engine.go 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265
  1. package rest
  2. import (
  3. "crypto/tls"
  4. "errors"
  5. "fmt"
  6. "net/http"
  7. "time"
  8. "github.com/justinas/alice"
  9. "github.com/zeromicro/go-zero/core/codec"
  10. "github.com/zeromicro/go-zero/core/load"
  11. "github.com/zeromicro/go-zero/core/stat"
  12. "github.com/zeromicro/go-zero/rest/handler"
  13. "github.com/zeromicro/go-zero/rest/httpx"
  14. "github.com/zeromicro/go-zero/rest/internal"
  15. "github.com/zeromicro/go-zero/rest/internal/response"
  16. )
  17. // use 1000m to represent 100%
  18. const topCpuUsage = 1000
  19. // ErrSignatureConfig is an error that indicates bad config for signature.
  20. var ErrSignatureConfig = errors.New("bad config for Signature")
  21. type engine struct {
  22. conf RestConf
  23. routes []featuredRoutes
  24. unauthorizedCallback handler.UnauthorizedCallback
  25. unsignedCallback handler.UnsignedCallback
  26. middlewares []Middleware
  27. shedder load.Shedder
  28. priorityShedder load.Shedder
  29. tlsConfig *tls.Config
  30. }
  31. func newEngine(c RestConf) *engine {
  32. svr := &engine{
  33. conf: c,
  34. }
  35. if c.CpuThreshold > 0 {
  36. svr.shedder = load.NewAdaptiveShedder(load.WithCpuThreshold(c.CpuThreshold))
  37. svr.priorityShedder = load.NewAdaptiveShedder(load.WithCpuThreshold(
  38. (c.CpuThreshold + topCpuUsage) >> 1))
  39. }
  40. return svr
  41. }
  42. func (ng *engine) addRoutes(r featuredRoutes) {
  43. ng.routes = append(ng.routes, r)
  44. }
  45. func (ng *engine) appendAuthHandler(fr featuredRoutes, chain alice.Chain,
  46. verifier func(alice.Chain) alice.Chain) alice.Chain {
  47. if fr.jwt.enabled {
  48. if len(fr.jwt.prevSecret) == 0 {
  49. chain = chain.Append(handler.Authorize(fr.jwt.secret,
  50. handler.WithUnauthorizedCallback(ng.unauthorizedCallback)))
  51. } else {
  52. chain = chain.Append(handler.Authorize(fr.jwt.secret,
  53. handler.WithPrevSecret(fr.jwt.prevSecret),
  54. handler.WithUnauthorizedCallback(ng.unauthorizedCallback)))
  55. }
  56. }
  57. return verifier(chain)
  58. }
  59. func (ng *engine) bindFeaturedRoutes(router httpx.Router, fr featuredRoutes, metrics *stat.Metrics) error {
  60. verifier, err := ng.signatureVerifier(fr.signature)
  61. if err != nil {
  62. return err
  63. }
  64. for _, route := range fr.routes {
  65. if err := ng.bindRoute(fr, router, metrics, route, verifier); err != nil {
  66. return err
  67. }
  68. }
  69. return nil
  70. }
  71. func (ng *engine) bindRoute(fr featuredRoutes, router httpx.Router, metrics *stat.Metrics,
  72. route Route, verifier func(chain alice.Chain) alice.Chain) error {
  73. chain := alice.New(
  74. handler.TracingHandler(ng.conf.Name, route.Path),
  75. ng.getLogHandler(),
  76. handler.PrometheusHandler(route.Path),
  77. handler.MaxConns(ng.conf.MaxConns),
  78. handler.BreakerHandler(route.Method, route.Path, metrics),
  79. handler.SheddingHandler(ng.getShedder(fr.priority), metrics),
  80. handler.TimeoutHandler(ng.checkedTimeout(fr.timeout)),
  81. handler.RecoverHandler,
  82. handler.MetricHandler(metrics),
  83. handler.MaxBytesHandler(ng.checkedMaxBytes(fr.maxBytes)),
  84. handler.GunzipHandler,
  85. )
  86. chain = ng.appendAuthHandler(fr, chain, verifier)
  87. for _, middleware := range ng.middlewares {
  88. chain = chain.Append(convertMiddleware(middleware))
  89. }
  90. handle := chain.ThenFunc(route.Handler)
  91. return router.Handle(route.Method, route.Path, handle)
  92. }
  93. func (ng *engine) bindRoutes(router httpx.Router) error {
  94. metrics := ng.createMetrics()
  95. for _, fr := range ng.routes {
  96. if err := ng.bindFeaturedRoutes(router, fr, metrics); err != nil {
  97. return err
  98. }
  99. }
  100. return nil
  101. }
  102. func (ng *engine) checkedTimeout(timeout time.Duration) time.Duration {
  103. if timeout > 0 {
  104. return timeout
  105. }
  106. return time.Duration(ng.conf.Timeout) * time.Millisecond
  107. }
  108. func (ng *engine) checkedMaxBytes(bytes int64) int64 {
  109. if bytes > 0 {
  110. return bytes
  111. }
  112. return ng.conf.MaxBytes
  113. }
  114. func (ng *engine) createMetrics() *stat.Metrics {
  115. var metrics *stat.Metrics
  116. if len(ng.conf.Name) > 0 {
  117. metrics = stat.NewMetrics(ng.conf.Name)
  118. } else {
  119. metrics = stat.NewMetrics(fmt.Sprintf("%s:%d", ng.conf.Host, ng.conf.Port))
  120. }
  121. return metrics
  122. }
  123. func (ng *engine) getLogHandler() func(http.Handler) http.Handler {
  124. if ng.conf.Verbose {
  125. return handler.DetailedLogHandler
  126. }
  127. return handler.LogHandler
  128. }
  129. func (ng *engine) getShedder(priority bool) load.Shedder {
  130. if priority && ng.priorityShedder != nil {
  131. return ng.priorityShedder
  132. }
  133. return ng.shedder
  134. }
  135. // notFoundHandler returns a middleware that handles 404 not found requests.
  136. func (ng *engine) notFoundHandler(next http.Handler) http.Handler {
  137. return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
  138. chain := alice.New(
  139. handler.TracingHandler(ng.conf.Name, ""),
  140. ng.getLogHandler(),
  141. )
  142. var h http.Handler
  143. if next != nil {
  144. h = chain.Then(next)
  145. } else {
  146. h = chain.Then(http.NotFoundHandler())
  147. }
  148. cw := response.NewHeaderOnceResponseWriter(w)
  149. h.ServeHTTP(cw, r)
  150. cw.WriteHeader(http.StatusNotFound)
  151. })
  152. }
  153. func (ng *engine) setTlsConfig(cfg *tls.Config) {
  154. ng.tlsConfig = cfg
  155. }
  156. func (ng *engine) setUnauthorizedCallback(callback handler.UnauthorizedCallback) {
  157. ng.unauthorizedCallback = callback
  158. }
  159. func (ng *engine) setUnsignedCallback(callback handler.UnsignedCallback) {
  160. ng.unsignedCallback = callback
  161. }
  162. func (ng *engine) signatureVerifier(signature signatureSetting) (func(chain alice.Chain) alice.Chain, error) {
  163. if !signature.enabled {
  164. return func(chain alice.Chain) alice.Chain {
  165. return chain
  166. }, nil
  167. }
  168. if len(signature.PrivateKeys) == 0 {
  169. if signature.Strict {
  170. return nil, ErrSignatureConfig
  171. }
  172. return func(chain alice.Chain) alice.Chain {
  173. return chain
  174. }, nil
  175. }
  176. decrypters := make(map[string]codec.RsaDecrypter)
  177. for _, key := range signature.PrivateKeys {
  178. fingerprint := key.Fingerprint
  179. file := key.KeyFile
  180. decrypter, err := codec.NewRsaDecrypter(file)
  181. if err != nil {
  182. return nil, err
  183. }
  184. decrypters[fingerprint] = decrypter
  185. }
  186. return func(chain alice.Chain) alice.Chain {
  187. if ng.unsignedCallback != nil {
  188. return chain.Append(handler.ContentSecurityHandler(
  189. decrypters, signature.Expiry, signature.Strict, ng.unsignedCallback))
  190. }
  191. return chain.Append(handler.ContentSecurityHandler(
  192. decrypters, signature.Expiry, signature.Strict))
  193. }, nil
  194. }
  195. func (ng *engine) start(router httpx.Router) error {
  196. if err := ng.bindRoutes(router); err != nil {
  197. return err
  198. }
  199. if len(ng.conf.CertFile) == 0 && len(ng.conf.KeyFile) == 0 {
  200. return internal.StartHttp(ng.conf.Host, ng.conf.Port, router)
  201. }
  202. return internal.StartHttps(ng.conf.Host, ng.conf.Port, ng.conf.CertFile,
  203. ng.conf.KeyFile, router, func(svr *http.Server) {
  204. if ng.tlsConfig != nil {
  205. svr.TLSConfig = ng.tlsConfig
  206. }
  207. })
  208. }
  209. func (ng *engine) use(middleware Middleware) {
  210. ng.middlewares = append(ng.middlewares, middleware)
  211. }
  212. func convertMiddleware(ware Middleware) func(http.Handler) http.Handler {
  213. return func(next http.Handler) http.Handler {
  214. return ware(next.ServeHTTP)
  215. }
  216. }