Skip to content
Toggle navigation
P
Projects
G
Groups
S
Snippets
Help
phsl
/
new-api
This project
Loading...
Sign in
Toggle navigation
Go to a project
Project
Repository
Issues
0
Merge Requests
0
Pipelines
Wiki
Snippets
Members
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Commit
d326e88a
authored
Oct 10, 2025
by
Calcium-Ion
Committed by
GitHub
Oct 10, 2025
Browse files
Options
Browse Files
Download
Plain Diff
Merge commit from fork
feat: enhance HTTP client wit redirect handling and SSRF protection
parents
40aa5490
bdb52202
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
22 additions
and
4 deletions
+22
-4
service/download.go
+2
-2
service/http_client.go
+20
-2
No files found.
service/download.go
View file @
d326e88a
...
...
@@ -45,7 +45,7 @@ func DoWorkerRequest(req *WorkerRequest) (*http.Response, error) {
return
nil
,
fmt
.
Errorf
(
"failed to marshal worker payload: %v"
,
err
)
}
return
http
.
Post
(
workerUrl
,
"application/json"
,
bytes
.
NewBuffer
(
workerPayload
))
return
GetHttpClient
()
.
Post
(
workerUrl
,
"application/json"
,
bytes
.
NewBuffer
(
workerPayload
))
}
func
DoDownloadRequest
(
originUrl
string
,
reason
...
string
)
(
resp
*
http
.
Response
,
err
error
)
{
...
...
@@ -64,6 +64,6 @@ func DoDownloadRequest(originUrl string, reason ...string) (resp *http.Response,
}
common
.
SysLog
(
fmt
.
Sprintf
(
"downloading from origin: %s, reason: %s"
,
common
.
MaskSensitiveInfo
(
originUrl
),
strings
.
Join
(
reason
,
", "
)))
return
http
.
Get
(
originUrl
)
return
GetHttpClient
()
.
Get
(
originUrl
)
}
}
service/http_client.go
View file @
d326e88a
...
...
@@ -7,6 +7,7 @@ import (
"net/http"
"net/url"
"one-api/common"
"one-api/setting/system_setting"
"sync"
"time"
...
...
@@ -19,12 +20,27 @@ var (
proxyClients
=
make
(
map
[
string
]
*
http
.
Client
)
)
func
checkRedirect
(
req
*
http
.
Request
,
via
[]
*
http
.
Request
)
error
{
fetchSetting
:=
system_setting
.
GetFetchSetting
()
urlStr
:=
req
.
URL
.
String
()
if
err
:=
common
.
ValidateURLWithFetchSetting
(
urlStr
,
fetchSetting
.
EnableSSRFProtection
,
fetchSetting
.
AllowPrivateIp
,
fetchSetting
.
DomainFilterMode
,
fetchSetting
.
IpFilterMode
,
fetchSetting
.
DomainList
,
fetchSetting
.
IpList
,
fetchSetting
.
AllowedPorts
,
fetchSetting
.
ApplyIPFilterForDomain
);
err
!=
nil
{
return
fmt
.
Errorf
(
"redirect to %s blocked: %v"
,
urlStr
,
err
)
}
if
len
(
via
)
>=
10
{
return
fmt
.
Errorf
(
"stopped after 10 redirects"
)
}
return
nil
}
func
InitHttpClient
()
{
if
common
.
RelayTimeout
==
0
{
httpClient
=
&
http
.
Client
{}
httpClient
=
&
http
.
Client
{
CheckRedirect
:
checkRedirect
,
}
}
else
{
httpClient
=
&
http
.
Client
{
Timeout
:
time
.
Duration
(
common
.
RelayTimeout
)
*
time
.
Second
,
Timeout
:
time
.
Duration
(
common
.
RelayTimeout
)
*
time
.
Second
,
CheckRedirect
:
checkRedirect
,
}
}
}
...
...
@@ -69,6 +85,7 @@ func NewProxyHttpClient(proxyURL string) (*http.Client, error) {
Transport
:
&
http
.
Transport
{
Proxy
:
http
.
ProxyURL
(
parsedURL
),
},
CheckRedirect
:
checkRedirect
,
}
client
.
Timeout
=
time
.
Duration
(
common
.
RelayTimeout
)
*
time
.
Second
proxyClientLock
.
Lock
()
...
...
@@ -102,6 +119,7 @@ func NewProxyHttpClient(proxyURL string) (*http.Client, error) {
return
dialer
.
Dial
(
network
,
addr
)
},
},
CheckRedirect
:
checkRedirect
,
}
client
.
Timeout
=
time
.
Duration
(
common
.
RelayTimeout
)
*
time
.
Second
proxyClientLock
.
Lock
()
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment