2014-08-25 10:50:37 +02:00
|
|
|
/*
|
|
|
|
* Copyright 2014 The Netty Project
|
|
|
|
*
|
|
|
|
* The Netty Project licenses this file to you under the Apache License,
|
|
|
|
* version 2.0 (the "License"); you may not use this file except in compliance
|
|
|
|
* with the License. You may obtain a copy of the License at:
|
|
|
|
*
|
|
|
|
* http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
*
|
|
|
|
* Unless required by applicable law or agreed to in writing, software
|
|
|
|
* distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
|
|
|
|
* WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
|
|
|
|
* License for the specific language governing permissions and limitations
|
|
|
|
* under the License.
|
|
|
|
*/
|
|
|
|
|
|
|
|
package io.netty.handler.proxy;
|
|
|
|
|
|
|
|
import io.netty.channel.ChannelHandlerContext;
|
|
|
|
import io.netty.channel.ChannelPipeline;
|
2014-12-22 14:25:28 +01:00
|
|
|
import io.netty.handler.codec.socksx.v5.DefaultSocks5InitialRequest;
|
|
|
|
import io.netty.handler.codec.socksx.v5.DefaultSocks5CommandRequest;
|
|
|
|
import io.netty.handler.codec.socksx.v5.DefaultSocks5PasswordAuthRequest;
|
2014-08-25 10:50:37 +02:00
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5AddressType;
|
2014-12-22 14:25:28 +01:00
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5AuthMethod;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5InitialRequest;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5InitialResponse;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5InitialResponseDecoder;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5ClientEncoder;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5CommandResponse;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5CommandResponseDecoder;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5CommandStatus;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5CommandType;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5PasswordAuthResponse;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5PasswordAuthResponseDecoder;
|
|
|
|
import io.netty.handler.codec.socksx.v5.Socks5PasswordAuthStatus;
|
2014-08-25 10:50:37 +02:00
|
|
|
import io.netty.util.NetUtil;
|
|
|
|
import io.netty.util.internal.StringUtil;
|
|
|
|
|
|
|
|
import java.net.InetSocketAddress;
|
|
|
|
import java.net.SocketAddress;
|
|
|
|
import java.util.Arrays;
|
|
|
|
import java.util.Collections;
|
|
|
|
|
|
|
|
public final class Socks5ProxyHandler extends ProxyHandler {
|
|
|
|
|
|
|
|
private static final String PROTOCOL = "socks5";
|
|
|
|
private static final String AUTH_PASSWORD = "password";
|
|
|
|
|
2014-12-22 14:25:28 +01:00
|
|
|
private static final Socks5InitialRequest INIT_REQUEST_NO_AUTH =
|
|
|
|
new DefaultSocks5InitialRequest(Collections.singletonList(Socks5AuthMethod.NO_AUTH));
|
2014-08-25 10:50:37 +02:00
|
|
|
|
2014-12-22 14:25:28 +01:00
|
|
|
private static final Socks5InitialRequest INIT_REQUEST_PASSWORD =
|
|
|
|
new DefaultSocks5InitialRequest(Arrays.asList(Socks5AuthMethod.NO_AUTH, Socks5AuthMethod.PASSWORD));
|
2014-08-25 10:50:37 +02:00
|
|
|
|
|
|
|
private final String username;
|
|
|
|
private final String password;
|
|
|
|
|
|
|
|
private String decoderName;
|
|
|
|
private String encoderName;
|
|
|
|
|
|
|
|
public Socks5ProxyHandler(SocketAddress proxyAddress) {
|
|
|
|
this(proxyAddress, null, null);
|
|
|
|
}
|
|
|
|
|
|
|
|
public Socks5ProxyHandler(SocketAddress proxyAddress, String username, String password) {
