发异地接口连调
- 远程登录内网windows机器
- 将本地服务映射到外网,用于演示
- Gitee仓库:https://gitee.com/dromara/neutrino-proxy
- Github仓库:https://github.com/dromara/neutrino-proxy
- 官网地址1: https://neutrino-proxy.dromara.org
- 官网地址2: https://dromara.gitee.io/neutrino-proxy
#### 主要特点:
- 1、流量监控:首页图表、报表管理多维度流量监控。全方位掌握实时、历史代理数据。
- 2、用户/License:支持多用户、多客户端使用。后台禁用实时生效。
- 3、端口池:对外端口统一管理,支持用户、License独占端口。
- 4、端口映射:新增、编辑、删除、禁用实时生效。
- 5、Docker:服务端/客户端支持Docker一键部署。
- 6、SSL证书:隧道通信支持SSL加密,保护您的数据安全。
- 7、域名映射:支持绑定子域名,方便本地调试三方回调
- 8、多种协议:支持代理TCP、HTTP、HTTPS、UDP协议
- 9、原生部署:支持编译为原生可执行文件,更低部署门槛、更少内存占用
- 10、采用最为宽松的MIT协议,免去你的后顾之忧
## 为什么开发Neutrino-Proxy(中微子代理)
2022年4月份左右,因工作原因需要用到内网穿透。此前一段时间使用的`coplar`,由于公司担心带来安全隐患,
因此决定自己研究一下这一块。
对于常年写业务代码的一介码农来说,内网穿透就是一个黑盒。为了打开这个黑盒,我开始到处找相关的开源项目,其中包括lanproxy、ngrok、nps、frp等。
经过一翻努力,2022年6月份,实现了中微子代理1.0.0。此版本纯粹为了练手, 所以是基于自己手写的一套底层框架(包含Ioc、Aop、SqlMaper(简易版本的mybatis)、xxljob等)
实现了客户端/服务端+纯配置文件版本的TCP代理。
千里之行,始于足下。1.0.0版本发布后,经过不断的迭代,如今2.0.0版本终于和大家见面了。
## 为什么选择Solon
中微子1.0.0版本发布之后,大约7~8个月的时间,进行了大量的更新,主要围绕在底层基础框架、
管理后台这一块。
此时中微子陆陆续续开始有了一些用户,开始迫切的需要加快代理相关功能的迭代进度。而此时自己手写
的底层框架成为了最大的掣肘,单单底层框架各种细节优化、测试、参考借鉴其他框架源码这些就足以耗光
我为数不多的业余时间,更别提在这个尚不成熟的框架上开发代理功能了。任何一次底层的优化调整,可能带来的
是上层代理功能的大量重构。
于是,我开始搜寻其它替代框架。因日常工作一直都在用Spring体系,我始终相信多种技术两相印证之后学到的东西更为深刻,所以自己的开源项目始终将Spring体系作为优先级最低
的选项。最终一个或偶然、或必然的机会,我了解到了Solon。
经过对Solon项目源码、官网文档、项目更新频率、生态完善度的深入了解,最终决定选择Solon作为中微子代理的底层框架。
2023年3月12日,中微子代理1.7.0版本发布,开始正式基于Solon框架。
2023年10月30日,中微子代理2.0.0版本发布,基于Solon Native实现原生部署。
## Solon简介
#### 项目简介
- Solon是一个全新的java生态体系,给人带来一种与众不同的开发体验,让你能更快的构建自己的应用、更小的打包产出、更快的启动速度。
- Gitee仓库:https://gitee.com/noear/solon
- Github仓库:https://github.com/noear/solon
- 官网地址:https://solon.noear.org/
#### 主要特性
> 启动快 5 ~ 10 倍;qps 高 2~ 3 倍;运行时内存节省 1/3 ~ 1/2;打包可以缩到 1/2 ~ 1/10
- 克制、简洁、高效、开放、生态
- 支持 JDK8、JDK11、JDK17、JDK21
- Http、WebSocket、Socket 三种信号统一的开发体验(俗称:三源合一)
- 支持“注解”与“手动”两种模式,按需自由操控
- Not Servlet,可以适配任何基础通讯框架(最小 0.3m 运行rpc架构)
- 独特的 IOC/AOP 容器设计。不会因为插件变多而启动变很慢
- 支持 Web、Data、Job、Remoting、Cloud 等任何开发场景
- 兼顾 Handler + Context 和 Listener + Message 两种架构模式
- 强调插件式扩展,可扩展可切换;适应不同的应用场景
- 支持 GraalVm Native Image 打包
- 允许业务插件“热插”、“热拔”、“热管理”
## 最后说点什么
开源实属不易,开源国产生态型基础框架更是举步维艰。不仅需要长时间、持续、稳定的投入迭代、测试、文档撰写、bug修复、发版、推广,
还经常需要面对来自四面八方汹涌如潮的质疑。
时光无言,它磨灭了一切、也证明着一切。
一千八百多个日日夜夜、五年的风雨兼程,Solon生态已经初具规模,社区汇聚了一大批开源爱好者。
大鹏一日通风起,扶摇直上九万里。我相信国产开源在大家的努力下,一定会越来越好!
@@ -0,0 +1,88 @@
# 客户端与服务器端采用不加密、SM2+AES加密、SSL加密方式进行的性能测试比较
* 本测试不作为性能测试参考,仅作为三种数据加密方式的性能比较使用
* 本测试使用的操作系统为windows10,
* 本测试使用的测试环境配置:内存:16G,CPU:i716核
## 1、测试程序准备情况
* 将程序分别打包为`server``client``jar`包,在本地运行一个`server`
* 拷贝三个客户端配置文件,配置文件名称为`app.yml``app-sm2-aes.yml``app-ssl.yml`,并修改相应配置,适配不加密、SM2+AES加密和SSL加密
## 2、测试思路和实现
1)准备1KB、10KB、20KB、50KB、100KB、1MB、2MB、5MB、10MB、20MB、100MB、500MB的文件
2)使用Nodejs实现的anywhere工具,在本地运行简单http服务
3)在server端生成3个licenseKey,分别对应不加密、SM2+AES加密和SSL加密通道,端口分别为9101,9102和9103,并同时映射到anywhere的8000端口
4)使用Hutool里的HttpUtil工具包,对每个文件进行下载,记录下载使用时间,重复执行10次
## 3、测试结果
序号| 加密方式 | 文件大小 |响应时间(ms)
---|---|---|---
1| 不加密 | 1KB |4
2| SM2+AES | 1KB |21
3| SSL | 1KB |67
4| 不加密 | 10KB |3
5| SM2+AES | 10KB |7
6| SSL | 10KB |4
7| 不加密 | 20KB |4
8| SM2+AES | 20KB |6
9| SSL | 20KB |5
10| 不加密 | 50KB |4
11| SM2+AES | 50KB |7
12| SSL | 50KB |6
13| 不加密 | 100KB |6
14| SM2+AES | 100KB |8
15| SSL | 100KB |6
16| 不加密 | 1MB |19
17| SM2+AES | 1MB |30
18| SSL | 1MB |19
19| 不加密 | 2MB |21
20| SM2+AES | 2MB |40
21| SSL | 2MB |24
22| 不加密 | 5MB |31
23| SM2+AES | 5MB |51
24| SSL | 5MB |36
25| 不加密 | 10MB |44
26| SM2+AES | 10MB |85
27| SSL | 10MB |47
28| 不加密 | 20MB |63
29| SM2+AES | 20MB |139
30| SSL | 20MB |92
31| 不加密 | 100MB |323
32| SM2+AES | 100MB |590
33| SSL | 100MB |322
34| 不加密 | 500MB |1414
35| SM2+AES | 500MB |2797
36| SSL | 500MB |1561
## 4、测试结论
从测试结果可以看出,SSL加密的方式在大部分情况下比SM2+AES的加密方式效率高。
## 5、测试使用的代码
```java
public static void main(String[] args) {
int serialNumber = 1;
int[] ports = new int[]{9101, 9102, 9103};
Map<Integer, String> portMap = new HashMap<>();
portMap.put(9101, "不加密");
portMap.put(9102, "SM2+AES");
portMap.put(9103, "SSL");
HttpUtil.downloadBytes("http://127.0.0.1:9101/1KB"); // 使用不加密通道做一下测试,避免初始化时耗时过高
String[] fileNames = "1KB,10KB,20KB,50KB,100KB,1MB,2MB,5MB,10MB,20MB,100MB,500MB".split(",");
for (String fileName : fileNames) {
for (int port : ports) {
String url = String.format("http://127.0.0.1:%s/%s", port, fileName);
long startTime = System.currentTimeMillis();
HttpUtil.downloadBytes(url);
long endTime = System.currentTimeMillis();
long resTimeMs = endTime - startTime;
String record = String.format("%s|%s|%s|%s", serialNumber++, portMap.get(port), fileName, resTimeMs);
System.out.println(record);
}
}
}
```
+1 -1
View File
@@ -1,5 +1,5 @@
module.exports = {
NODE_ENV: '"production"',
ENV_CONFIG: '"prod"',
BASE_API: '"https://api-prod"'
BASE_API: '""'
}
+1 -1
View File
@@ -70,7 +70,7 @@
"friendly-errors-webpack-plugin": "1.6.1",
"html-webpack-plugin": "2.30.1",
"node-notifier": "5.1.2",
"node-sass": "^4.7.2",
"node-sass": "^9.0.0",
"optimize-css-assets-webpack-plugin": "3.2.0",
"ora": "1.3.0",
"portfinder": "1.0.13",
+8 -5
View File
@@ -1,12 +1,15 @@
FROM openjdk:17-jdk-alpine
FROM openjdk:21-jdk-oracle
#同步时间
RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories && \
apk update && apk add wget unzip vim && apk add -U tzdata && \
ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime && echo 'Asia/Shanghai' >/etc/timezone
#RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories && \
# apk update && apk add wget unzip vim && apk add -U tzdata && \
# ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime && echo 'Asia/Shanghai' >/etc/timezone
# 设置时区为北京时间
ENV TZ=Asia/Shanghai
RUN ln -snf /usr/share/zoneinfo/$TZ /etc/localtime && echo $TZ > /etc/timezone
RUN mkdir -p /root/neutrino-proxy/config
WORKDIR /root/neutrino-proxy
COPY ./target/neutrino-proxy-client.jar /root/neutrino-proxy/neutrino-proxy-client.jar
COPY ./src/main/resources/app.yml /root/neutrino-proxy/config
COPY ./src/main/resources/app-copy.yml /root/neutrino-proxy/config/app.yml
#VOLUME ["/root/neutrino-proxy"]
ENTRYPOINT ["java","-jar","neutrino-proxy-client.jar","config=./config/app.yml"]
+7
View File
@@ -28,6 +28,13 @@
<build>
<finalName>${project.artifactId}</finalName>
<resources>
<resource>
<directory>src/main/resources</directory>
<filtering>true</filtering>
<includes>
<include>*.yml</include>
</includes>
</resource>
<resource>
<directory>${project.basedir}/src/main/resources</directory>
<filtering>false</filtering>
@@ -24,6 +24,7 @@ public class ProxyClient {
setAlias("neutrino.proxy.tunnel.server-ip", "serverIp");
setAlias("neutrino.proxy.tunnel.server-port", "serverPort");
setAlias("neutrino.proxy.tunnel.sm2-encrypt-enable", "sm2EncryptEnable");
setAlias("neutrino.proxy.tunnel.ssl-enable", "sslEnable");
setAlias("neutrino.proxy.tunnel.jks-path", "jksPath");
setAlias("neutrino.proxy.tunnel.key-store-password", "keyStorePassword");
@@ -37,6 +37,7 @@ public class ProxyConfig {
private String jksPath;
private String serverIp;
private Integer serverPort;
private Boolean sm2EncryptEnable;
private Boolean sslEnable;
private Integer obtainLicenseInterval;
private String licenseKey;
@@ -1,6 +1,7 @@
package org.dromara.neutrinoproxy.client.handler;
import io.netty.channel.ChannelHandlerContext;
import io.netty.util.Attribute;
import lombok.extern.slf4j.Slf4j;
import org.dromara.neutrinoproxy.client.config.ProxyConfig;
import org.dromara.neutrinoproxy.core.Constants;
@@ -8,6 +9,7 @@ import org.dromara.neutrinoproxy.core.ExceptionEnum;
import org.dromara.neutrinoproxy.core.ProxyMessage;
import org.dromara.neutrinoproxy.core.ProxyMessageHandler;
import org.dromara.neutrinoproxy.core.dispatcher.Match;
import org.dromara.neutrinoproxy.core.util.EncryptUtil;
import org.noear.snack.ONode;
import org.noear.solon.Solon;
import org.noear.solon.annotation.Component;
@@ -29,7 +31,7 @@ public class ProxyMessageAuthHandler implements ProxyMessageHandler {
String info = proxyMessage.getInfo();
ONode load = ONode.load(info);
Integer code = load.get("code").getInt();
log.info("Auth result:{}", info);
log.info("Auth result: {}", load.get("msg").getString());
if (ExceptionEnum.AUTH_FAILED.getCode().equals(code)) {
// 客户端认证失败,直接停止服务
log.info("client auth failed , client stop.");
@@ -42,5 +44,26 @@ public class ProxyMessageAuthHandler implements ProxyMessageHandler {
){
context.channel().close();
}
// 是否进行通道加密
if (!proxyConfig.getTunnel().getSm2EncryptEnable()) {
return;
}
// 默认设置为非安全链路,需要服务端确认后,再设置为安全链路
Attribute<Boolean> booleanAttribute = context.attr(Constants.IS_SECURITY);
booleanAttribute.set(false);
// 获取认证成功的后的公钥信息,并生成随机密码,加密发到服务端确认
String publicKey = load.get("publicKey").getString();
byte[] secureKey = EncryptUtil.generateAesKey();
// 存储密码
Attribute<byte[]> secureKeyAttr = context.attr(Constants.SECURE_KEY);
secureKeyAttr.set(secureKey);
// 使用SM2算法对密钥进行加密并发送到服务端
byte[] encryptSecureKey = EncryptUtil.encryptBySm2(publicKey, secureKey);
context.writeAndFlush(ProxyMessage.buildSecureKeyMessage(encryptSecureKey));
context.flush();
}
}
@@ -56,12 +56,15 @@ public class ProxyMessageConnectHandler implements ProxyMessageHandler {
channel.attr(Constants.NEXT_CHANNEL).set(realServerChannel);
realServerChannel.attr(Constants.NEXT_CHANNEL).set(channel);
// 远程绑定
// 通知服务端进行远程绑定,此绑定信息不加密,该条消息为身份标识
channel.writeAndFlush(ProxyMessage.buildConnectMessage(visitorId + "@" + proxyConfig.getTunnel().getLicenseKey()));
realServerChannel.config().setOption(ChannelOption.AUTO_READ, true);
ProxyUtil.addRealServerChannel(visitorId, realServerChannel);
ProxyUtil.setRealServerChannelVisitorId(realServerChannel, visitorId);
// 连接信息发送后,将该通道设置为加密
ProxyUtil.setChannelSecurity(channel);
}
@Override
@@ -0,0 +1,49 @@
package org.dromara.neutrinoproxy.client.handler;
import io.netty.channel.ChannelHandlerContext;
import io.netty.util.Attribute;
import lombok.extern.slf4j.Slf4j;
import org.dromara.neutrinoproxy.client.config.ProxyConfig;
import org.dromara.neutrinoproxy.client.util.ProxyUtil;
import org.dromara.neutrinoproxy.core.Constants;
import org.dromara.neutrinoproxy.core.ProxyMessage;
import org.dromara.neutrinoproxy.core.ProxyMessageHandler;
import org.dromara.neutrinoproxy.core.dispatcher.Match;
import org.dromara.neutrinoproxy.core.util.EncryptUtil;
import org.noear.solon.annotation.Component;
import org.noear.solon.annotation.Inject;
@Slf4j
@Match(type = Constants.ProxyDataTypeName.SECURE_KEY)
@Component
public class ProxyMessageSecureKeyHandler implements ProxyMessageHandler {
@Inject
private ProxyConfig proxyConfig;
@Override
public void handle(ChannelHandlerContext ctx, ProxyMessage proxyMessage) {
if (!proxyConfig.getTunnel().getSm2EncryptEnable()) {
return;
}
log.info("收到服务端的加密确认");
Attribute<byte[]> secureKeyAttr = ctx.attr(Constants.SECURE_KEY);
byte[] secureKey = secureKeyAttr.get();
byte[] data = proxyMessage.getData();
byte[] decryptedData = EncryptUtil.decryptByAes(secureKey, data);
String m = new String(decryptedData);
if ("ok".equals(m)) {
// 设置当前cmd通道为安全,之后使用该通道传输的消息均会加密
Attribute<Boolean> booleanAttribute = ctx.attr(Constants.IS_SECURITY);
booleanAttribute.set(true);
// 全局存储密钥
ProxyUtil.setSecureKey(secureKey);
log.info("Encrypted link established successfully");
} else {
ctx.channel().close();
}
}
}
@@ -46,6 +46,9 @@ public class UdpProxyMessageConnectHandler implements ProxyMessageHandler {
.setTargetIp(udpBaseInfo.getTargetIp())
.setTargetPort(udpBaseInfo.getTargetPort())
).setData(proxyConfig.getTunnel().getLicenseKey().getBytes()));
// connect类型的消息不加密,用于标识身份,发送标识消息后,再将通道设置加密标识
ProxyUtil.setChannelSecurity(channel);
}
@Override
@@ -72,6 +72,8 @@ public class ProxyUtil {
private static String clientId;
private static final String CLIENT_ID_FILE = ".NEUTRINO_PROXY_CLIENT_ID";
private static byte[] secureKey = null;
public static void borrowTcpProxyChanel(Bootstrap tcpProxyTunnelBootstrap, final ProxyChannelBorrowListener borrowListener) {
Channel channel = tcpProxyChannelPool.poll();
if (null != channel) {
@@ -89,6 +91,10 @@ public class ProxyUtil {
}
public static void returnTcpProxyChanel(Channel proxyChanel) {
if (proxyChanel != null) {
proxyChanel.attr(Constants.IS_SECURITY).set(null);
proxyChanel.attr(Constants.SECURE_KEY).set(null);
}
if (tcpProxyChannelPool.size() > MAX_POOL_SIZE) {
proxyChanel.close();
} else {
@@ -121,6 +127,10 @@ public class ProxyUtil {
}
public static void returnUdpProxyChanel(Channel proxyChanel) {
if (proxyChanel != null) {
proxyChanel.attr(Constants.IS_SECURITY).set(null);
proxyChanel.attr(Constants.SECURE_KEY).set(null);
}
if (udpProxyChannelPool.size() > MAX_POOL_SIZE) {
proxyChanel.close();
} else {
@@ -223,4 +233,16 @@ public class ProxyUtil {
return null;
}
public static void setSecureKey(byte[] key) {
secureKey = key;
}
public static void setChannelSecurity(Channel channel) {
if (null == secureKey) {
return;
}
channel.attr(Constants.IS_SECURITY).set(true);
channel.attr(Constants.SECURE_KEY).set(secureKey);
}
}
@@ -0,0 +1,41 @@
solon.logging.logger:
"root":
level: info
neutrino:
proxy:
tunnel:
# 线程池相关配置,用于技术调优,可忽略
thread-count: 50
# 隧道SSL证书配置
key-store-password: ${STORE_PASS:123456}
jks-path: ${JKS_PATH:classpath:/test.jks}
# 服务端IP
server-ip: ${SERVER_IP:localhost}
# 服务端端口(对应服务端app.yml中的tunnel.port、tunnel.ssl-port)
server-port: ${SERVER_PORT:9002}
# 是否启用SSL(注意:该配置必须和server-port对应上)
ssl-enable: ${SSL_ENABLE:true}
# 客户端连接唯一凭证
license-key: ${LICENSE_KEY:}
# 客户端唯一身份标识(可忽略,若不设置首次启动会自动生成)
client-id: ${CLIENT_ID:}
# 是否开启隧道传输报文日志(日志级别为debug时开启才有效)
transfer-log-enable: ${CLIENT_LOG:false}
# 是否开启心跳日志
heartbeat-log-enable: ${HEARTBEAT_LOG:false}
# 重连设置
reconnection:
# 重连间隔(秒)
interval-seconds: 10
# 是否开启无限重连(未开启时,客户端license不合法会自动停止应用,开启了则不会,请谨慎开启)
unlimited: false
client:
udp:
# 线程池相关配置,用于技术调优,可忽略
boss-thread-count: 5
work-thread-count: 20
# udp傀儡端口范围
puppet-port-range: 10000-10500
# 是否开启隧道传输报文日志(日志级别为debug时开启才有效)
transfer-log-enable: ${CLIENT_LOG:false}
@@ -1,6 +1,9 @@
solon:
config:
add: ./app.yml
app:
name: neutrino-proxy-client
version: @revision@
# 日志级别
solon.logging.appender:
console:
@@ -13,13 +16,14 @@ solon.logging.appender:
solon.logging.logger:
"root":
level: info
neutrino:
application:
name: neutrino-proxy-client
proxy:
protocol:
max-frame-length: 2097152
max-frame-length: 1048576000
length-field-offset: 0
length-field-length: 4
initial-bytes-to-strip: 0
@@ -30,17 +34,18 @@ neutrino:
tunnel:
# 线程池相关配置,用于技术调优,可忽略
thread-count: 50
sm2-encrypt-enable: ${SM2_ENCRYPT_ENABLE:true}
# 隧道SSL证书配置
key-store-password: ${STORE_PASS:123456}
jks-path: ${JKS_PATH:classpath:/test.jks}
# 服务端IP
server-ip: ${SERVER_IP:localhost}
# 服务端端口(对应服务端app.yml中的tunnel.port、tunnel.ssl-port)
server-port: ${SERVER_PORT:9002}
server-port: ${SERVER_PORT:9000}
# 是否启用SSL(注意:该配置必须和server-port对应上)
ssl-enable: ${SSL_ENABLE:true}
ssl-enable: ${SSL_ENABLE:false}
# 客户端连接唯一凭证
license-key: ${LICENSE_KEY:}
license-key: ${LICENSE_KEY:b0a907332b474b25897c4dcb31fc7eb6}
# 客户端唯一身份标识(可忽略,若不设置首次启动会自动生成)
client-id: ${CLIENT_ID:}
# 是否开启隧道传输报文日志(日志级别为debug时开启才有效)
+9 -3
View File
@@ -24,16 +24,22 @@
<groupId>io.netty</groupId>
<artifactId>netty-all</artifactId>
</dependency>
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcprov-jdk15to18</artifactId>
</dependency>
<!--hutool -->
<dependency>
<groupId>cn.hutool</groupId>
<artifactId>hutool-core</artifactId>
<version>${hutool.version}</version>
</dependency>
<!--lombok-->
<dependency>
<groupId>org.projectlombok</groupId>
<artifactId>lombok</artifactId>
<groupId>cn.hutool</groupId>
<artifactId>hutool-crypto</artifactId>
<version>${hutool.version}</version>
</dependency>
</dependencies>
@@ -38,6 +38,12 @@ public interface Constants {
AttributeKey<String> VISITOR_ID = AttributeKey.newInstance("visitor_id");
AttributeKey<String> SECURE_PRIVATE_KEY = AttributeKey.newInstance("secure_private_key");
AttributeKey<byte[]> SECURE_KEY = AttributeKey.newInstance("secure_key");
AttributeKey<Boolean> IS_SECURITY = AttributeKey.newInstance("is_security");
AttributeKey<Integer> LICENSE_ID = AttributeKey.newInstance("license_id");
AttributeKey<String> TARGET_IP = AttributeKey.newInstance("targetIp");
@@ -57,6 +63,7 @@ public interface Constants {
interface ProxyDataTypeName {
String HEARTBEAT = "HEARTBEAT";
String SECURE_KEY = "SECURE_KEY";
String AUTH = "AUTH";
String CONNECT = "CONNECT";
String DISCONNECT = "DISCONNECT";
@@ -0,0 +1,31 @@
/**
* Copyright (c) 2022 aoshiguchen
*
* Permission is hereby granted, free of charge, to any person obtaining a copy
* of this software and associated documentation files (the "Software"), to deal
* in the Software without restriction, including without limitation the rights
* to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
* copies of the Software, and to permit persons to whom the Software is
* furnished to do so, subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
* SOFTWARE.
