HttpClientHandler.cs 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254
  1. using FastGithub.Configuration;
  2. using FastGithub.DomainResolve;
  3. using System;
  4. using System.Collections;
  5. using System.Collections.Generic;
  6. using System.IO;
  7. using System.Linq;
  8. using System.Net;
  9. using System.Net.Http;
  10. using System.Net.Security;
  11. using System.Net.Sockets;
  12. using System.Runtime.CompilerServices;
  13. using System.Security.Cryptography.X509Certificates;
  14. using System.Threading;
  15. using System.Threading.Tasks;
  16. namespace FastGithub.Http
  17. {
  18. /// <summary>
  19. /// HttpClientHandler
  20. /// </summary>
  21. class HttpClientHandler : DelegatingHandler
  22. {
  23. private readonly DomainConfig domainConfig;
  24. private readonly IDomainResolver domainResolver;
  25. private readonly TimeSpan connectTimeout = TimeSpan.FromSeconds(10d);
  26. /// <summary>
  27. /// HttpClientHandler
  28. /// </summary>
  29. /// <param name="domainConfig"></param>
  30. /// <param name="domainResolver"></param>
  31. public HttpClientHandler(DomainConfig domainConfig, IDomainResolver domainResolver)
  32. {
  33. this.domainResolver = domainResolver;
  34. this.domainConfig = domainConfig;
  35. this.InnerHandler = this.CreateSocketsHttpHandler();
  36. }
  37. /// <summary>
  38. /// 发送请求
  39. /// </summary>
  40. /// <param name="request"></param>
  41. /// <param name="cancellationToken"></param>
  42. /// <returns></returns>
  43. protected override async Task<HttpResponseMessage> SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)
  44. {
  45. var uri = request.RequestUri;
  46. if (uri == null)
  47. {
  48. throw new FastGithubException("必须指定请求的URI");
  49. }
  50. // 请求上下文信息
  51. var isHttps = uri.Scheme == Uri.UriSchemeHttps;
  52. var tlsSniValue = this.domainConfig.GetTlsSniPattern().WithDomain(uri.Host).WithRandom();
  53. request.SetRequestContext(new RequestContext(isHttps, tlsSniValue));
  54. // 设置请求头host,修改协议为http,使用ip取代域名
  55. var address = await this.domainResolver.ResolveAnyAsync(uri.Host, cancellationToken);
  56. var uriBuilder = new UriBuilder(uri)
  57. {
  58. Scheme = Uri.UriSchemeHttp,
  59. Host = address.ToString()
  60. };
  61. request.Headers.Host = uri.Host;
  62. request.RequestUri = uriBuilder.Uri;
  63. if (this.domainConfig.Timeout != null)
  64. {
  65. using var timeoutTokenSource = new CancellationTokenSource(this.domainConfig.Timeout.Value);
  66. using var linkedTokenSource = CancellationTokenSource.CreateLinkedTokenSource(cancellationToken, timeoutTokenSource.Token);
  67. return await base.SendAsync(request, linkedTokenSource.Token);
  68. }
  69. return await base.SendAsync(request, cancellationToken);
  70. }
  71. /// <summary>
  72. /// 创建转发代理的httpHandler
  73. /// </summary>
  74. /// <returns></returns>
  75. private SocketsHttpHandler CreateSocketsHttpHandler()
  76. {
  77. return new SocketsHttpHandler
  78. {
  79. Proxy = null,
  80. UseProxy = false,
  81. UseCookies = false,
  82. AllowAutoRedirect = false,
  83. AutomaticDecompression = DecompressionMethods.None,
  84. ConnectCallback = this.ConnectCallback
  85. };
  86. }
  87. /// <summary>
  88. /// 连接回调
  89. /// </summary>
  90. /// <param name="context"></param>
  91. /// <param name="cancellationToken"></param>
  92. /// <returns></returns>
  93. private async ValueTask<Stream> ConnectCallback(SocketsHttpConnectionContext context, CancellationToken cancellationToken)
  94. {
  95. var innerExceptions = new List<Exception>();
  96. var dnsEndPoint = new DnsEndPoint(context.InitialRequestMessage.Headers.Host!, context.DnsEndPoint.Port);
  97. var ipEndPoints = this.GetIPEndPointsAsync(dnsEndPoint, cancellationToken);
  98. await foreach (var ipEndPoint in ipEndPoints)
  99. {
  100. try
  101. {
  102. using var timeoutTokenSource = new CancellationTokenSource(this.connectTimeout);
  103. using var linkedTokenSource = CancellationTokenSource.CreateLinkedTokenSource(timeoutTokenSource.Token, cancellationToken);
  104. return await this.ConnectAsync(context, ipEndPoint, linkedTokenSource.Token);
  105. }
  106. catch (OperationCanceledException)
  107. {
  108. cancellationToken.ThrowIfCancellationRequested();
  109. innerExceptions.Add(new SocketException((int)SocketError.TimedOut));
  110. }
  111. catch (Exception ex)
  112. {
  113. innerExceptions.Add(ex);
  114. }
  115. }
  116. throw new AggregateException("没有可连接成功的IP", innerExceptions);
  117. }
  118. /// <summary>
  119. /// 建立连接
  120. /// </summary>
  121. /// <param name="context"></param>
  122. /// <param name="ipEndPoint"></param>
  123. /// <param name="cancellationToken"></param>
  124. /// <returns></returns>
  125. private async ValueTask<Stream> ConnectAsync(SocketsHttpConnectionContext context, IPEndPoint ipEndPoint, CancellationToken cancellationToken)
  126. {
  127. var socket = new Socket(SocketType.Stream, ProtocolType.Tcp);
  128. await socket.ConnectAsync(ipEndPoint, cancellationToken);
  129. var stream = new NetworkStream(socket, ownsSocket: true);
  130. var requestContext = context.InitialRequestMessage.GetRequestContext();
  131. if (requestContext.IsHttps == false)
  132. {
  133. return stream;
  134. }
  135. var tlsSniValue = requestContext.TlsSniValue.WithIPAddress(ipEndPoint.Address);
  136. var sslStream = new SslStream(stream, leaveInnerStreamOpen: false);
  137. await sslStream.AuthenticateAsClientAsync(new SslClientAuthenticationOptions
  138. {
  139. TargetHost = tlsSniValue.Value,
  140. RemoteCertificateValidationCallback = ValidateServerCertificate
  141. }, cancellationToken);
  142. return sslStream;
  143. // 验证证书有效性
  144. bool ValidateServerCertificate(object sender, X509Certificate? cert, X509Chain? chain, SslPolicyErrors errors)
  145. {
  146. if (errors.HasFlag(SslPolicyErrors.RemoteCertificateNameMismatch))
  147. {
  148. if (this.domainConfig.TlsIgnoreNameMismatch == true)
  149. {
  150. return true;
  151. }
  152. var domain = context.InitialRequestMessage.Headers.Host!;
  153. var dnsNames = ReadDnsNames(cert);
  154. return dnsNames.Any(dns => IsMatch(dns, domain));
  155. }
  156. return errors == SslPolicyErrors.None;
  157. }
  158. }
  159. /// <summary>
  160. /// 解析为IPEndPoint
  161. /// </summary>
  162. /// <param name="dnsEndPoint"></param>
  163. /// <param name="cancellationToken"></param>
  164. /// <returns></returns>
  165. private async IAsyncEnumerable<IPEndPoint> GetIPEndPointsAsync(DnsEndPoint dnsEndPoint, [EnumeratorCancellation] CancellationToken cancellationToken)
  166. {
  167. if (IPAddress.TryParse(this.domainConfig.IPAddress, out var address) ||
  168. IPAddress.TryParse(dnsEndPoint.Host, out address))
  169. {
  170. yield return new IPEndPoint(address, dnsEndPoint.Port);
  171. }
  172. else
  173. {
  174. await foreach (var item in this.domainResolver.ResolveAllAsync(dnsEndPoint.Host, cancellationToken))
  175. {
  176. yield return new IPEndPoint(item, dnsEndPoint.Port);
  177. }
  178. }
  179. }
  180. /// <summary>
  181. /// 读取使用的DNS名称
  182. /// </summary>
  183. /// <param name="cert"></param>
  184. /// <returns></returns>
  185. private static IEnumerable<string> ReadDnsNames(X509Certificate? cert)
  186. {
  187. if (cert == null)
  188. {
  189. yield break;
  190. }
  191. var parser = new Org.BouncyCastle.X509.X509CertificateParser();
  192. var x509Cert = parser.ReadCertificate(cert.GetRawCertData());
  193. var subjects = x509Cert.GetSubjectAlternativeNames();
  194. foreach (var subject in subjects)
  195. {
  196. if (subject is IList list)
  197. {
  198. if (list.Count >= 2 && list[0] is int nameType && nameType == 2)
  199. {
  200. var dnsName = list[1]?.ToString();
  201. if (dnsName != null)
  202. {
  203. yield return dnsName;
  204. }
  205. }
  206. }
  207. }
  208. }
  209. /// <summary>
  210. /// 比较域名
  211. /// </summary>
  212. /// <param name="dnsName"></param>
  213. /// <param name="domain"></param>
  214. /// <returns></returns>
  215. private static bool IsMatch(string dnsName, string? domain)
  216. {
  217. if (domain == null)
  218. {
  219. return false;
  220. }
  221. if (dnsName == domain)
  222. {
  223. return true;
  224. }
  225. if (dnsName[0] == '*')
  226. {
  227. return domain.EndsWith(dnsName[1..]);
  228. }
  229. return false;
  230. }
  231. }
  232. }