Skip to content
Toggle navigation
P
Projects
G
Groups
S
Snippets
Help
phsl
/
new-api
This project
Loading...
Sign in
Toggle navigation
Go to a project
Project
Repository
Issues
0
Merge Requests
0
Pipelines
Wiki
Snippets
Members
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Commit
bdb52202
authored
Oct 10, 2025
by
CaIon
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
feat: enhance HTTP client with custom redirect handling and SSRF protection
parent
30112005
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
22 additions
and
4 deletions
+22
-4
service/download.go
+2
-2
service/http_client.go
+20
-2
No files found.
service/download.go
View file @
bdb52202
...
...
@@ -45,7 +45,7 @@ func DoWorkerRequest(req *WorkerRequest) (*http.Response, error) {
return
nil
,
fmt
.
Errorf
(
"failed to marshal worker payload: %v"
,
err
)
}
return
http
.
Post
(
workerUrl
,
"application/json"
,
bytes
.
NewBuffer
(
workerPayload
))
return
GetHttpClient
()
.
Post
(
workerUrl
,
"application/json"
,
bytes
.
NewBuffer
(
workerPayload
))
}
func
DoDownloadRequest
(
originUrl
string
,
reason
...
string
)
(
resp
*
http
.
Response
,
err
error
)
{
...
...
@@ -64,6 +64,6 @@ func DoDownloadRequest(originUrl string, reason ...string) (resp *http.Response,
}
common
.
SysLog
(
fmt
.
Sprintf
(
"downloading from origin: %s, reason: %s"
,
common
.
MaskSensitiveInfo
(
originUrl
),
strings
.
Join
(
reason
,
", "
)))
return
http
.
Get
(
originUrl
)
return
GetHttpClient
()
.
Get
(
originUrl
)
}
}
service/http_client.go
View file @
bdb52202
...
...
@@ -7,6 +7,7 @@ import (
"net/http"
"net/url"
"one-api/common"
"one-api/setting/system_setting"
"sync"
"time"
...
...
@@ -19,12 +20,27 @@ var (
proxyClients
=
make
(
map
[
string
]
*
http
.
Client
)
)
func
checkRedirect
(
req
*
http
.
Request
,
via
[]
*
http
.
Request
)
error
{
fetchSetting
:=
system_setting
.
GetFetchSetting
()
urlStr
:=
req
.
URL
.
String
()
if
err
:=
common
.
ValidateURLWithFetchSetting
(
urlStr
,
fetchSetting
.
EnableSSRFProtection
,
fetchSetting
.
AllowPrivateIp
,
fetchSetting
.
DomainFilterMode
,
fetchSetting
.
IpFilterMode
,
fetchSetting
.
DomainList
,
fetchSetting
.
IpList
,
fetchSetting
.
AllowedPorts
,
fetchSetting
.
ApplyIPFilterForDomain
);
err
!=
nil
{
return
fmt
.
Errorf
(
"redirect to %s blocked: %v"
,
urlStr
,
err
)
}
if
len
(
via
)
>=
10
{
return
fmt
.
Errorf
(
"stopped after 10 redirects"
)
}
return
nil
}
func
InitHttpClient
()
{
if
common
.
RelayTimeout
==
0
{
httpClient
=
&
http
.
Client
{}
httpClient
=
&
http
.
Client
{
CheckRedirect
:
checkRedirect
,
}
}
else
{
httpClient
=
&
http
.
Client
{
Timeout
:
time
.
Duration
(
common
.
RelayTimeout
)
*
time
.
Second
,
Timeout
:
time
.
Duration
(
common
.
RelayTimeout
)
*
time
.
Second
,
CheckRedirect
:
checkRedirect
,
}
}
}
...
...
@@ -69,6 +85,7 @@ func NewProxyHttpClient(proxyURL string) (*http.Client, error) {
Transport
:
&
http
.
Transport
{
Proxy
:
http
.
ProxyURL
(
parsedURL
),
},
CheckRedirect
:
checkRedirect
,
}
client
.
Timeout
=
time
.
Duration
(
common
.
RelayTimeout
)
*
time
.
Second
proxyClientLock
.
Lock
()
...
...
@@ -102,6 +119,7 @@ func NewProxyHttpClient(proxyURL string) (*http.Client, error) {
return
dialer
.
Dial
(
network
,
addr
)
},
},
CheckRedirect
:
checkRedirect
,
}
client
.
Timeout
=
time
.
Duration
(
common
.
RelayTimeout
)
*
time
.
Second
proxyClientLock
.
Lock
()
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment