HttpClientHandler.cs 9.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250
  1. using FastGithub.Configuration;
  2. using FastGithub.DomainResolve;
  3. using System;
  4. using System.Collections;
  5. using System.Collections.Generic;
  6. using System.IO;
  7. using System.Linq;
  8. using System.Net;
  9. using System.Net.Http;
  10. using System.Net.Security;
  11. using System.Net.Sockets;
  12. using System.Runtime.CompilerServices;
  13. using System.Security.Cryptography.X509Certificates;
  14. using System.Threading;
  15. using System.Threading.Tasks;
  16. namespace FastGithub.Http
  17. {
  18. /// <summary>
  19. /// HttpClientHandler
  20. /// </summary>
  21. class HttpClientHandler : DelegatingHandler
  22. {
  23. private readonly IDomainResolver domainResolver;
  24. private readonly TimeSpan connectTimeout = TimeSpan.FromSeconds(10d);
  25. /// <summary>
  26. /// 获取域名配置
  27. /// </summary>
  28. public DomainConfig DomainConfig { get; }
  29. /// <summary>
  30. /// HttpClientHandler
  31. /// </summary>
  32. /// <param name="domainConfig"></param>
  33. /// <param name="domainResolver"></param>
  34. public HttpClientHandler(DomainConfig domainConfig, IDomainResolver domainResolver)
  35. {
  36. this.domainResolver = domainResolver;
  37. this.DomainConfig = domainConfig;
  38. this.InnerHandler = this.CreateSocketsHttpHandler();
  39. }
  40. /// <summary>
  41. /// 发送请求
  42. /// </summary>
  43. /// <param name="request"></param>
  44. /// <param name="cancellationToken"></param>
  45. /// <returns></returns>
  46. protected override async Task<HttpResponseMessage> SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)
  47. {
  48. var uri = request.RequestUri;
  49. if (uri == null)
  50. {
  51. throw new FastGithubException("必须指定请求的URI");
  52. }
  53. // 请求上下文信息
  54. var isHttps = uri.Scheme == Uri.UriSchemeHttps;
  55. var tlsSniValue = this.DomainConfig.GetTlsSniPattern().WithDomain(uri.Host).WithRandom();
  56. request.SetRequestContext(new RequestContext(isHttps, tlsSniValue));
  57. // 设置请求头host,修改协议为http
  58. request.Headers.Host = uri.Host;
  59. request.RequestUri = new UriBuilder(uri) { Scheme = Uri.UriSchemeHttp }.Uri;
  60. if (this.DomainConfig.Timeout != null)
  61. {
  62. using var timeoutTokenSource = new CancellationTokenSource(this.DomainConfig.Timeout.Value);
  63. using var linkedTokenSource = CancellationTokenSource.CreateLinkedTokenSource(cancellationToken, timeoutTokenSource.Token);
  64. return await base.SendAsync(request, linkedTokenSource.Token);
  65. }
  66. return await base.SendAsync(request, cancellationToken);
  67. }
  68. /// <summary>
  69. /// 创建转发代理的httpHandler
  70. /// </summary>
  71. /// <returns></returns>
  72. private SocketsHttpHandler CreateSocketsHttpHandler()
  73. {
  74. return new SocketsHttpHandler
  75. {
  76. Proxy = null,
  77. UseProxy = false,
  78. UseCookies = false,
  79. AllowAutoRedirect = false,
  80. AutomaticDecompression = DecompressionMethods.None,
  81. ConnectCallback = this.ConnectCallback
  82. };
  83. }
  84. /// <summary>
  85. /// 连接回调
  86. /// </summary>
  87. /// <param name="context"></param>
  88. /// <param name="cancellationToken"></param>
  89. /// <returns></returns>
  90. private async ValueTask<Stream> ConnectCallback(SocketsHttpConnectionContext context, CancellationToken cancellationToken)
  91. {
  92. var innerExceptions = new List<Exception>();
  93. var ipEndPoints = this.GetIPEndPointsAsync(context.DnsEndPoint, cancellationToken);
  94. await foreach (var ipEndPoint in ipEndPoints)
  95. {
  96. try
  97. {
  98. using var timeoutTokenSource = new CancellationTokenSource(this.connectTimeout);
  99. using var linkedTokenSource = CancellationTokenSource.CreateLinkedTokenSource(timeoutTokenSource.Token, cancellationToken);
  100. return await this.ConnectAsync(context, ipEndPoint, linkedTokenSource.Token);
  101. }
  102. catch (OperationCanceledException)
  103. {
  104. cancellationToken.ThrowIfCancellationRequested();
