HttpClientHandler.cs 8.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236
  1. using FastGithub.Configuration;
  2. using FastGithub.DomainResolve;
  3. using System;
  4. using System.Collections.Generic;
  5. using System.IO;
  6. using System.Linq;
  7. using System.Net;
  8. using System.Net.Http;
  9. using System.Net.Security;
  10. using System.Net.Sockets;
  11. using System.Runtime.CompilerServices;
  12. using System.Security.Cryptography.X509Certificates;
  13. using System.Threading;
  14. using System.Threading.Tasks;
  15. namespace FastGithub.Http
  16. {
  17. /// <summary>
  18. /// HttpClientHandler
  19. /// </summary>
  20. class HttpClientHandler : DelegatingHandler
  21. {
  22. private readonly DomainConfig domainConfig;
  23. private readonly IDomainResolver domainResolver;
  24. private readonly TimeSpan connectTimeout = TimeSpan.FromSeconds(10d);
  25. /// <summary>
  26. /// HttpClientHandler
  27. /// </summary>
  28. /// <param name="domainConfig"></param>
  29. /// <param name="domainResolver"></param>
  30. public HttpClientHandler(DomainConfig domainConfig, IDomainResolver domainResolver)
  31. {
  32. this.domainConfig = domainConfig;
  33. this.domainResolver = domainResolver;
  34. this.InnerHandler = this.CreateSocketsHttpHandler();
  35. }
  36. /// <summary>
  37. /// 发送请求
  38. /// </summary>
  39. /// <param name="request"></param>
  40. /// <param name="cancellationToken"></param>
  41. /// <returns></returns>
  42. protected override async Task<HttpResponseMessage> SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)
  43. {
  44. var uri = request.RequestUri;
  45. if (uri == null)
  46. {
  47. throw new FastGithubException("必须指定请求的URI");
  48. }
  49. // 请求上下文信息
  50. var isHttps = uri.Scheme == Uri.UriSchemeHttps;
  51. var tlsSniValue = this.domainConfig.GetTlsSniPattern().WithDomain(uri.Host).WithRandom();
  52. request.SetRequestContext(new RequestContext(isHttps, tlsSniValue));
  53. // 设置请求头host,修改协议为http
  54. request.Headers.Host = uri.Host;
  55. request.RequestUri = new UriBuilder(uri) { Scheme = Uri.UriSchemeHttp }.Uri;
  56. if (this.domainConfig.Timeout != null)
  57. {
  58. using var timeoutTokenSource = new CancellationTokenSource(this.domainConfig.Timeout.Value);
  59. using var linkedTokenSource = CancellationTokenSource.CreateLinkedTokenSource(cancellationToken, timeoutTokenSource.Token);
  60. return await base.SendAsync(request, linkedTokenSource.Token);
  61. }
  62. return await base.SendAsync(request, cancellationToken);
  63. }
  64. /// <summary>
  65. /// 创建转发代理的httpHandler
  66. /// </summary>
  67. /// <returns></returns>
  68. private SocketsHttpHandler CreateSocketsHttpHandler()
  69. {
  70. return new SocketsHttpHandler
  71. {
  72. Proxy = null,
  73. UseProxy = false,
  74. UseCookies = false,
  75. AllowAutoRedirect = false,
  76. AutomaticDecompression = DecompressionMethods.None,
  77. ConnectCallback = this.ConnectCallback
  78. };
  79. }
  80. /// <summary>
  81. /// 连接回调
  82. /// </summary>
  83. /// <param name="context"></param>
  84. /// <param name="cancellationToken"></param>
  85. /// <returns></returns>
  86. private async ValueTask<Stream> ConnectCallback(SocketsHttpConnectionContext context, CancellationToken cancellationToken)
  87. {
  88. var innerExceptions = new List<Exception>();
  89. var ipEndPoints = this.GetIPEndPointsAsync(context.DnsEndPoint, cancellationToken);
  90. await foreach (var ipEndPoint in ipEndPoints)
  91. {
  92. try
  93. {
  94. using var timeoutTokenSource = new CancellationTokenSource(this.connectTimeout);
  95. using var linkedTokenSource = CancellationTokenSource.CreateLinkedTokenSource(timeoutTokenSource.Token, cancellationToken);
  96. return await this.ConnectAsync(context, ipEndPoint, linkedTokenSource.Token);
  97. }
  98. catch (OperationCanceledException)
  99. {
  100. cancellationToken.ThrowIfCancellationRequested();