*/
package org.dromara.neutrinoproxy.core;
/**
* 存储公钥和私钥
* @param privateKey
* @param publicKey
*/
public record KeyPairRecord(String privateKey, String publicKey) {
}
@@ -47,7 +47,9 @@ public enum ProxyDataTypeEnum {
PORT_MAPPING_SYNC(0x07, Constants.ProxyDataTypeName.PORT_MAPPING_SYNC, "PORT_MAPPING_SYNC"),
UDP_CONNECT(0x08, Constants.ProxyDataTypeName.UDP_CONNECT,"UDP_CONNECT"),
UDP_DISCONNECT(0x09, Constants.ProxyDataTypeName.UDP_DISCONNECT,"UDP_DISCONNECT"),
UDP_TRANSFER(0x10, Constants.ProxyDataTypeName.UDP_TRANSFER,"UDP_TRANSFER");
UDP_TRANSFER(0x10, Constants.ProxyDataTypeName.UDP_TRANSFER,"UDP_TRANSFER"),
SECURE_KEY(0x11, Constants.ProxyDataTypeName.SECURE_KEY, "SECURE_KEY"),
;
private static Map<Integer,ProxyDataTypeEnum> cache = Stream.of(values()).collect(Collectors.toMap(ProxyDataTypeEnum::getType, Function.identity()));
private int type;
@@ -24,6 +24,7 @@ package org.dromara.neutrinoproxy.core;
import lombok.Data;
import lombok.experimental.Accessors;
import org.dromara.neutrinoproxy.core.util.EncryptUtil;
import org.noear.snack.ONode;
import java.util.Arrays;
@@ -79,6 +80,11 @@ public class ProxyMessage {
*/
public static final byte TYPE_UDP_TRANSFER = 0x10;
/**
* 安全密钥协商
*/
public static final byte TYPE_SECURE_KEY = 0x11;
/**
* 消息类型
*/
@@ -117,11 +123,12 @@ public class ProxyMessage {
.setInfo(info + "," + clientId);
}
public static ProxyMessage buildAuthResultMessage(Integer code, String msg, String licenseKey) {
public static ProxyMessage buildAuthResultMessage(Integer code, String msg, String licenseKey, String publicKey) {
ONode data = ONode.newObject();
data.set("code", code);
data.set("msg", msg);
data.set("licenseKey", licenseKey);
data.set("publicKey", publicKey);
return create().setType(TYPE_AUTH)
.setInfo(data.toJson());
}
@@ -136,6 +143,17 @@ public class ProxyMessage {
.setInfo(info);
}
public static ProxyMessage buildSecureKeyMessage(byte[] secureKey) {
return create().setType(TYPE_SECURE_KEY)
.setInfo(EncryptUtil.digestBySm3(secureKey))
.setData(secureKey);
}
public static ProxyMessage buildSecureKeyReturnMessage(byte[] content) {
return create().setType(TYPE_SECURE_KEY)
.setData(content);
}
public static ProxyMessage buildTransferMessage(String visitorId, byte[] data) {
return create().setType(TYPE_TRANSFER)
.setInfo(visitorId)
@@ -22,11 +22,18 @@
package org.dromara.neutrinoproxy.core;
import cn.hutool.core.util.HexUtil;
import io.netty.buffer.ByteBuf;
import io.netty.buffer.Unpooled;
import io.netty.channel.ChannelHandlerContext;
import io.netty.handler.codec.LengthFieldBasedFrameDecoder;
import io.netty.util.Attribute;
import lombok.extern.slf4j.Slf4j;
import org.dromara.neutrinoproxy.core.util.EncryptUtil;
import static org.dromara.neutrinoproxy.core.Constants.*;
@Slf4j
/**
*
* @author: aoshiguchen
@@ -70,28 +77,52 @@ public class ProxyMessageDecoder extends LengthFieldBasedFrameDecoder {
return null;
}
int frameLength = in.readInt();
if (in.readableBytes() < frameLength) {
return null;
Attribute<Boolean> booleanAttribute = ctx.attr(Constants.IS_SECURITY);
Boolean isSecurity = booleanAttribute.get();
ByteBuf buf;
// 考虑isSecurity为null的情况,null的情况也为false
if (isSecurity != null && isSecurity) {
int packageLength = in.readInt();
if (in.readableBytes() < packageLength) {
return null;
}
// 获取加密数据
byte[] encryptedBytes = new byte[packageLength];
in.readBytes(encryptedBytes);
in.release();
// 获取解密密钥
Attribute<byte[]> secureKeyAttr = ctx.attr(SECURE_KEY);
byte[] secureKey = secureKeyAttr.get();
// 解密
byte[] decryptedData = EncryptUtil.decryptByAes(secureKey, encryptedBytes);
buf = Unpooled.wrappedBuffer(decryptedData);
} else {
buf = in;
}
ProxyMessage proxyMessage = new ProxyMessage();
byte type = in.readByte();
long sn = in.readLong();
int frameLength = buf.readInt();
byte type = buf.readByte();
long sn = buf.readLong();
proxyMessage.setSerialNumber(sn);
proxyMessage.setType(type);
int infoLength = in.readInt();
int infoLength = buf.readInt();
byte[] infoBytes = new byte[infoLength];
in.readBytes(infoBytes);
buf.readBytes(infoBytes);
proxyMessage.setInfo(new String(infoBytes));
byte[] data = new byte[frameLength - TYPE_SIZE - SERIAL_NUMBER_SIZE - INFO_LENGTH_SIZE - infoLength];
in.readBytes(data);
buf.readBytes(data);
proxyMessage.setData(data);
in.release();
buf.release();
return proxyMessage;
}
@@ -22,9 +22,15 @@
package org.dromara.neutrinoproxy.core;
import cn.hutool.core.util.HexUtil;
import io.netty.buffer.ByteBuf;
import io.netty.buffer.Unpooled;
import io.netty.channel.ChannelHandlerContext;
import io.netty.handler.codec.MessageToByteEncoder;
import io.netty.util.Attribute;
import lombok.extern.slf4j.Slf4j;
import org.dromara.neutrinoproxy.core.util.EncryptUtil;
import static org.dromara.neutrinoproxy.core.Constants.*;
/**
@@ -32,6 +38,7 @@ import static org.dromara.neutrinoproxy.core.Constants.*;
* @author: aoshiguchen
* @date: 2022/6/16
*/
@Slf4j
public class ProxyMessageEncoder extends MessageToByteEncoder<ProxyMessage> {
public ProxyMessageEncoder() {
@@ -40,6 +47,7 @@ public class ProxyMessageEncoder extends MessageToByteEncoder<ProxyMessage> {
@Override
protected void encode(ChannelHandlerContext ctx, ProxyMessage msg, ByteBuf out) throws Exception {
int bodyLength = TYPE_SIZE + SERIAL_NUMBER_SIZE + INFO_LENGTH_SIZE;
byte[] infoBytes = null;
if (msg.getInfo() != null) {
@@ -51,21 +59,50 @@ public class ProxyMessageEncoder extends MessageToByteEncoder<ProxyMessage> {
bodyLength += msg.getData().length;
}
// write the total packet length but without length field's length.
out.writeInt(bodyLength);
Attribute<Boolean> booleanAttribute = ctx.attr(Constants.IS_SECURITY);
Boolean isSecurity = booleanAttribute.get();
out.writeByte(msg.getType());
out.writeLong(msg.getSerialNumber());
ByteBuf buf;
// 考虑isSecurity为null的情况,null的情况也为false
if (isSecurity != null && isSecurity) {
buf = Unpooled.directBuffer(bodyLength);
} else {
buf = out;
}
// write the total packet length but without length field's length.
buf.writeInt(bodyLength);
buf.writeByte(msg.getType());
buf.writeLong(msg.getSerialNumber());
if (infoBytes != null) {
out.writeInt(infoBytes.length);
out.writeBytes(infoBytes);
buf.writeInt(infoBytes.length);
buf.writeBytes(infoBytes);
} else {
out.writeInt(0x00);
buf.writeInt(0x00);
}
if (msg.getData() != null) {
out.writeBytes(msg.getData());
buf.writeBytes(msg.getData());
}
// 考虑isSecurity为null的情况,null的情况也为false
if (isSecurity != null && isSecurity) {
// 执行加密
byte[] data = new byte[buf.writerIndex()];
buf.readBytes(data);
// 获取加密密钥
Attribute<byte[]> secureKeyAttr = ctx.attr(SECURE_KEY);
byte[] secureKey = secureKeyAttr.get();
// 执行加密
byte[] encryptedData = EncryptUtil.encryptByAes(secureKey, data);
out.writeInt(encryptedData.length);
out.writeBytes(encryptedData);
buf.release();
}
}
}
@@ -25,6 +25,10 @@ public class NeutrinoCoreRuntimeNativeRegistrar implements RuntimeNativeRegistra
metadata.registerReflection(ProxyMessage.class, MemberCategory.DECLARED_FIELDS, MemberCategory.INVOKE_DECLARED_METHODS, MemberCategory.INVOKE_DECLARED_CONSTRUCTORS);
metadata.registerReflection(ProxyMessage.UdpBaseInfo.class, MemberCategory.DECLARED_FIELDS, MemberCategory.INVOKE_DECLARED_METHODS, MemberCategory.INVOKE_DECLARED_CONSTRUCTORS);
metadata.registerArg("--add-opens java.base/java.lang.invoke=ALL-UNNAMED --add-exports=java.base/jdk.internal.misc=ALL-UNNAMED -march=compatibility");
metadata.registerArg("-J--add-opens=java.base/java.lang.invoke=ALL-UNNAMED");
metadata.registerArg("-J--add-opens=java.base/java.nio=ALL-UNNAMED");
metadata.registerArg("-J--add-exports=java.base/jdk.internal.misc=ALL-UNNAMED");
metadata.registerArg("-march=compatibility");
}
}
@@ -0,0 +1,58 @@
package org.dromara.neutrinoproxy.core.util;
import cn.hutool.core.util.RandomUtil;
import javax.crypto.Cipher;
import javax.crypto.spec.SecretKeySpec;
import java.nio.charset.StandardCharsets;
import java.util.Base64;
import java.util.Random;
/**
* AES工具
*/
public class AesUtil {
public static byte[] generateKey() {
byte[] keyBytes = new byte[16];
Random random = RandomUtil.getRandom(true);
random.nextBytes(keyBytes);
return keyBytes;
}
/**
* AES解密
* @param decryptKey 秘钥,16位
* @param encryptBytes 密文
* @return 明文
* @throws Exception
*/
public static byte[] decrypt(byte[] decryptKey, byte[] encryptBytes) {
try{
Cipher cipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
cipher.init(Cipher.DECRYPT_MODE, new SecretKeySpec(decryptKey, "AES"));
return cipher.doFinal(encryptBytes);
} catch (Exception e) {
e.printStackTrace();
}
return null;
}
/**
* AES加密
* @param encryptKey 秘钥,必须为16个字符组成
* @param data 明文
* @return 密文
* @throws Exception
*/
public static byte[] encrypt(byte[] encryptKey, byte[] data) {
try {
Cipher cipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
cipher.init(Cipher.ENCRYPT_MODE, new SecretKeySpec(encryptKey, "AES"));
return cipher.doFinal(data);
} catch (Exception e) {
e.printStackTrace();
}
return null;
}
}
@@ -0,0 +1,150 @@
/**
* Copyright (c) 2022 aoshiguchen
*
* Permission is hereby granted, free of charge, to any person obtaining a copy
* of this software and associated documentation files (the "Software"), to deal
* in the Software without restriction, including without limitation the rights
* to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
* copies of the Software, and to permit persons to whom the Software is
* furnished to do so, subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
* SOFTWARE.
*/
package org.dromara.neutrinoproxy.core.util;
import cn.hutool.core.util.HexUtil;
import cn.hutool.crypto.SecureUtil;
import cn.hutool.crypto.SmUtil;
import cn.hutool.crypto.symmetric.SymmetricAlgorithm;
import cn.hutool.crypto.symmetric.SymmetricCrypto;
import org.bouncycastle.jcajce.provider.asymmetric.ec.BCECPrivateKey;
import org.bouncycastle.jcajce.provider.asymmetric.ec.BCECPublicKey;
import org.bouncycastle.util.encoders.Hex;
import org.dromara.neutrinoproxy.core.KeyPairRecord;
import javax.crypto.SecretKey;
import java.security.KeyPair;
import java.security.PrivateKey;
import java.security.PublicKey;
/**
* 国密算法加解密工具
* @author: az
* @date: 2023/11/07
*/
public class EncryptUtil {
/**
* 生成SM2密钥对
* @return
*/
public static KeyPairRecord generateSm2KeyPair() {
String privateKeyHex = null;
String publicKeyHex = null;
KeyPair keyPair = Sm2Util.createECKeyPair();
PrivateKey privateKey = keyPair.getPrivate();
if (privateKey instanceof BCECPrivateKey) {
//获取32字节十六进制私钥串
privateKeyHex = ((BCECPrivateKey) privateKey).getD().toString(16);
}
PublicKey publicKey = keyPair.getPublic();
if (publicKey instanceof BCECPublicKey) {
//获取65字节非压缩缩的十六进制公钥串(0x04)
publicKeyHex = Hex.toHexString(((BCECPublicKey) publicKey).getQ().getEncoded(false));
}
return new KeyPairRecord(privateKeyHex, publicKeyHex);
}
/**
* 使用SM2算法对数据进行加密
* @param publicKey 加密所需的公钥
* @param data 需要加密的数据
* @return 加密后的字节数组
*/
public static byte[] encryptBySm2(String publicKey, byte[] data) {
return Sm2Util.encrypt(publicKey, data);
}
/**
* 使用SM2算法对数据进行解密
* @param privateKey 解密所需私钥
* @param data 需要解密的数据
* @return 解密后的字节数组
*/
public static byte[] decryptBySm2(String privateKey, byte[] data) {
return Sm2Util.decrypt(privateKey, data);
}
public static byte[] generateSm4Key() {
return SecureUtil.generateKey("AES", 128).getEncoded();
}
/**
* 使用SM4算法加密数据
* @param key 密钥
* @param data 待加密的数据
* @return 已加密的数据
*/
public static byte[] encryptBySm4(byte[] key, byte[] data) {
return SmUtil.sm4(key).encrypt(data);
}
/**
* 使用SM4算法解密数据
* @param key 密钥
* @param encryptedData 已加密数据
* @return 解密后的数据
*/
public static byte[] decryptBySm4(byte[] key, byte[] encryptedData) {
return SmUtil.sm4(key).decrypt(encryptedData);
}
public static byte[] generateAesKey() {
return AesUtil.generateKey();
}
/**
* 使用AES算法加密数据
* @param key 密钥
* @param data 被加密数据
* @return 加密后的数据
*/
public static byte[] encryptByAes(byte[] key, byte[] data) {
return AesUtil.encrypt(key, data);
}
/**
* 使用AES法解密数据
* @param key 密钥
* @param encryptedData 已加密数据
* @return 解密后的数据
*/
public static byte[] decryptByAes(byte[] key, byte[] encryptedData) {
return AesUtil.decrypt(key, encryptedData);
}
/**
* 使用SM3算法对内容生成摘要
* @param data
* @return
*/
public static String digestBySm3(byte[] data) {
return SmUtil.sm3().digestHex(data);
}
}
@@ -0,0 +1,19 @@
package org.dromara.neutrinoproxy.core.util;
import org.noear.solon.Solon;
/**
* @author songyinyin
* @since 2023/10/31 11:48
*/
public class NeutrinoProxyVersion {
/**
* 获取 NeutrinoProxy 版本号
*/
public static String getVersion() {
return Solon.cfg().get("solon.app.version");
}
}
@@ -0,0 +1,216 @@
package org.dromara.neutrinoproxy.core.util;
import org.bouncycastle.asn1.gm.GMNamedCurves;
import org.bouncycastle.asn1.x9.X9ECParameters;
import org.bouncycastle.crypto.engines.SM2Engine;
import org.bouncycastle.crypto.params.ECDomainParameters;
import org.bouncycastle.crypto.params.ECPrivateKeyParameters;
import org.bouncycastle.crypto.params.ECPublicKeyParameters;
import org.bouncycastle.crypto.params.ParametersWithRandom;
import org.bouncycastle.jcajce.provider.asymmetric.ec.BCECPrivateKey;
import org.bouncycastle.jcajce.provider.asymmetric.ec.BCECPublicKey;
import org.bouncycastle.jce.provider.BouncyCastleProvider;
import org.bouncycastle.jce.spec.ECParameterSpec;
import org.bouncycastle.jce.spec.ECPrivateKeySpec;
import org.bouncycastle.jce.spec.ECPublicKeySpec;
import java.math.BigInteger;
import java.security.KeyPair;
import java.security.KeyPairGenerator;
import java.security.SecureRandom;
import java.security.spec.ECGenParameterSpec;
/**
* @ClassName SM2Utils
* @Description SM2算法工具类
*/
public class Sm2Util {
/**
* @Description 生成秘钥对
* @return KeyPair
*/
public static KeyPair createECKeyPair() {
//使用标准名称创建EC参数生成的参数规范
final ECGenParameterSpec sm2Spec = new ECGenParameterSpec("sm2p256v1");
// 获取一个椭圆曲线类型的密钥对生成器
final KeyPairGenerator kpg;
try {
kpg = KeyPairGenerator.getInstance("EC", new BouncyCastleProvider());
// 使用SM2算法域参数集初始化密钥生成器(默认使用以最高优先级安装的提供者的 SecureRandom 的实现作为随机源)
// kpg.initialize(sm2Spec);
// 使用SM2的算法域参数集和指定的随机源初始化密钥生成器
kpg.initialize(sm2Spec, new SecureRandom());
// 通过密钥生成器生成密钥对
return kpg.generateKeyPair();
} catch (Exception e) {
e.printStackTrace();
return null;
}
}
/**
* @Description 公钥加密
* @param publicKeyHex SM2十六进制公钥
* @param data 明文数据
* @return String
*/
public static byte[] encrypt(String publicKeyHex, byte[] data) {
return encrypt(getECPublicKeyByPublicKeyHex(publicKeyHex), data, 1);
}
/**
* @Description 公钥加密
* @param publicKey SM2公钥
* @param data 明文数据
* @param modeType 加密模式
* @return String
*/
public static byte[] encrypt(BCECPublicKey publicKey, byte[] data, int modeType) {
//加密模式
SM2Engine.Mode mode = SM2Engine.Mode.C1C3C2;
if (modeType != 1) {
mode = SM2Engine.Mode.C1C2C3;
}
//通过公钥对象获取公钥的基本域参数。
ECParameterSpec ecParameterSpec = publicKey.getParameters();
ECDomainParameters ecDomainParameters = new ECDomainParameters(ecParameterSpec.getCurve(),
ecParameterSpec.getG(), ecParameterSpec.getN());
//通过公钥值和公钥基本参数创建公钥参数对象
ECPublicKeyParameters ecPublicKeyParameters = new ECPublicKeyParameters(publicKey.getQ(), ecDomainParameters);
//根据加密模式实例化SM2公钥加密引擎
SM2Engine sm2Engine = new SM2Engine(mode);
//初始化加密引擎
sm2Engine.init(true, new ParametersWithRandom(ecPublicKeyParameters, new SecureRandom()));
byte[] arrayOfBytes = null;
try {
//将明文字符串转换为指定编码的字节串
//通过加密引擎对字节数串行加密
arrayOfBytes = sm2Engine.processBlock(data, 0, data.length);
} catch (Exception e) {
System.out.println("SM2加密时出现异常:" + e.getMessage());
e.printStackTrace();
}
//将加密后的字节串转换为十六进制字符串
return arrayOfBytes;
}
/**
* @Description 私钥解密
* @param privateKeyHex SM2十六进制私钥
* @param cipherData 密文数据
* @return String
*/
public static byte[] decrypt(String privateKeyHex, byte[] cipherData) {
return decrypt(getBCECPrivateKeyByPrivateKeyHex(privateKeyHex), cipherData, 1);
}
/**
* @Description 私钥解密
* @param privateKey SM私钥
* @param cipherDataByte 密文数据
* @param modeType 解密模式
* @return
*/
public static byte[] decrypt(BCECPrivateKey privateKey, byte[] cipherDataByte, int modeType) {
//解密模式
SM2Engine.Mode mode = SM2Engine.Mode.C1C3C2;
if (modeType != 1)
mode = SM2Engine.Mode.C1C2C3;
//通过私钥对象获取私钥的基本域参数。
ECParameterSpec ecParameterSpec = privateKey.getParameters();
ECDomainParameters ecDomainParameters = new ECDomainParameters(ecParameterSpec.getCurve(),
ecParameterSpec.getG(), ecParameterSpec.getN());
//通过私钥值和私钥钥基本参数创建私钥参数对象
ECPrivateKeyParameters ecPrivateKeyParameters = new ECPrivateKeyParameters(privateKey.getD(),
ecDomainParameters);
//通过解密模式创建解密引擎并初始化
SM2Engine sm2Engine = new SM2Engine(mode);
sm2Engine.init(false, ecPrivateKeyParameters);
try {
//通过解密引擎对密文字节串进行解密
return sm2Engine.processBlock(cipherDataByte, 0, cipherDataByte.length);
} catch (Exception e) {
System.out.println("SM2解密时出现异常" + e.getMessage());
}
return new byte[0];
}
//椭圆曲线ECParameters ASN.1 结构
private static X9ECParameters x9ECParameters = GMNamedCurves.getByName("sm2p256v1");
//椭圆曲线公钥或私钥的基本域参数。
private static ECParameterSpec ecDomainParameters = new ECParameterSpec(x9ECParameters.getCurve(), x9ECParameters.getG(), x9ECParameters.getN());
/**
* @Description 公钥字符串转换为 BCECPublicKey 公钥对象
* @param pubKeyHex 64字节十六进制公钥字符串(如果公钥字符串为65字节首个字节为0x04:表示该公钥为非压缩格式,操作时需要删除)
* @return BCECPublicKey SM2公钥对象
*/
public static BCECPublicKey getECPublicKeyByPublicKeyHex(String pubKeyHex) {
//截取64字节有效的SM2公钥(如果公钥首个字节为0x04)
if (pubKeyHex.length() > 128) {
pubKeyHex = pubKeyHex.substring(pubKeyHex.length() - 128);
}
//将公钥拆分为x,y分量(各32字节)
String stringX = pubKeyHex.substring(0, 64);
String stringY = pubKeyHex.substring(stringX.length());
//将公钥x、y分量转换为BigInteger类型
BigInteger x = new BigInteger(stringX, 16);
BigInteger y = new BigInteger(stringY, 16);
//通过公钥x、y分量创建椭圆曲线公钥规范
ECPublicKeySpec ecPublicKeySpec = new ECPublicKeySpec(x9ECParameters.getCurve().createPoint(x, y), ecDomainParameters);
//通过椭圆曲线公钥规范,创建出椭圆曲线公钥对象(可用于SM2加密及验签)
return new BCECPublicKey("EC", ecPublicKeySpec, BouncyCastleProvider.CONFIGURATION);
}
/**
* @Description 私钥字符串转换为 BCECPrivateKey 私钥对象
* @param privateKeyHex 32字节十六进制私钥字符串
* @return BCECPrivateKey SM2私钥对象
*/
public static BCECPrivateKey getBCECPrivateKeyByPrivateKeyHex(String privateKeyHex) {
//将十六进制私钥字符串转换为BigInteger对象
BigInteger d = new BigInteger(privateKeyHex, 16);
//通过私钥和私钥域参数集创建椭圆曲线私钥规范
ECPrivateKeySpec ecPrivateKeySpec = new ECPrivateKeySpec(d, ecDomainParameters);
//通过椭圆曲线私钥规范,创建出椭圆曲线私钥对象(可用于SM2解密和签名)
return new BCECPrivateKey("EC", ecPrivateKeySpec, BouncyCastleProvider.CONFIGURATION);
}
public static void main(String[] args) {
/*String publicKeyHex = null;
String privateKeyHex = null;*/
/*KeyPair keyPair = createECKeyPair();
PublicKey publicKey = keyPair.getPublic();
if (publicKey instanceof BCECPublicKey) {
//获取65字节非压缩缩的十六进制公钥串(0x04)
publicKeyHex = Hex.toHexString(((BCECPublicKey) publicKey).getQ().getEncoded(false));
System.out.println("---->SM2公钥:" + publicKeyHex);
}
PrivateKey privateKey = keyPair.getPrivate();
if (privateKey instanceof BCECPrivateKey) {
//获取32字节十六进制私钥串
privateKeyHex = ((BCECPrivateKey) privateKey).getD().toString(16);
System.out.println("---->SM2私钥:" + privateKeyHex);
}*/
/**
* 公钥加密
*/
// String data = "az";
//将十六进制公钥串转换为 BCECPublicKey 公钥对象
/*String encryptData = encrypt(publicKeyHex, data);
System.out.println("---->加密结果:" + encryptData);*/
/**
* 私钥解密
*/
//将十六进制私钥串转换为 BCECPrivateKey 私钥对象
/*data = decrypt("xx", "xx");
System.out.println("---->解密结果:" + data);*/
}
}
+8 -5
View File
@@ -1,12 +1,15 @@
FROM openjdk:17-jdk-alpine
FROM openjdk:21-jdk-oracle
#同步时间
RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories && \
apk update && apk add wget unzip vim && apk add -U tzdata && \
ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime && echo 'Asia/Shanghai' >/etc/timezone
#RUN sed -i 's/dl-cdn.alpinelinux.org/mirrors.aliyun.com/g' /etc/apk/repositories && \
# apk update && apk add wget unzip vim && apk add -U tzdata && \
# ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime && echo 'Asia/Shanghai' >/etc/timezone
# 设置时区为北京时间
ENV TZ=Asia/Shanghai
RUN ln -snf /usr/share/zoneinfo/$TZ /etc/localtime && echo $TZ > /etc/timezone
RUN mkdir -p /root/neutrino-proxy/config
WORKDIR /root/neutrino-proxy
COPY ./target/neutrino-proxy-server.jar /root/neutrino-proxy/neutrino-proxy-server.jar
COPY ./src/main/resources/app.yml /root/neutrino-proxy/config
COPY ./src/main/resources/app-copy.yml /root/neutrino-proxy/config/app.yml
#VOLUME ["/root/neutrino-proxy"]
ENTRYPOINT ["java","-jar","neutrino-proxy-server.jar","config=./config/app.yml"]
+7
View File
@@ -61,6 +61,13 @@
<build>
<finalName>${project.artifactId}</finalName>
<resources>
<resource>
<directory>src/main/resources</directory>
<filtering>true</filtering>
<includes>
<include>*.yml</include>
</includes>
</resource>
<resource>
<directory>${project.basedir}/src/main/resources</directory>
<filtering>false</filtering>
@@ -23,9 +23,10 @@
package org.dromara.neutrinoproxy.server.proxy.handler;
import cn.hutool.core.util.StrUtil;
import org.dromara.neutrinoproxy.core.*;
import io.netty.util.Attribute;
import org.dromara.neutrinoproxy.core.*;
import org.dromara.neutrinoproxy.core.dispatcher.Match;
import org.dromara.neutrinoproxy.core.util.EncryptUtil;
import org.dromara.neutrinoproxy.server.base.proxy.ProxyConfig;
import org.dromara.neutrinoproxy.server.constant.ClientConnectTypeEnum;
import org.dromara.neutrinoproxy.server.constant.EnableStatusEnum;
@@ -90,7 +91,7 @@ public class ProxyMessageAuthHandler implements ProxyMessageHandler {
if (StrUtil.isEmpty(licenseKey)) {
log.warn("[client connection] license cannot empty info:{} ", info);
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.AUTH_FAILED.getCode(), "license不能为空!", licenseKey));
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.AUTH_FAILED.getCode(), "license不能为空!", licenseKey, null));
ctx.channel().close();
clientConnectRecordService.add(new ClientConnectRecordDO()
.setIp(ip)
@@ -104,22 +105,22 @@ public class ProxyMessageAuthHandler implements ProxyMessageHandler {
}
LicenseDO licenseDO = licenseService.findByKey(licenseKey);
if (null == licenseDO) {
log.warn("[client connection] license notfound info:{} ", info);
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.AUTH_FAILED.getCode(), "license不存在!", licenseKey));
log.warn("[client connection] license not found info:{} ", info);
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.AUTH_FAILED.getCode(), "license不存在!", licenseKey, null));
ctx.channel().close();
clientConnectRecordService.add(new ClientConnectRecordDO()
.setIp(ip)
.setType(ClientConnectTypeEnum.CONNECT.getType())
.setMsg(licenseKey)
.setCode(SuccessCodeEnum.FAIL.getCode())
.setErr("license notfound!")
.setErr("license not found!")
.setCreateTime(now)
);
return;
}
if (EnableStatusEnum.DISABLE.getStatus().equals(licenseDO.getEnable())) {
log.warn("[client connection] the license disabled info:{} ", info);
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.AUTH_FAILED.getCode(), "the license disabled!", licenseKey));
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.AUTH_FAILED.getCode(), "the license disabled!", licenseKey, null));
ctx.channel().close();
clientConnectRecordService.add(new ClientConnectRecordDO()
.setIp(ip)
@@ -134,7 +135,7 @@ public class ProxyMessageAuthHandler implements ProxyMessageHandler {
UserDO userDO = userService.findById(licenseDO.getUserId());
if (null == userDO || EnableStatusEnum.DISABLE.getStatus().equals(userDO.getEnable())) {
log.warn("[client connection] the license invalid info:{} ", info);
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.AUTH_FAILED.getCode(), "the license invalid!", licenseKey));
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.AUTH_FAILED.getCode(), "the license invalid!", licenseKey, null));
ctx.channel().close();
clientConnectRecordService.add(new ClientConnectRecordDO()
.setIp(ip)
@@ -151,7 +152,7 @@ public class ProxyMessageAuthHandler implements ProxyMessageHandler {
String _clientId = ProxyUtil.getClientIdByLicenseId(licenseDO.getId());
if (!clientId.equals(_clientId)) {
log.warn("[client connection] the license on another no used info:{} _clientId:{}", info, _clientId);
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.AUTH_FAILED.getCode(), "the license on another no used!", licenseKey));
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.AUTH_FAILED.getCode(), "the license on another no used!", licenseKey, null));
ctx.channel().close();
clientConnectRecordService.add(new ClientConnectRecordDO()
.setIp(ip)
@@ -164,8 +165,22 @@ public class ProxyMessageAuthHandler implements ProxyMessageHandler {
return;
}
}
// 存储状态为非安全,如果客户端响应以下的公钥信息,则在响应中设置为安全
Attribute<Boolean> booleanAttribute = ctx.attr(Constants.IS_SECURITY);
booleanAttribute.set(false);
// 生成获取SM2密钥对,私钥存入ctx,公钥拼装参数随Auth数据包返回
KeyPairRecord record = EncryptUtil.generateSm2KeyPair();
// 私钥存入ctx
ctx.attr(Constants.SECURE_PRIVATE_KEY).set(record.privateKey());
// 存储licenseId
ctx.attr(Constants.LICENSE_ID).set(licenseDO.getId());
// 发送认证成功消息
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.SUCCESS.getCode(), "auth success!", licenseKey));
ctx.channel().writeAndFlush(ProxyMessage.buildAuthResultMessage(ExceptionEnum.SUCCESS.getCode(), "auth success!", licenseKey, record.publicKey()));
clientConnectRecordService.add(new ClientConnectRecordDO()
.setIp(ip)
@@ -50,7 +50,7 @@ public class ProxyMessageConnectHandler implements ProxyMessageHandler {
LicenseDO licenseDO = licenseService.findByKey(licenseKey);
if (null == licenseDO) {
ctx.channel().writeAndFlush(ProxyMessage.buildErrMessage(ExceptionEnum.CONNECT_FAILED, "the license notfound!"));
ctx.channel().writeAndFlush(ProxyMessage.buildErrMessage(ExceptionEnum.CONNECT_FAILED, "the license not found!"));
ctx.channel().close();
return;
}
@@ -69,7 +69,7 @@ public class ProxyMessageConnectHandler implements ProxyMessageHandler {
Channel cmdChannel = ProxyUtil.getCmdChannelByLicenseId(licenseDO.getId());
if (null == cmdChannel) {
ctx.channel().writeAndFlush(ProxyMessage.buildErrMessage(ExceptionEnum.CONNECT_FAILED, "server errorcmd channel notfound!"));
ctx.channel().writeAndFlush(ProxyMessage.buildErrMessage(ExceptionEnum.CONNECT_FAILED, "server errorcmd channel not found!"));
ctx.channel().close();
return;
}
@@ -92,6 +92,9 @@ public class ProxyMessageConnectHandler implements ProxyMessageHandler {
ProxyUtil.remoteProxyConnectAttachment(visitorId);
proxyAttachment.execute();
}
// 设置加密
ProxyUtil.setChannelSecurity(licenseDO.getId(), ctx.channel());
}
@Override
@@ -0,0 +1,75 @@
package org.dromara.neutrinoproxy.server.proxy.handler;
import cn.hutool.core.util.StrUtil;
import io.netty.channel.Channel;
import io.netty.channel.ChannelHandlerContext;
import io.netty.util.Attribute;
import lombok.extern.slf4j.Slf4j;
import org.dromara.neutrinoproxy.core.Constants;
import org.dromara.neutrinoproxy.core.ProxyDataTypeEnum;
import org.dromara.neutrinoproxy.core.ProxyMessage;
import org.dromara.neutrinoproxy.core.ProxyMessageHandler;
import org.dromara.neutrinoproxy.core.dispatcher.Match;
import org.dromara.neutrinoproxy.core.util.EncryptUtil;
import org.dromara.neutrinoproxy.server.util.ProxyUtil;
import org.noear.solon.annotation.Component;
import java.util.Map;
@Slf4j
@Match(type= Constants.ProxyDataTypeName.SECURE_KEY)
@Component
public class ProxyMessageSecureKeyHandler implements ProxyMessageHandler {
@Override
public void handle(ChannelHandlerContext ctx, ProxyMessage proxyMessage) {
log.info("收到客户端的加密信息");
// data为加密后的密码,info为加密密码的摘要
byte[] data = proxyMessage.getData();
String receivedDigest = proxyMessage.getInfo();
String digest = EncryptUtil.digestBySm3(data);
if (!digest.equals(receivedDigest)) {
// 获取加密信息失败
log.warn("密码协商失败");
// TODO 应该断开连接
return;
}
// 获取私钥
Attribute<String> privateKeyAttr = ctx.attr(Constants.SECURE_PRIVATE_KEY);
String privateKey = privateKeyAttr.get();
if (StrUtil.isEmpty(privateKey)) {
// 获取私钥失败
log.warn("获取私钥失败");
// TODO 应该断开连接
return;
}
// 解密传输密码
byte[] secureKey = EncryptUtil.decryptBySm2(privateKey, data);
// 传输密码存储ctx中
Attribute<byte[]> secureKeyAttr = ctx.attr(Constants.SECURE_KEY);
secureKeyAttr.setIfAbsent(secureKey);
// 使用密码加密success给客户端表示密码已确认
byte[] encryptedSuccessInfoData = EncryptUtil.encryptByAes(secureKey, "ok".getBytes());
// 发送回去,以示确认
ctx.writeAndFlush(ProxyMessage.buildSecureKeyReturnMessage(encryptedSuccessInfoData));
ctx.flush();
// 设置该链路以及相关链路状态为安全,之后使用链路传输的数据均会加密
Integer licenseId = ctx.attr(Constants.LICENSE_ID).get();
ProxyUtil.setSecureKey(licenseId, secureKey);
ProxyUtil.setChannelSecurity(licenseId, ctx.channel());
}
@Override
public String name() {
return ProxyDataTypeEnum.SECURE_KEY.getDesc();
}
}
@@ -35,11 +35,9 @@ import org.noear.solon.Solon;
import org.noear.solon.annotation.Component;
import org.noear.solon.annotation.Init;
import org.noear.solon.annotation.Inject;
import org.noear.solon.core.runtime.NativeDetector;
import java.util.Date;
import java.util.HashMap;
import java.util.List;
import java.util.Map;
import java.util.*;
import java.util.stream.Collectors;
/**
@@ -67,6 +65,10 @@ public class JobInfoService implements IJobSource {
@Init
public void init() {
// aot 阶段,不初始化
if (NativeDetector.isAotRuntime()) {
return;
}
jobHandlerMap.put("DataCleanJob", dataCleanJob);
jobHandlerMap.put("DemoJob", demoJob);
jobHandlerMap.put("FlowReportForDayJob", flowReportForDayJob);
@@ -107,6 +109,10 @@ public class JobInfoService implements IJobSource {
@Override
public List<JobInfo> sourceList() {
// aot 阶段,不查数据库
if (NativeDetector.isAotRuntime()) {
return Collections.emptyList();
}
List<JobInfo> jobInfoList = Lists.newArrayList();
List<JobInfoDO> jobInfoDOList = jobInfoMapper.findList();
if (CollectionUtil.isEmpty(jobInfoDOList)) {
@@ -35,7 +35,9 @@ import org.dromara.neutrinoproxy.server.dal.entity.JobLogDO;
import org.dromara.solonplugins.job.IJobCallback;
import org.dromara.solonplugins.job.JobInfo;
import org.noear.solon.annotation.Component;
import org.noear.solon.core.runtime.NativeDetector;
import java.util.Collections;
import java.util.Date;
import java.util.List;
import java.util.stream.Collectors;
@@ -53,6 +55,10 @@ public class JobLogService implements IJobCallback {
@Override
public void executeLog(JobInfo jobInfo, String param, Throwable throwable) {
// aot 阶段,不查数据库
if (NativeDetector.isAotRuntime()) {
return;
}
Integer code = 0;
String msg = "";
if (null == throwable) {
@@ -34,6 +34,7 @@ import org.noear.solon.annotation.Component;
import org.noear.solon.annotation.Init;
import org.noear.solon.annotation.Inject;
import org.noear.solon.core.bean.LifecycleBean;
import org.noear.solon.core.runtime.NativeDetector;
import java.util.Arrays;
import java.util.Date;
@@ -238,6 +239,10 @@ public class LicenseService implements LifecycleBean {
*/
@Init
public void init() {
// aot 阶段,不初始化
if (NativeDetector.isAotRuntime()) {
return;
}
licenseMapper.updateOnlineStatus(OnlineStatusEnum.OFFLINE.getStatus(), new Date());
}
@@ -40,6 +40,7 @@ import org.noear.solon.annotation.Component;
import org.noear.solon.annotation.Init;
import org.noear.solon.annotation.Inject;
import org.noear.solon.core.bean.LifecycleBean;
import org.noear.solon.core.runtime.NativeDetector;
import java.util.Comparator;
import java.util.Date;
@@ -295,6 +296,10 @@ public class PortMappingService implements LifecycleBean {
*/
@Init
public void init() {
// aot 阶段,不初始化
if (NativeDetector.isAotRuntime()) {
return;
}
portMappingMapper.updateOnlineStatus(OnlineStatusEnum.OFFLINE.getStatus(), new Date());
// 未配置域名,则不需要处理域名映射逻辑
@@ -38,15 +38,15 @@ public class ProxyUtil {
/**
* 服务端口 -> 指令通道映射
*/
private static Map<Integer, Channel> serverPortToCmdChannelMap = new ConcurrentHashMap<>();
private static final Map<Integer, Channel> serverPortToCmdChannelMap = new ConcurrentHashMap<>();
/**
* license -> 指令通道映射
*/
private static Map<Integer, Channel> licenseToCmdChannelMap = new ConcurrentHashMap<>();
private static final Map<Integer, Channel> licenseToCmdChannelMap = new ConcurrentHashMap<>();
/**
* 服务端口 -> 访问通道映射
*/
private static Map<Integer, Channel> serverPortToVisitorChannel = new ConcurrentHashMap<>();
private static final Map<Integer, Channel> serverPortToVisitorChannel = new ConcurrentHashMap<>();
/**
* cmdChannelAttachInfo.getUserChannelMap() 读写锁
@@ -55,19 +55,21 @@ public class ProxyUtil {
/**
* 访问者ID生成器
*/
private static AtomicLong visitorIdProducer = new AtomicLong(0);
private static final AtomicLong visitorIdProducer = new AtomicLong(0);
/**
* 代理 - connect附加映射
*/
private static Map<String, ProxyAttachment> proxyConnectAttachmentMap = new HashMap<>();
private static final Map<String, ProxyAttachment> proxyConnectAttachmentMap = new HashMap<>();
/**
* 子域名 - 服务端端口映射
*/
private static Map<String, Integer> subdomainToServerPort = new HashMap<>();
private static final Map<String, Integer> subdomainToServerPort = new HashMap<>();
/**
* licenseId - 客户端Id映射
