增加非白名单的日志
This commit is contained in:
1 parent
7f4adad7b1
commit
06bb066d82
7 files changed
+332
-28
No files matched your search
@@ -10,6 +10,7 @@ import (
|
||||
"io"
|
||||
"log"
|
||||
"net/http"
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
@@ -105,9 +106,10 @@ func (h *DashScopeChatHandler) ServeHTTP(w http.ResponseWriter, r *http.Request)
|
||||
h.logResult(requestID, "method_not_allowed", false, started)
|
||||
return
|
||||
}
|
||||
if !h.authorizeOrigin(w, r.Header.Get("Origin")) {
|
||||
origin := r.Header.Get("Origin")
|
||||
if !h.authorizeOrigin(w, origin) {
|
||||
h.writeError(w, http.StatusForbidden, requestID, "CHAT_ORIGIN_FORBIDDEN", "Chat browser origin is not allowed.")
|
||||
h.logResult(requestID, "forbidden_origin", false, started)
|
||||
h.logForbiddenOrigin(requestID, origin, started)
|
||||
return
|
||||
}
|
||||
if !h.validToken(r.Header.Get("xtoken")) {
|
||||
@@ -346,10 +348,22 @@ type dashScopeStreamError struct {
|
||||
|
||||
func (h *DashScopeChatHandler) handlePreflight(w http.ResponseWriter, r *http.Request, requestID string, started time.Time) {
|
||||
origin := r.Header.Get("Origin")
|
||||
if origin == "" || !h.authorizeOrigin(w, origin) || r.Header.Get("Access-Control-Request-Method") != http.MethodPost ||
|
||||
!validDashScopePreflightHeaders(r.Header.Get("Access-Control-Request-Headers")) {
|
||||
requestedMethod := r.Header.Get("Access-Control-Request-Method")
|
||||
requestedHeaders := r.Header.Get("Access-Control-Request-Headers")
|
||||
forbiddenReason := ""
|
||||
switch {
|
||||
case origin == "":
|
||||
forbiddenReason = "origin_missing"
|
||||
case !h.authorizeOrigin(w, origin):
|
||||
forbiddenReason = "origin_not_allowed"
|
||||
case requestedMethod != http.MethodPost:
|
||||
forbiddenReason = "method_not_allowed"
|
||||
case !validDashScopePreflightHeaders(requestedHeaders):
|
||||
forbiddenReason = "headers_not_allowed"
|
||||
}
|
||||
if forbiddenReason != "" {
|
||||
h.writeError(w, http.StatusForbidden, requestID, "CHAT_ORIGIN_FORBIDDEN", "Chat browser origin or preflight request is not allowed.")
|
||||
h.logResult(requestID, "preflight_forbidden", false, started)
|
||||
h.logForbiddenPreflight(requestID, origin, requestedMethod, requestedHeaders, forbiddenReason, started)
|
||||
return
|
||||
}
|
||||
w.Header().Set("Access-Control-Allow-Methods", http.MethodPost)
|
||||
@@ -391,6 +405,35 @@ func (h *DashScopeChatHandler) logResult(requestID, result string, reused bool,
|
||||
h.logger.Printf("dashscope_chat_request request_id=%s result=%s reused=%t duration_ms=%d", requestID, result, reused, time.Since(started).Milliseconds())
|
||||
}
|
||||
|
||||
func (h *DashScopeChatHandler) logForbiddenOrigin(requestID, origin string, started time.Time) {
|
||||
h.logger.Printf(
|
||||
"dashscope_chat_request request_id=%s result=forbidden_origin reused=false duration_ms=%d origin=%s",
|
||||
requestID,
|
||||
time.Since(started).Milliseconds(),
|
||||
quotedBoundedLogHeader(origin),
|
||||
)
|
||||
}
|
||||
|
||||
func (h *DashScopeChatHandler) logForbiddenPreflight(requestID, origin, requestedMethod, requestedHeaders, reason string, started time.Time) {
|
||||
h.logger.Printf(
|
||||
"dashscope_chat_request request_id=%s result=preflight_forbidden reused=false duration_ms=%d origin=%s preflight_method=%s preflight_headers=%s reason=%s",
|
||||
requestID,
|
||||
time.Since(started).Milliseconds(),
|
||||
quotedBoundedLogHeader(origin),
|
||||
quotedBoundedLogHeader(requestedMethod),
|
||||
quotedBoundedLogHeader(requestedHeaders),
|
||||
strconv.Quote(reason),
|
||||
)
|
||||
}
|
||||
|
||||
func quotedBoundedLogHeader(value string) string {
|
||||
const maximumLoggedHeaderBytes = 256
|
||||
if len(value) > maximumLoggedHeaderBytes {
|
||||
value = value[:maximumLoggedHeaderBytes] + "...[truncated]"
|
||||
}
|
||||
return strconv.QuoteToASCII(value)
|
||||
}
|
||||
|
||||
func writeDashScopeSSE(w io.Writer, flusher http.Flusher, id int, event string, payload any) error {
|
||||
data, err := json.Marshal(payload)
|
||||
if err != nil {
|
||||
|
||||
Reference in new issue
Block a user