  101. innerExceptions.Add(new HttpConnectTimeoutException(ipEndPoint.Address));
  102. }
  103. catch (Exception ex)
  104. {
  105. innerExceptions.Add(ex);
  106. }
  107. }
  108. throw new AggregateException("找不到任何可成功连接的IP", innerExceptions);
  109. }
  110. /// <summary>
  111. /// 建立连接
  112. /// </summary>
  113. /// <param name="context"></param>
  114. /// <param name="ipEndPoint"></param>
  115. /// <param name="cancellationToken"></param>
  116. /// <returns></returns>
  117. private async ValueTask<Stream> ConnectAsync(SocketsHttpConnectionContext context, IPEndPoint ipEndPoint, CancellationToken cancellationToken)
  118. {
  119. var socket = new Socket(ipEndPoint.AddressFamily, SocketType.Stream, ProtocolType.Tcp);
  120. await socket.ConnectAsync(ipEndPoint, cancellationToken);
  121. var stream = new NetworkStream(socket, ownsSocket: true);
  122. var requestContext = context.InitialRequestMessage.GetRequestContext();
  123. if (requestContext.IsHttps == false)
  124. {
  125. return stream;
  126. }
  127. var tlsSniValue = requestContext.TlsSniValue.WithIPAddress(ipEndPoint.Address);
  128. var sslStream = new SslStream(stream, leaveInnerStreamOpen: false);
  129. await sslStream.AuthenticateAsClientAsync(new SslClientAuthenticationOptions
  130. {
  131. TargetHost = tlsSniValue.Value,
  132. RemoteCertificateValidationCallback = ValidateServerCertificate
  133. }, cancellationToken);
  134. return sslStream;
  135. // 验证证书有效性
  136. bool ValidateServerCertificate(object sender, X509Certificate? cert, X509Chain? chain, SslPolicyErrors errors)
  137. {
  138. if (errors.HasFlag(SslPolicyErrors.RemoteCertificateNameMismatch))
  139. {
  140. if (this.domainConfig.TlsIgnoreNameMismatch == true)
  141. {
  142. return true;
  143. }
  144. var domain = context.DnsEndPoint.Host;
  145. var dnsNames = ReadDnsNames(cert);
  146. return dnsNames.Any(dns => IsMatch(dns, domain));
  147. }
  148. return errors == SslPolicyErrors.None;
  149. }
  150. }
  151. /// <summary>
  152. /// 解析为IPEndPoint
  153. /// </summary>
  154. /// <param name="dnsEndPoint"></param>
  155. /// <param name="cancellationToken"></param>
  156. /// <returns></returns>
  157. private async IAsyncEnumerable<IPEndPoint> GetIPEndPointsAsync(DnsEndPoint dnsEndPoint, [EnumeratorCancellation] CancellationToken cancellationToken)
  158. {
  159. if (IPAddress.TryParse(dnsEndPoint.Host, out var address))
  160. {
  161. yield return new IPEndPoint(address, dnsEndPoint.Port);
  162. }
  163. else
  164. {
  165. if (this.domainConfig.IPAddress != null)
  166. {
  167. yield return new IPEndPoint(this.domainConfig.IPAddress, dnsEndPoint.Port);
  168. }
  169. await foreach (var item in this.domainResolver.ResolveAsync(dnsEndPoint, cancellationToken))
  170. {
  171. yield return new IPEndPoint(item, dnsEndPoint.Port);
  172. }
  173. }
  174. }
  175. /// <summary>
  176. /// 读取使用的DNS名称
  177. /// </summary>
  178. /// <param name="cert"></param>
  179. /// <returns></returns>
  180. private static IEnumerable<string> ReadDnsNames(X509Certificate? cert)
  181. {
  182. if (cert is X509Certificate2 x509)
  183. {
  184. var extension = x509.Extensions.OfType<X509SubjectAlternativeNameExtension>().FirstOrDefault();
  185. if (extension != null)
  186. {
  187. return extension.EnumerateDnsNames();
  188. }
  189. }
  190. return Array.Empty<string>();
  191. }
  192. /// <summary>
  193. /// 比较域名
  194. /// </summary>
  195. /// <param name="dnsName"></param>
  196. /// <param name="domain"></param>
  197. /// <returns></returns>
  198. private static bool IsMatch(string dnsName, string? domain)
  199. {
  200. if (domain == null)
  201. {
  202. return false;
  203. }
  204. if (dnsName == domain)
  205. {
  206. return true;
  207. }
  208. if (dnsName[0] == '*')
  209. {
  210. return domain.EndsWith(dnsName[1..]);
  211. }
  212. return false;
  213. }
  214. }
  215. }