  105. innerExceptions.Add(new SocketException((int)SocketError.TimedOut));
  106. }
  107. catch (Exception ex)
  108. {
  109. innerExceptions.Add(ex);
  110. }
  111. }
  112. throw new AggregateException("找不到任何可成功连接的IP", innerExceptions);
  113. }
  114. /// <summary>
  115. /// 建立连接
  116. /// </summary>
  117. /// <param name="context"></param>
  118. /// <param name="ipEndPoint"></param>
  119. /// <param name="cancellationToken"></param>
  120. /// <returns></returns>
  121. private async ValueTask<Stream> ConnectAsync(SocketsHttpConnectionContext context, IPEndPoint ipEndPoint, CancellationToken cancellationToken)
  122. {
  123. var socket = new Socket(SocketType.Stream, ProtocolType.Tcp);
  124. await socket.ConnectAsync(ipEndPoint, cancellationToken);
  125. var stream = new NetworkStream(socket, ownsSocket: true);
  126. var requestContext = context.InitialRequestMessage.GetRequestContext();
  127. if (requestContext.IsHttps == false)
  128. {
  129. return stream;
  130. }
  131. var tlsSniValue = requestContext.TlsSniValue.WithIPAddress(ipEndPoint.Address);
  132. var sslStream = new SslStream(stream, leaveInnerStreamOpen: false);
  133. await sslStream.AuthenticateAsClientAsync(new SslClientAuthenticationOptions
  134. {
  135. TargetHost = tlsSniValue.Value,
  136. RemoteCertificateValidationCallback = ValidateServerCertificate
  137. }, cancellationToken);
  138. return sslStream;
  139. // 验证证书有效性
  140. bool ValidateServerCertificate(object sender, X509Certificate? cert, X509Chain? chain, SslPolicyErrors errors)
  141. {
  142. if (errors.HasFlag(SslPolicyErrors.RemoteCertificateNameMismatch))
  143. {
  144. if (this.DomainConfig.TlsIgnoreNameMismatch == true)
  145. {
  146. return true;
  147. }
  148. var domain = context.DnsEndPoint.Host;
  149. var dnsNames = ReadDnsNames(cert);
  150. return dnsNames.Any(dns => IsMatch(dns, domain));
  151. }
  152. return errors == SslPolicyErrors.None;
  153. }
  154. }
  155. /// <summary>
  156. /// 解析为IPEndPoint
  157. /// </summary>
  158. /// <param name="dnsEndPoint"></param>
  159. /// <param name="cancellationToken"></param>
  160. /// <returns></returns>
  161. private async IAsyncEnumerable<IPEndPoint> GetIPEndPointsAsync(DnsEndPoint dnsEndPoint, [EnumeratorCancellation] CancellationToken cancellationToken)
  162. {
  163. if (IPAddress.TryParse(this.DomainConfig.IPAddress, out var address) ||
  164. IPAddress.TryParse(dnsEndPoint.Host, out address))
  165. {
  166. yield return new IPEndPoint(address, dnsEndPoint.Port);
  167. }
  168. else
  169. {
  170. await foreach (var item in this.domainResolver.ResolveAllAsync(dnsEndPoint, cancellationToken))
  171. {
  172. yield return new IPEndPoint(item, dnsEndPoint.Port);
  173. }
  174. }
  175. }
  176. /// <summary>
  177. /// 读取使用的DNS名称
  178. /// </summary>
  179. /// <param name="cert"></param>
  180. /// <returns></returns>
  181. private static IEnumerable<string> ReadDnsNames(X509Certificate? cert)
  182. {
  183. if (cert == null)
  184. {
  185. yield break;
  186. }
  187. var parser = new Org.BouncyCastle.X509.X509CertificateParser();
  188. var x509Cert = parser.ReadCertificate(cert.GetRawCertData());
  189. var subjects = x509Cert.GetSubjectAlternativeNames();
  190. foreach (var subject in subjects)
  191. {
  192. if (subject is IList list)
  193. {
  194. if (list.Count >= 2 && list[0] is int nameType && nameType == 2)
  195. {
  196. var dnsName = list[1]?.ToString();
  197. if (dnsName != null)
  198. {
  199. yield return dnsName;
  200. }
  201. }
  202. }
  203. }
  204. }
  205. /// <summary>
  206. /// 比较域名
  207. /// </summary>
  208. /// <param name="dnsName"></param>
  209. /// <param name="domain"></param>
  210. /// <returns></returns>
  211. private static bool IsMatch(string dnsName, string? domain)
  212. {
  213. if (domain == null)
  214. {
  215. return false;
  216. }
  217. if (dnsName == domain)
  218. {
  219. return true;
  220. }
  221. if (dnsName[0] == '*')
  222. {
  223. return domain.EndsWith(dnsName[1..]);
  224. }
  225. return false;
  226. }
  227. }
  228. }