*/
private static Map<Integer, String> licenseIdToClientIdMap = new HashMap<>();
private static final Map<Integer, String> licenseIdToClientIdMap = new HashMap<>();
private static final Map<Integer, byte[]> licenseIdToSecureKeyMap = new ConcurrentHashMap<>();
/**
* 初始化代理信息
@@ -421,4 +423,22 @@ public class ProxyUtil {
public static void removeClientIdByLicenseId(Integer licenseId) {
licenseIdToClientIdMap.remove(licenseId);
}
public static void setSecureKey(Integer licenseId, byte[] key) {
licenseIdToSecureKeyMap.put(licenseId, key);
}
public static void setLicenseIdRelativeProxyChannelSecurity(Integer licenseId) {
Set<Integer> portSet = licenseToServerPortMap.get(licenseId);
for(Integer port : portSet) {
// TODO 代理客户端
}
}
public static void setChannelSecurity(Integer licenseId, Channel channel) {
if (channel != null && licenseIdToSecureKeyMap.containsKey(licenseId)) {
channel.attr(Constants.IS_SECURITY).set(true);
channel.attr(Constants.SECURE_KEY).set(licenseIdToSecureKeyMap.get(licenseId));
}
}
}
@@ -0,0 +1,59 @@
server:
# 服务端web端口,用于支持HTTP接口,管理后台页面访问
port: 8888
# 日志级别
solon.logging.logger:
"root":
level: info
neutrino:
proxy:
# 隧道相关配置-用于维持服务端与客户端的通信
tunnel:
# 线程池相关配置,用于技术调优,可忽略
boss-thread-count: 2
work-thread-count: 10
# 隧道非SSL端口
port: ${OPEN_PORT:9000}
# 隧道SSL端口
ssl-port: ${SSL_PORT:9002}
# 隧道SSL证书配置
key-store-password: ${STORE_PASS:123456}
key-manager-password: ${MGR_PASS:123456}
jks-path: ${JKS_PATH:classpath:/test.jks}
# 是否开启隧道传输报文日志(日志级别为debug时开启才有效)
transfer-log-enable: ${TUNNEL_LOG:false}
# 是否开启心跳日志
heartbeat-log-enable: ${HEARTBEAT_LOG:false}
server:
tcp:
# 线程池相关配置,用于技术调优,可忽略
boss-thread-count: 5
work-thread-count: 20
# http代理端口,默认80
http-proxy-port: ${HTTP_PROXY_PORT:80}
# https代理端口,默认443 (需要配置域名、证书)
https-proxy-port: ${HTTPS_PROXY_PORT:443}
# 如果不配置,则不支持域名映射
domain-name: ${DOMAIN_NAME:}
# https证书配置
key-store-password: ${HTTPS_STORE_PASS:}
jks-path: ${HTTPS_JKS_PATH:}
# 是否开启代理服务报文日志(日志级别为debug时开启才有效)
transfer-log-enable: ${SERVER_LOG:false}
udp:
# 线程池相关配置,用于技术调优,可忽略
boss-thread-count: 5
work-thread-count: 20
# 是否开启代理服务报文日志(日志级别为debug时开启才有效)
transfer-log-enable: ${SERVER_LOG:false}
data:
db:
# 数据库类型,目前支持h2、mysql、mariadb
type: ${DB_TYPE:h2}
# 数据库连接URL
url: ${DB_URL:jdbc:h2:file:./data/db;MODE=MySQL;AUTO_SERVER=TRUE}
# 数据库用户名
username: ${DB_USER:}
# 数据库密码
password: ${DB_PASSWORD:}
@@ -5,10 +5,9 @@ server:
solon:
app:
name: neutrino-proxy-server
version: @revision@
config:
add: ./app.yml
# aot:
# jvmArguments: --add-opens java.base/java.lang=ALL-UNNAMED
# 日志级别
solon.logging.appender:
console:
@@ -25,7 +24,7 @@ solon.logging.logger:
neutrino:
proxy:
protocol:
max-frame-length: ${MAX_FRAME_LENGTH:2097152}
max-frame-length: ${MAX_FRAME_LENGTH:1048576000}
length-field-offset: 0
length-field-length: 4
initial-bytes-to-strip: 0
@@ -0,0 +1,19 @@
package org.dromara.neutrinoproxy.server;
import org.dromara.neutrinoproxy.core.util.NeutrinoProxyVersion;
import org.dromara.neutrinoproxy.server.app.AppBaseTest;
import org.junit.Assert;
import org.junit.Test;
/**
* @author songyinyin
* @since 2023/10/31 11:51
*/
public class VersionTest extends AppBaseTest {
@Test
public void testVersion() {
Assert.assertNotNull(NeutrinoProxyVersion.getVersion());
System.out.println("version: " + NeutrinoProxyVersion.getVersion());
}
}
@@ -0,0 +1,15 @@
package org.dromara.neutrinoproxy.server.app;
import org.dromara.neutrinoproxy.server.ProxyServer;
import org.junit.runner.RunWith;
import org.noear.solon.test.SolonJUnit4ClassRunner;
import org.noear.solon.test.SolonTest;
/**
* @author songyinyin
* @since 2023/10/31 11:56
*/
@SolonTest(value = ProxyServer.class, properties = "server.port=18888")
@RunWith(SolonJUnit4ClassRunner.class)
public class AppBaseTest {
}
@@ -6,14 +6,14 @@ permalink: /pages/eebea1/
## 1、环境准备
- 首先确保已安装Java17运行环境
- 打开[发行版页面](https://gitee.com/dromara/neutrino-proxy/releases),下载最新的release包:`neutrino-proxy-server.jar``neutrino-proxy-client.jar`
- 打开[发行版页面](https://gitee.com/dromara/neutrino-proxy/releases),下载最新的release包:`neutrino-proxy-server-jar.zip``neutrino-proxy-client-jar.zip`
## 2、部署服务端
- 在服务器上新建部署目录:`/work/projects/neutrino-proxy-server`
-` neutrino-proxy-server.jar`上传至服务器部署目录
-`neutrino-proxy-server-jar.zip`上传至服务器部署目录,并解压
- 执行命令`java -Dfile.encoding=utf-8 -jar neutrino-proxy-server.jar`启动服务端完成部署,默认使用h2数据库。
- 若需要指定自己的mysql数据库,同样的需要在当前目录下新建`app.yml`文件,配置内容如下。执行命令`java -Dfile.encoding=utf-8 -jar neutrino-proxy-server.jar config=app.yml`启动服务端完成部署
- 若需要指定自己的mysql数据库,需要在当前目录下`app.yml`文件中,修改数据库配置如下:
```yml
neutrino:
@@ -32,8 +32,8 @@ neutrino:
- 可参照 https://gitee.com/dromara/neutrino-proxy/blob/master/scripts/unix/server_start.sh 使用shell脚本启动服务端。
## 3、部署客户端
- 客户端采用docker部署,使用代理时会存在更多的坑点,因此官方并不推荐
- 在本地`neutrino-proxy-client.jar`同级别目录下新建`app.yml`文件,并配置如下内容
- 本地解压`neutrino-proxy-client-jar.zip`文件
- 修改`app.yml`文件中的server-ip为服务器公网ip,并配置license-key,以下是相关的部分配置
```yml
neutrino:
proxy:
@@ -51,5 +51,5 @@ neutrino:
# licenseKey,客户端凭证。此处需要配置刚刚从管理后台复制的LicenseKey
license-key: xxxx
```
- 执行命令`java -jar neutrino-proxy-client.jar config=app.yml`启动客户端
- 执行命令`java -jar neutrino-proxy-client.jar`启动客户端
@@ -35,7 +35,7 @@ neutrino:
## 2、部署客户端
- 命令中的服务端ip、license请自行补充
- 若是首次使用,请仔细月度快速上手,以确定license从哪里取得
- 若是首次使用,请仔细阅读快速上手,以确定license从哪里取得
```shell
docker run -it -d --restart=always --name npclient -e SERVER_IP=xxxx -e LICENSE_KEY=xxxx \
aoshiguchen/neutrino-proxy-client:latest
@@ -3,3 +3,59 @@ title: 原生部署
date: 2023-10-26 13:51:44
permalink: /pages/69699a/
---
::: tip
1、目前的原生部署包支持mac、linux、windows三个平台
2、这三个平台的部署包均由作者分别测试通过
3、尽管如此,仍然可能存在有的机器不支持的情况,可自行拉取仓库源码编译出目标平台可执行文件、或换成其它部署方式
4、若linux/mac下提示文件没有执行权限,可执行`chmod +x {文件路径}`解决
5、若mac下运行提示移到废纸篓,可执行`sudo xattr -rd com.apple.quarantine {文件路径}`解决
:::
## 1、安装包下载
- 打开[发行版页面](https://gitee.com/dromara/neutrino-proxy/releases),下载所需的最新的release包:
- 比如服务器为linux则可下载`neutrino-proxy-server-ubuntu-20.04-native.zip`文件,客户端为windows则可下载`neutrino-proxy-client-windows-2022-native.zip`
## 2、部署服务端
- 将服务端安装包上传至服务器,并解压
- 服务端默认使用h2数据库,若需要改为mysql,则可修改安装包`app.yml`内的数据库配置,如下:
```yml
neutrino:
data:
db:
type: mysql
# 自己的数据库实例,创建一个空的名为'neutrino-proxy'的数据库即可,首次启动服务端会自动初始化
url: jdbc:mysql://xxxx:3306/neutrino-proxy?useUnicode=true&characterEncoding=UTF-8&allowMultiQueries=true&useAffectedRows=true&useSSL=false
driver-class: com.mysql.jdbc.Driver
# 数据库帐号
username: xxx
# 数据库密码
password: xxx
```
- 然后直接启动服务端可执行程序即可
## 3、部署客户端
- 本地解压客户端安装包
- 修改`app.yml`文件中的server-ip为服务器公网ip,并配置license-key,以下是相关的部分配置:
```yml
neutrino:
proxy:
tunnel:
# ssl证书密钥(使用jjar包内自带的证书,则此处无需修改)
key-store-password: 123456
# ssl证书管理密钥(使用jjar包内自带的证书,则此处无需修改。自定义证书,则此处配置对应的路径)
jks-path: classpath:/test.jks
# 代理服务端IP
server-ip: xxxx
# 代理服务端IP, 若是非ssl端口,则ssl-enable需要配置为false
server-port: 9002
# 是否启用ssl
ssl-enable: true
# licenseKey,客户端凭证。此处需要配置刚刚从管理后台复制的LicenseKey
license-key: xxxx
```
- 然后直接启动客户端可执行程序即可
@@ -16,12 +16,13 @@ permalink: /pages/f2d0f1/
server:
# 服务端web端口,用于支持HTTP接口,管理后台页面访问
port: ${WEB_PORT:8888}
# 日志级别
solon.logging.logger:
"root":
level: info
neutrino:
proxy:
logger:
# 日志级别
level: ${LOG_LEVEL:info}
# 隧道相关配置-用于维持服务端与客户端的通信
tunnel:
# 线程池相关配置,用于技术调优,可忽略
@@ -37,6 +38,8 @@ neutrino:
jks-path: ${JKS_PATH:classpath:/test.jks}
# 是否开启隧道传输报文日志(日志级别为debug时开启才有效)
transfer-log-enable: ${TUNNEL_LOG:false}
# 是否开启心跳日志
heartbeat-log-enable: ${HEARTBEAT_LOG:false}
server:
tcp:
# 线程池相关配置,用于技术调优,可忽略
@@ -61,10 +64,10 @@ neutrino:
transfer-log-enable: ${SERVER_LOG:false}
data:
db:
# 数据库类型,目前支持sqlite、mysql、mariadb
type: ${DB_TYPE:sqlite}
# 数据库类型,目前支持h2、mysql、mariadb
type: ${DB_TYPE:h2}
# 数据库连接URL
url: ${DB_URL:jdbc:sqlite:data.db}
url: ${DB_URL:jdbc:h2:file:./data/db;MODE=MySQL;AUTO_SERVER=TRUE}
# 数据库用户名
username: ${DB_USER:}
# 数据库密码
@@ -12,11 +12,13 @@ permalink: /pages/50ce10/
# 以下是最新的客户端配置格式(app.yml)
```yml
# 日志级别
solon.logging.logger:
"root":
level: info
neutrino:
proxy:
logger:
# 日志级别
level: ${LOG_LEVEL:info}
tunnel:
# 线程池相关配置,用于技术调优,可忽略
thread-count: 50
@@ -35,6 +37,8 @@ neutrino:
client-id: ${CLIENT_ID:}
# 是否开启隧道传输报文日志(日志级别为debug时开启才有效)
transfer-log-enable: ${CLIENT_LOG:false}
# 是否开启心跳日志
heartbeat-log-enable: ${HEARTBEAT_LOG:false}
# 重连设置
reconnection:
# 重连间隔(秒)
@@ -6,6 +6,8 @@ permalink: /pages/cded59/
| 日期 | 渠道 | 金额 |昵称| 备注 |
|:-----------|:---|:-----|:-|:-----------------|
|2023-11-01|微信红包|20|Sun|感谢大佬,请你喝杯奶茶[微笑]|
|2023-10-30|微信赞赏|50|杨娃娃||
|2023-10-16|微信转账|50|Mark Isaac赵方丈|金额不大,开源感恩。|
|2023-10-11|微信红包|50|喜鸽小宝||
|2023-10-10|微信红包|20|海洋||
+1 -261
View File
@@ -1,261 +1 @@
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<parent>
<groupId>org.noear</groupId>
<artifactId>solon-parent</artifactId>
<version>2.5.12-SNAPSHOT</version>
<relativePath />
</parent>
<groupId>org.dromara.neutrino-proxy</groupId>
<artifactId>neutrino-proxy</artifactId>
<packaging>pom</packaging>
<version>${revision}</version>
<modules>
<module>neutrino-proxy-core</module>
<module>neutrino-proxy-client</module>
<module>neutrino-proxy-server</module>
</modules>
<properties>
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
<maven.compiler.encoding>UTF-8</maven.compiler.encoding>
<revision>1.1-SNAPSHOT</revision>
<native.version>0.9.28</native.version>
<java.version>17</java.version>
<maven-compiler-plugin.version>3.8.0</maven-compiler-plugin.version>
<maven-flatten.version>1.1.0</maven-flatten.version>
</properties>
<dependencyManagement>
<dependencies>
<dependency>
<groupId>io.netty</groupId>
<artifactId>netty-all</artifactId>
<version>4.1.100.Final</version>
</dependency>
<dependency>
<groupId>org.yaml</groupId>
<artifactId>snakeyaml</artifactId>
<version>1.33</version>
</dependency>
<dependency>
<groupId>junit</groupId>
<artifactId>junit</artifactId>
<version>4.12</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.apache.commons</groupId>
<artifactId>commons-lang3</artifactId>
<version>3.9</version>
</dependency>
<dependency>
<groupId>com.google.guava</groupId>
<artifactId>guava</artifactId>
<version>28.0-jre</version>
</dependency>
<dependency>
<groupId>commons-fileupload</groupId>
<artifactId>commons-fileupload</artifactId>
<version>1.3.1</version>
</dependency>
<dependency>
<groupId>com.h2database</groupId>
<artifactId>h2</artifactId>
<version>2.2.224</version>
</dependency>
<dependency>
<groupId>mysql</groupId>
<artifactId>mysql-connector-java</artifactId>
<version>8.0.33</version>
</dependency>
<dependency>
<groupId>org.mariadb.jdbc</groupId>
<artifactId>mariadb-java-client</artifactId>
<version>2.7.4</version>
</dependency>
<dependency>
<groupId>com.zaxxer</groupId>
<artifactId>HikariCP</artifactId>
<version>4.0.3</version>
</dependency>
<dependency>
<groupId>org.dromara.solon-plugins</groupId>
<artifactId>job-solon-plugin</artifactId>
<version>0.1.1</version>
<exclusions>
<exclusion>
<groupId>cn.hutool</groupId>
<artifactId>hutool-core</artifactId>
</exclusion>
</exclusions>
</dependency>
</dependencies>
</dependencyManagement>
<dependencies>
<dependency>
<groupId>org.noear</groupId>
<artifactId>solon.logging.logback</artifactId>
</dependency>
<dependency>
<groupId>org.projectlombok</groupId>
<artifactId>lombok</artifactId>
</dependency>
<dependency>
<groupId>org.apache.commons</groupId>
<artifactId>commons-lang3</artifactId>
</dependency>
<dependency>
<groupId>com.google.guava</groupId>
<artifactId>guava</artifactId>
</dependency>
<dependency>
<groupId>junit</groupId>
<artifactId>junit</artifactId>
<scope>test</scope>
</dependency>
</dependencies>
<build>
<resources>
<resource>
<directory>src/main/resources</directory>
</resource>
</resources>
<plugins>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-compiler-plugin</artifactId>
<version>${maven-compiler-plugin.version}</version>
<configuration>
<source>${java.version}</source>
<target>${java.version}</target>
<encoding>UTF-8</encoding>
<annotationProcessorPaths>
<path>
<groupId>org.projectlombok</groupId>
<artifactId>lombok</artifactId>
<version>${lombok.version}</version>
</path>
</annotationProcessorPaths>
</configuration>
</plugin>
<!-- 添加flatten-maven-plugin插件 -->
<plugin>
<groupId>org.codehaus.mojo</groupId>
<artifactId>flatten-maven-plugin</artifactId>
<version>${maven-flatten.version}</version>
<configuration>
<updatePomFile>true</updatePomFile>
<flattenMode>resolveCiFriendliesOnly</flattenMode>
</configuration>
<executions>
<execution>
<id>flatten</id>
<phase>process-resources</phase>
<goals>
<goal>flatten</goal>
</goals>
</execution>
<execution>
<id>flatten.clean</id>
<phase>clean</phase>
<goals>
<goal>clean</goal>
</goals>
</execution>
</executions>
</plugin>
</plugins>
</build>
<repositories>
<repository>
<id>tencent</id>
<url>https://mirrors.cloud.tencent.com/nexus/repository/maven-public/</url>
<snapshots>
<enabled>false</enabled>
</snapshots>
</repository>
<repository>
<id>sonatype-nexus-snapshots</id>
<name>Sonatype Nexus Snapshots</name>
<url>https://oss.sonatype.org/content/repositories/snapshots</url>
<releases>
<enabled>false</enabled>
</releases>
</repository>
</repositories>
<pluginRepositories>
<pluginRepository>
<id>sonatype-nexus-snapshots</id>
<name>Sonatype Nexus Snapshots</name>
<url>https://oss.sonatype.org/content/repositories/snapshots</url>
<releases>
<enabled>false</enabled>
</releases>
</pluginRepository>
</pluginRepositories>
<profiles>
<profile>
<id>native</id>
<build>
<plugins>
<plugin>
<groupId>org.noear</groupId>
<artifactId>solon-maven-plugin</artifactId>
<version>${solon-maven-plugin.version}</version>
<executions>
<execution>
<id>process-aot</id>
<goals>
<goal>process-aot</goal>
</goals>
</execution>
</executions>
<dependencies>
<dependency>
<groupId>org.codehaus.plexus</groupId>
<artifactId>plexus-utils</artifactId>
<version>3.5.1</version>
</dependency>
</dependencies>
</plugin>
<plugin>
<groupId>org.graalvm.buildtools</groupId>
<artifactId>native-maven-plugin</artifactId>
<version>${native.version}</version>
<!-- 使用graalvm提供的可达性元数据,很多第三方库就直接可以构建成可执行文件了 -->
<configuration>
<metadataRepository>
<enabled>true</enabled>
</metadataRepository>
</configuration>
<executions>
<execution>
<id>add-reachability-metadata</id>
<goals>
<goal>add-reachability-metadata</goal>
</goals>
</execution>
</executions>
</plugin>
</plugins>
</build>
</profile>
</profiles>
</project>
<?xml version="1.0" encoding="UTF-8"?><project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"><modelVersion>4.0.0</modelVersion>␍␍ <parent><groupId>org.noear</groupId><artifactId>solon-parent</artifactId><version>2.5.12</version><relativePath /></parent>␍␍ <groupId>org.dromara.neutrino-proxy</groupId><artifactId>neutrino-proxy</artifactId><packaging>pom</packaging><version>${revision}</version>␍␍ <modules><module>neutrino-proxy-core</module><module>neutrino-proxy-client</module><module>neutrino-proxy-server</module></modules>␍␍ <properties><project.build.sourceEncoding>UTF-8</project.build.sourceEncoding><project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding><maven.compiler.encoding>UTF-8</maven.compiler.encoding><revision>2.0.1-SNAPSHOT</revision>␍␍ <native.version>0.9.28</native.version>␍␍ <java.version>21</java.version><maven-compiler-plugin.version>3.8.0</maven-compiler-plugin.version><maven-flatten.version>1.1.0</maven-flatten.version></properties>␍␍ <dependencyManagement><dependencies><dependency><groupId>io.netty</groupId><artifactId>netty-all</artifactId><version>4.1.100.Final</version></dependency><dependency><groupId>org.yaml</groupId><artifactId>snakeyaml</artifactId><version>1.33</version></dependency><dependency><groupId>junit</groupId><artifactId>junit</artifactId><version>4.12</version><scope>test</scope></dependency><dependency><groupId>org.apache.commons</groupId><artifactId>commons-lang3</artifactId><version>3.9</version></dependency><dependency><groupId>com.google.guava</groupId><artifactId>guava</artifactId><version>28.0-jre</version></dependency><dependency><groupId>commons-fileupload</groupId><artifactId>commons-fileupload</artifactId><version>1.3.1</version></dependency><dependency><groupId>com.h2database</groupId><artifactId>h2</artifactId><version>2.2.224</version></dependency><dependency><groupId>mysql</groupId><artifactId>mysql-connector-java</artifactId><version>8.0.33</version></dependency><dependency><groupId>org.mariadb.jdbc</groupId><artifactId>mariadb-java-client</artifactId><version>2.7.4</version></dependency><dependency><groupId>com.zaxxer</groupId><artifactId>HikariCP</artifactId><version>4.0.3</version></dependency><dependency><groupId>org.bouncycastle</groupId><artifactId>bcprov-jdk15to18</artifactId><version>1.69</version></dependency><dependency><groupId>org.dromara.solon-plugins</groupId><artifactId>job-solon-plugin</artifactId><version>0.1.1</version><exclusions><exclusion><groupId>cn.hutool</groupId><artifactId>hutool-core</artifactId></exclusion></exclusions></dependency></dependencies></dependencyManagement>␍␍ <dependencies><dependency><groupId>org.noear</groupId><artifactId>solon.logging.logback</artifactId></dependency><dependency><groupId>org.projectlombok</groupId><artifactId>lombok</artifactId><scope>provided</scope></dependency><dependency><groupId>org.apache.commons</groupId><artifactId>commons-lang3</artifactId></dependency><dependency><groupId>com.google.guava</groupId><artifactId>guava</artifactId></dependency>␍␍ <dependency><groupId>org.noear</groupId><artifactId>solon-test</artifactId><scope>test</scope></dependency></dependencies>␍␍ <build><resources><resource><directory>src/main/resources</directory></resource></resources><plugins><plugin><groupId>org.apache.maven.plugins</groupId><artifactId>maven-compiler-plugin</artifactId><version>${maven-compiler-plugin.version}</version><configuration><source>${java.version}</source><target>${java.version}</target><encoding>UTF-8</encoding><annotationProcessorPaths><path><groupId>org.projectlombok</groupId><artifactId>lombok</artifactId><version>${lombok.version}</version></path></annotationProcessorPaths></configuration></plugin><!-- 添加flatten-maven-plugin插件 --><plugin><groupId>org.codehaus.mojo</groupId><artifactId>flatten-maven-plugin</artifactId><version>${maven-flatten.version}</version><configuration><updatePomFile>true</updatePomFile><flattenMode>resolveCiFriendliesOnly</flattenMode></configuration><executions><execution><id>flatten</id><phase>process-resources</phase><goals><goal>flatten</goal></goals></execution><execution><id>flatten.clean</id><phase>clean</phase><goals><goal>clean</goal></goals></execution></executions></plugin></plugins></build>␍␍ <repositories><repository><id>tencent</id><url>https://mirrors.cloud.tencent.com/nexus/repository/maven-public/</url><snapshots><enabled>false</enabled></snapshots></repository><repository><id>sonatype-nexus-snapshots</id><name>Sonatype Nexus Snapshots</name><url>https://oss.sonatype.org/content/repositories/snapshots</url><releases><enabled>false</enabled></releases></repository></repositories><pluginRepositories><pluginRepository><id>sonatype-nexus-snapshots</id><name>Sonatype Nexus Snapshots</name><url>https://oss.sonatype.org/content/repositories/snapshots</url><releases><enabled>false</enabled></releases></pluginRepository></pluginRepositories>␍␍ <profiles><profile><id>native</id><build><plugins><plugin><groupId>org.noear</groupId><artifactId>solon-maven-plugin</artifactId><version>${solon.version}</version><executions><execution><id>process-aot</id><goals><goal>process-aot</goal></goals></execution></executions>␍␍ <dependencies><dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>3.5.1</version></dependency></dependencies></plugin><plugin><groupId>org.graalvm.buildtools</groupId><artifactId>native-maven-plugin</artifactId><version>${native.version}</version><!-- 使用graalvm提供的可达性元数据,很多第三方库就直接可以构建成可执行文件了 --><configuration><metadataRepository><enabled>true</enabled></metadataRepository></configuration><executions><execution><id>add-reachability-metadata</id><goals><goal>add-reachability-metadata</goal></goals></execution></executions></plugin></plugins></build></profile></profiles></project>␍␍
+12 -7
View File
@@ -1,7 +1,7 @@
#!/bin/sh
# 中微子代理客户端编译打包脚本,基础参数请自行修改
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-17.0.8+7.1/Contents/Home
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-21.0.1+12.1/Contents/Home
export MAVEN_HOME=/Users/yangwen/my/service/maven/apache-maven-3.8.1
export PATH=:$PATH:$JAVA_HOME/bin:$MAVEN_HOME/bin
@@ -11,15 +11,20 @@ clientDeployDir=$deployDir"/client"
#切到项目根目录
cd ../..