|
|
|
|
super(proxyAddress);
|
2017-02-13 22:31:09 +01:00
|
|
|
if (username != null && username.isEmpty()) {
|
2014-08-25 10:50:37 +02:00
|
|
|
username = null;
|
|
|
|
}
|
2017-02-13 22:31:09 +01:00
|
|
|
if (password != null && password.isEmpty()) {
|
2014-08-25 10:50:37 +02:00
|
|
|
password = null;
|
|
|
|
}
|
|
|
|
this.username = username;
|
|
|
|
this.password = password;
|
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
|
|
public String protocol() {
|
|
|
|
return PROTOCOL;
|
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
|
|
public String authScheme() {
|
2014-12-22 14:25:28 +01:00
|
|
|
return socksAuthMethod() == Socks5AuthMethod.PASSWORD? AUTH_PASSWORD : AUTH_NONE;
|
2014-08-25 10:50:37 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
public String username() {
|
|
|
|
return username;
|
|
|
|
}
|
|
|
|
|
|
|
|
public String password() {
|
|
|
|
return password;
|
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
|
|
protected void addCodec(ChannelHandlerContext ctx) throws Exception {
|
|
|
|
ChannelPipeline p = ctx.pipeline();
|
|
|
|
String name = ctx.name();
|
|
|
|
|
2014-12-22 14:25:28 +01:00
|
|
|
Socks5InitialResponseDecoder decoder = new Socks5InitialResponseDecoder();
|
2014-08-25 10:50:37 +02:00
|
|
|
p.addBefore(name, null, decoder);
|
|
|
|
|
|
|
|
decoderName = p.context(decoder).name();
|
|
|
|
encoderName = decoderName + ".encoder";
|
|
|
|
|
2014-12-22 14:25:28 +01:00
|
|
|
p.addBefore(name, encoderName, Socks5ClientEncoder.DEFAULT);
|
2014-08-25 10:50:37 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
|
|
protected void removeEncoder(ChannelHandlerContext ctx) throws Exception {
|
|
|
|
ctx.pipeline().remove(encoderName);
|
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
|
|
protected void removeDecoder(ChannelHandlerContext ctx) throws Exception {
|
|
|
|
ChannelPipeline p = ctx.pipeline();
|
|
|
|
if (p.context(decoderName) != null) {
|
|
|
|
p.remove(decoderName);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
|
|
protected Object newInitialMessage(ChannelHandlerContext ctx) throws Exception {
|
2014-12-22 14:25:28 +01:00
|
|
|
return socksAuthMethod() == Socks5AuthMethod.PASSWORD? INIT_REQUEST_PASSWORD : INIT_REQUEST_NO_AUTH;
|
2014-08-25 10:50:37 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
|
|
protected boolean handleResponse(ChannelHandlerContext ctx, Object response) throws Exception {
|
2014-12-22 14:25:28 +01:00
|
|
|
if (response instanceof Socks5InitialResponse) {
|
|
|
|
Socks5InitialResponse res = (Socks5InitialResponse) response;
|
|
|
|
Socks5AuthMethod authMethod = socksAuthMethod();
|
2014-08-25 10:50:37 +02:00
|
|
|
|
2014-12-22 14:25:28 +01:00
|
|
|
if (res.authMethod() != Socks5AuthMethod.NO_AUTH && res.authMethod() != authMethod) {
|
2014-08-25 10:50:37 +02:00
|
|
|
// Server did not allow unauthenticated access nor accept the requested authentication scheme.
|
2014-12-22 14:25:28 +01:00
|
|
|
throw new ProxyConnectException(exceptionMessage("unexpected authMethod: " + res.authMethod()));
|
2014-08-25 10:50:37 +02:00
|
|
|
}
|
|
|
|
|
2014-12-22 14:25:28 +01:00
|
|
|
if (authMethod == Socks5AuthMethod.NO_AUTH) {
|
2014-08-25 10:50:37 +02:00
|
|
|
sendConnectCommand(ctx);
|
2014-12-22 14:25:28 +01:00
|
|
|
} else if (authMethod == Socks5AuthMethod.PASSWORD) {
|
2014-08-25 10:50:37 +02:00
|
|
|
// In case of password authentication, send an authentication request.
|
2014-12-22 14:25:28 +01:00
|
|
|
ctx.pipeline().replace(decoderName, decoderName, new Socks5PasswordAuthResponseDecoder());
|
|
|
|
sendToProxyServer(new DefaultSocks5PasswordAuthRequest(
|
|
|
|
username != null? username : "", password != null? password : ""));
|
|
|
|
} else {
|
2014-08-25 10:50:37 +02:00
|
|
|
// Should never reach here.
|
|
|
|
throw new Error();
|
|
|
|
}
|
|
|
|
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2014-12-22 14:25:28 +01:00
|
|
|
if (response instanceof Socks5PasswordAuthResponse) {
|
2014-08-25 10:50:37 +02:00
|
|
|
// Received an authentication response from the server.
|
2014-12-22 14:25:28 +01:00
|
|
|
Socks5PasswordAuthResponse res = (Socks5PasswordAuthResponse) response;
|
|
|
|
if (res.status() != Socks5PasswordAuthStatus.SUCCESS) {
|
|
|
|
throw new ProxyConnectException(exceptionMessage("authStatus: " + res.status()));
|
2014-08-25 10:50:37 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
sendConnectCommand(ctx);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
// This should be the last message from the server.
|
2014-12-22 14:25:28 +01:00
|
|
|
Socks5CommandResponse res = (Socks5CommandResponse) response;
|
|
|
|
if (res.status() != Socks5CommandStatus.SUCCESS) {
|
|
|
|
throw new ProxyConnectException(exceptionMessage("status: " + res.status()));
|
2014-08-25 10:50:37 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2014-12-22 14:25:28 +01:00
|
|
|
private Socks5AuthMethod socksAuthMethod() {
|
|
|
|
Socks5AuthMethod authMethod;
|
2014-08-25 10:50:37 +02:00
|
|
|
if (username == null && password == null) {
|
2014-12-22 14:25:28 +01:00
|
|
|
authMethod = Socks5AuthMethod.NO_AUTH;
|
2014-08-25 10:50:37 +02:00
|
|
|
} else {
|
2014-12-22 14:25:28 +01:00
|
|
|
authMethod = Socks5AuthMethod.PASSWORD;
|
2014-08-25 10:50:37 +02:00
|
|
|
}
|
2014-12-22 14:25:28 +01:00
|
|
|
return authMethod;
|
2014-08-25 10:50:37 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
private void sendConnectCommand(ChannelHandlerContext ctx) throws Exception {
|
|
|
|
InetSocketAddress raddr = destinationAddress();
|
|
|
|
Socks5AddressType addrType;
|
|
|
|
String rhost;
|
|
|
|
if (raddr.isUnresolved()) {
|
|
|
|
addrType = Socks5AddressType.DOMAIN;
|
|
|
|
rhost = raddr.getHostString();
|
|
|
|
} else {
|
|
|
|
rhost = raddr.getAddress().getHostAddress();
|
|
|
|
if (NetUtil.isValidIpV4Address(rhost)) {
|
|
|
|
addrType = Socks5AddressType.IPv4;
|
|
|
|
} else if (NetUtil.isValidIpV6Address(rhost)) {
|
|
|
|
addrType = Socks5AddressType.IPv6;
|
|
|
|
} else {
|
|
|
|
throw new ProxyConnectException(
|
|
|
|
exceptionMessage("unknown address type: " + StringUtil.simpleClassName(rhost)));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-12-22 14:25:28 +01:00
|
|
|
ctx.pipeline().replace(decoderName, decoderName, new Socks5CommandResponseDecoder());
|
|
|
|
sendToProxyServer(new DefaultSocks5CommandRequest(Socks5CommandType.CONNECT, addrType, rhost, raddr.getPort()));
|
2014-08-25 10:50:37 +02:00
|
|
|
}
|
|
|
|
}
|