# Copyright, 2018, by Samuel G. D. Williams. <http://www.codeotaku.com># # Permission is hereby granted, free of charge, to any person obtaining a copy# of this software and associated documentation files (the "Software"), to deal# in the Software without restriction, including without limitation the rights# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell# copies of the Software, and to permit persons to whom the Software is# furnished to do so, subject to the following conditions:# # The above copyright notice and this permission notice shall be included in# all copies or substantial portions of the Software.# # THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN# THE SOFTWARE.require'async/io/endpoint'require_relative'host'require_relative'proxy'require_relative'redirection'require'async/container'require'async/container/controller'require'async/http/endpoint'moduleFalconclassHostsSERVER_CIPHERS="EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5".freezedefinitialize(configuration)@named={}@server_context=nil@server_endpoint=nilconfiguration.each(:authority)do|environment|add(Host.new(environment))endenddefeach(&block)@named.each_value(&block)enddefendpoint@server_endpoint||=Async::HTTP::Endpoint.parse('https://[::]',ssl_context: self.ssl_context,reuse_address: true)enddefssl_context@server_context||=OpenSSL::SSL::SSLContext.new.tapdo|context|context.servername_cb=Proc.newdo|socket,hostname|self.host_context(socket,hostname)endcontext.session_id_context="falcon"context.set_params(ciphers: SERVER_CIPHERS,verify_mode: OpenSSL::SSL::VERIFY_NONE,)context.setupendenddefhost_context(socket,hostname)ifhost=@named[hostname]Async.logger.debug(self){"Resolving #{hostname} -> #{host}"}socket.hostname=hostnamereturnhost.ssl_contextelseAsync.logger.warn(self){"Unable to resolve #{hostname}!"}returnnilendenddefadd(host)@named[host.authority]=hostenddefproxyProxy.new(Falcon::BadRequest,@named)enddefredirection(secure_endpoint)Redirection.new(Falcon::BadRequest,@named,secure_endpoint)enddefrun(container=Async::Container.new,**options)secure_endpoint=Async::HTTP::Endpoint.parse(options[:bind_secure],ssl_context: self.ssl_context)insecure_endpoint=Async::HTTP::Endpoint.parse(options[:bind_insecure])secure_endpoint_bound=insecure_endpoint_bound=nilAsync::Reactor.rundosecure_endpoint_bound=Async::IO::SharedEndpoint.bound(secure_endpoint)insecure_endpoint_bound=Async::IO::SharedEndpoint.bound(insecure_endpoint)end.waitcontainer.run(name: "Falcon Proxy",restart: true)do|task,instance|proxy=self.proxyproxy_server=Falcon::Server.new(proxy,secure_endpoint_bound,secure_endpoint.protocol,secure_endpoint.scheme)proxy_server.runendcontainer.run(name: "Falcon Redirector",restart: true)do|task,instance|redirection=self.redirection(secure_endpoint)redirection_server=Falcon::Server.new(redirection,insecure_endpoint_bound,insecure_endpoint.protocol,insecure_endpoint.scheme)redirection_server.runendcontainer.attachdosecure_endpoint_bound.closeinsecure_endpoint_bound.closeendreturncontainerendendend