#初始化文件夹
#if [ ! -d "$deployDir" ];then
# mkdir $deployDir
#fi
#if [ ! -d "$clientDeployDir" ];then
# mkdir $clientDeployDir
#fi
mkdir -p $clientDeployDir
rm -rf $clientDeployDir/neutrino-proxy-client.jar
rm -rf $clientDeployDir/neutrino-proxy-client-jar
rm -rf $clientDeployDir/neutrino-proxy-client-jar.zip
#客户端打包
mvn clean install -U -pl neutrino-proxy-client -am -Dmaven.test.skip=true
# 拷贝到deploy目录下
cp ./neutrino-proxy-client/target/neutrino-proxy-client.jar $clientDeployDir/neutrino-proxy-client.jar
#打zip包,用于发版
cd $clientDeployDir
mkdir neutrino-proxy-client-jar
cp ../../neutrino-proxy-client/target/neutrino-proxy-client.jar ./neutrino-proxy-client-jar/neutrino-proxy-client.jar
cp ../../neutrino-proxy-client/src/main/resources/app-copy.yml ./neutrino-proxy-client-jar/app.yml
zip -r neutrino-proxy-client-jar.zip ./neutrino-proxy-client-jar
rm -rf $clientDeployDir/neutrino-proxy-client-jar
+24 -1
View File
@@ -1,12 +1,13 @@
#!/bin/sh
# 中微子代理客户端编译打包脚本,基础参数请自行修改
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-17.0.8+7.1/Contents/Home
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-21.0.1+12.1/Contents/Home
export MAVEN_HOME=/Users/yangwen/my/service/maven/apache-maven-3.8.1
export PATH=:$PATH:$JAVA_HOME/bin:$MAVEN_HOME/bin
deployDir="deploy"
clientDeployDir=$deployDir"/client"
machine=macos
#切到项目根目录
cd ../..
@@ -16,6 +17,10 @@ mkdir -p $clientDeployDir
# 删除原来的编译文件
rm -rf $clientDeployDir/neutrino-proxy-client.jar
rm -rf $clientDeployDir/neutrino-proxy-client
rm -rf $clientDeployDir/neutrino-proxy-client-jar
rm -rf $clientDeployDir/neutrino-proxy-client-jar.zip
rm -rf $clientDeployDir/neutrino-proxy-client-${machine}-native
rm -rf $clientDeployDir/neutrino-proxy-client-${machine}-native.zip
#客户端打包
mvn clean install -U -pl neutrino-proxy-client -am -Dmaven.test.skip=true
@@ -23,7 +28,25 @@ cd neutrino-proxy-client
mvn clean native:compile -P native -DskipTests
cd ..
# 给执行权限
chmod +x ./neutrino-proxy-client/target/neutrino-proxy-client
# 拷贝到deploy目录下
cp ./neutrino-proxy-client/target/neutrino-proxy-client.jar $clientDeployDir/neutrino-proxy-client.jar
cp ./neutrino-proxy-client/target/neutrino-proxy-client $clientDeployDir/neutrino-proxy-client
#打zip包,用于发版
cd $clientDeployDir
## jar
mkdir neutrino-proxy-client-jar
cp ../../neutrino-proxy-client/target/neutrino-proxy-client.jar ./neutrino-proxy-client-jar/neutrino-proxy-client.jar
cp ../../neutrino-proxy-client/src/main/resources/app-copy.yml ./neutrino-proxy-client-jar/app.yml
zip -r neutrino-proxy-client-jar.zip ./neutrino-proxy-client-jar
rm -rf ./neutrino-proxy-client-jar
## native
mkdir neutrino-proxy-client-${machine}-native
cp ../../neutrino-proxy-client/target/neutrino-proxy-client ./neutrino-proxy-client-${machine}-native/neutrino-proxy-client
cp ../../neutrino-proxy-client/src/main/resources/app-copy.yml ./neutrino-proxy-client-${machine}-native/app.yml
zip -r neutrino-proxy-client-${machine}-native.zip ./neutrino-proxy-client-${machine}-native
rm -rf ./neutrino-proxy-client-${machine}-native
+1 -1
View File
@@ -2,7 +2,7 @@
# 中微子代理客户端启动脚本,基础参数请自行修改
JAVA_OPS="-server -Xms256m -Xmx512m -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=/work/$NAME/heapError/"
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-17.0.8+7.1/Contents/Home
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-21.0.1+12.1/Contents/Home
export PATH=:$PATH:$JAVA_HOME/bin
export CLASSPATH=.:$JAVA_HOME/jre/lib/rt.jar:$JAVA_HOME/lib/dt.jar:$JAVA_HOME/lib/tools.jar
mkdir -p /work/$NAME/heapError/
+11 -7
View File
@@ -1,7 +1,7 @@
#!/bin/sh
# 中微子代理服务端编译打包脚本,基础参数请自行修改
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-17.0.8+7.1/Contents/Home
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-21.0.1+12.1/Contents/Home
export MAVEN_HOME=/Users/yangwen/my/service/maven/apache-maven-3.8.1
export PATH=:$PATH:$JAVA_HOME/bin:$MAVEN_HOME/bin
@@ -11,16 +11,20 @@ serverDeployDir=$deployDir"/server"
#切到项目根目录
cd ../..
#初始化文件夹
#if [ ! -d "$deployDir" ];then
# mkdir $deployDir
#fi
#if [ ! -d "$serverDeployDir" ];then
# mkdir $serverDeployDir
#fi
mkdir -p $serverDeployDir
rm -rf $serverDeployDir/neutrino-proxy-server.jar
rm -rf $serverDeployDir/neutrino-proxy-server-jar
rm -rf $serverDeployDir/neutrino-proxy-server-jar.zip
#服务端打包
mvn clean install -U -pl neutrino-proxy-server -am -Dmaven.test.skip=true
# 拷贝到deploy目录下
cp ./neutrino-proxy-server/target/neutrino-proxy-server.jar $serverDeployDir/neutrino-proxy-server.jar
#打zip包,用于发版
cd $serverDeployDir
mkdir neutrino-proxy-server-jar
cp ../../neutrino-proxy-server/target/neutrino-proxy-server.jar ./neutrino-proxy-server-jar/neutrino-proxy-server.jar
cp ../../neutrino-proxy-server/src/main/resources/app-copy.yml ./neutrino-proxy-server-jar/app.yml
zip -r neutrino-proxy-server-jar.zip ./neutrino-proxy-server-jar
rm -rf $serverDeployDir/neutrino-proxy-server-jar
+24 -1
View File
@@ -1,12 +1,13 @@
#!/bin/sh
# 中微子代理服务端编译打包脚本,基础参数请自行修改
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-17.0.8+7.1/Contents/Home
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-21.0.1+12.1/Contents/Home
export MAVEN_HOME=/Users/yangwen/my/service/maven/apache-maven-3.8.1
export PATH=:$PATH:$JAVA_HOME/bin:$MAVEN_HOME/bin
deployDir="deploy"
serverDeployDir=$deployDir"/server"
machine=macos
#切到项目根目录
cd ../..
@@ -16,6 +17,10 @@ mkdir -p $serverDeployDir
# 删除原来的编译文件
rm -rf $serverDeployDir/neutrino-proxy-server.jar
rm -rf $serverDeployDir/neutrino-proxy-server
rm -rf $serverDeployDir/neutrino-proxy-server-jar
rm -rf $serverDeployDir/neutrino-proxy-server-jar.zip
rm -rf $serverDeployDir/neutrino-proxy-server-${machine}-native
rm -rf $serverDeployDir/neutrino-proxy-server-${machine}-native.zip
# 不需要每次都重新编译一次前端代码,如果前端代码有变更,编译前需要手动执行`admin_build_docker.sh`
##前端页面打包
@@ -32,7 +37,25 @@ cd neutrino-proxy-server
mvn clean native:compile -P native -DskipTests
cd ..
# 给执行权限
chmod +x ./neutrino-proxy-server/target/neutrino-proxy-server
# 拷贝到deploy目录下
cp ./neutrino-proxy-server/target/neutrino-proxy-server.jar $serverDeployDir/neutrino-proxy-server.jar
cp ./neutrino-proxy-server/target/neutrino-proxy-server $serverDeployDir/neutrino-proxy-server
#打zip包,用于发版
cd $serverDeployDir
## jar
mkdir neutrino-proxy-server-jar
cp ../../neutrino-proxy-server/target/neutrino-proxy-server.jar ./neutrino-proxy-server-jar/neutrino-proxy-server.jar
cp ../../neutrino-proxy-server/src/main/resources/app-copy.yml ./neutrino-proxy-server-jar/app.yml
zip -r neutrino-proxy-server-jar.zip ./neutrino-proxy-server-jar
rm -rf ./neutrino-proxy-server-jar
## native
mkdir neutrino-proxy-server-${machine}-native
cp ../../neutrino-proxy-server/target/neutrino-proxy-server ./neutrino-proxy-server-${machine}-native/neutrino-proxy-server
cp ../../neutrino-proxy-server/src/main/resources/app-copy.yml ./neutrino-proxy-server-${machine}-native/app.yml
zip -r neutrino-proxy-server-${machine}-native.zip ./neutrino-proxy-server-${machine}-native
rm -rf ./neutrino-proxy-server-${machine}-native
+1 -1
View File
@@ -2,7 +2,7 @@
# 中微子代理服务端启动脚本,基础参数请自行修改
JAVA_OPS="-server -Xms256m -Xmx1024m -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=/work/$NAME/heapError/"
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-17.0.8+7.1/Contents/Home
export JAVA_HOME=/Users/yangwen/my/service/graalvm/graalvm-community-openjdk-21.0.1+12.1/Contents/Home
export PATH=:$PATH:$JAVA_HOME/bin
export CLASSPATH=.:$JAVA_HOME/jre/lib/rt.jar:$JAVA_HOME/lib/dt.jar:$JAVA_HOME/lib/tools.jar
mkdir -p /work/$NAME/heapError/
+3
View File
@@ -0,0 +1,3 @@
#!/bin/sh
echo 'hello'
+21 -51
View File
@@ -1,54 +1,21 @@
# 1.x规划
- Bug
- 优化
- 添加端口映射时,验证端口是否被其他服务占用
- 拉下搜索license,支持模糊搜索
- license下拉用户搜索,支持模糊搜索
- UDP支持
- 官网文档完善
- HTTPS配置说明
- 协议重构
- 代码重构
# 1.8.6
- [x] 端口映射选择端口支持分页
- [x] 新增/更新端口映射,增加端口占用检测
- [x] 拉下搜索license,支持模糊搜索
- [x] license下拉用户搜索,支持模糊搜索
- [x] 端口映射编辑时,如果端口号没有变动,则不验证。避免出现端口映射正在使用时,无法更新端口映射其他信息的问题
- [x] 端口映射HTTP(S)新增打开网页按钮
- [x] 客户端断开连接时,记录日志空指针异常问题修复
# 1.9.0
- [x] 支持UDP
- 服务端
-`neutrino.proxy.server`配置移到`neutrino.proxy.server.tcp`
- 客户端
-`neutrino.proxy.client`配置移到`neutrino.proxy.tunnel`
- [x] 端口映射HTTP(S)新增打开网页按钮,优先使用域名打开
- [x] 新增/编辑端口映射时端口占用检测功能屏蔽,解决docker下使用的各种问题
# 1.9.1
- [ ] 如果UDP映射服务端端口变动,流量统计似乎不准,转发功能或许也受到影响,需要评估、测试、思考如何优化
- [ ] 增加服务端/客户端jar式一键部署脚本
- [ ] 排查解决问题:https://gitee.com/dromara/neutrino-proxy/issues/I7LGLB
- [ ] 访问白名单
- [ ] 端口映射分组
# Bug
- 指令通达被close的问题,org.dromara.neutrinoproxy.server.proxy.core.ProxyTunnelChannelHandler.channelInactive
- windows环境下直接运行发布版的jar包,日志输出乱码
- 代理mysql时,使用未开启远程访问的账号走代理访问mysql,代理客户端出现断开现象
- 客户端连接映射某个端口以后,如果在服务器端禁用了,没有立刻反映出来,要灯客户端重连以后才会屏蔽被禁用的端口。
# 2.x规划
- 插件开发
- [ ] neutrino-proxy-solon-plugin
- [ ] neutrino-proxy-jetbrains-plugin
- [ ] neutrino-proxy-starter (SpringBoot)
- 思考
- 流量编排
- 插件化定制
- 重构
- 代码重构
- 多租户支持
- 多个代理服务端节点支持
- 协议重构
- 支持多个隧道协议,支持扩展(TCP、KCP、QUIC)
- 支持不同语言客户端、服务端接入
- 基础优化
- [ ] 访问白名单
- [ ] 端口映射分组
- [ ] 支持批量端口映射
- [ ] 代理协议规范化,方便后续更好扩展、支持不同语言客户端接入
- [ ] 如果UDP映射服务端端口变动,流量统计似乎不准,转发功能或许也受到影响,需要评估、测试、思考如何优化
- [ ] 排查解决问题:https://gitee.com/dromara/neutrino-proxy/issues/I7LGLB
- 监控运维
- [ ] 监控服务端状态
- [ ] 支持调整服务端端口、证书
@@ -56,11 +23,14 @@
- [ ] 服务端日志
- [ ] 支持持管理后台动态调整日志级别。
- [ ] 动态调整转发、报文、心跳输出
- client+计划启动
- [ ] 安卓客户端
- [ ] 基于electron-egg的多平台客户端
# 3.x规划
- [ ] 支持针对用户限速、限流
- [ ] 支持P2P穿透
- [ ] 支持原生编译
- 插件开发
- [ ] neutrino-proxy-solon-plugin
- [ ] neutrino-proxy-jetbrains-plugin
- [ ] neutrino-proxy-starter (SpringBoot)
- client+计划启动
- [ ] 安卓客户端
- [ ] 基于electron-egg的多平台客户端
-7
View File
@@ -1,7 +0,0 @@
以下为部分使用中机构/组织/个人:
---
|单位/组织名称| 主营业务描述 |使用中微子的主要用途|
|:----|:----------|:--------|
|常州裕景信息科技有限公司| 高校数字化软件建设 |统筹管理个单位的服务器|