issue.go 3.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162
  1. package certificate
  2. import (
  3. "github.com/0xJacky/Nginx-UI/internal/cert"
  4. "github.com/0xJacky/Nginx-UI/internal/logger"
  5. "github.com/0xJacky/Nginx-UI/internal/nginx"
  6. "github.com/0xJacky/Nginx-UI/model"
  7. "github.com/gin-gonic/gin"
  8. "github.com/go-acme/lego/v4/certcrypto"
  9. "github.com/gorilla/websocket"
  10. "net/http"
  11. "strings"
  12. )
  13. const (
  14. Success = "success"
  15. Info = "info"
  16. Error = "error"
  17. )
  18. type IssueCertResponse struct {
  19. Status string `json:"status"`
  20. Message string `json:"message"`
  21. SSLCertificate string `json:"ssl_certificate,omitempty"`
  22. SSLCertificateKey string `json:"ssl_certificate_key,omitempty"`
  23. KeyType certcrypto.KeyType `json:"key_type"`
  24. }
  25. func handleIssueCertLogChan(conn *websocket.Conn, log *cert.Logger, logChan chan string) {
  26. defer func() {
  27. if err := recover(); err != nil {
  28. logger.Error(err)
  29. }
  30. }()
  31. for logString := range logChan {
  32. log.Info(logString)
  33. err := conn.WriteJSON(IssueCertResponse{
  34. Status: Info,
  35. Message: logString,
  36. })
  37. if err != nil {
  38. logger.Error(err)
  39. return
  40. }
  41. }
  42. }
  43. func IssueCert(c *gin.Context) {
  44. var upGrader = websocket.Upgrader{
  45. CheckOrigin: func(r *http.Request) bool {
  46. return true
  47. },
  48. }
  49. // upgrade http to websocket
  50. ws, err := upGrader.Upgrade(c.Writer, c.Request, nil)
  51. if err != nil {
  52. logger.Error(err)
  53. return
  54. }
  55. defer func(ws *websocket.Conn) {
  56. _ = ws.Close()
  57. }(ws)
  58. // read
  59. payload := &cert.ConfigPayload{}
  60. err = ws.ReadJSON(payload)
  61. if err != nil {
  62. logger.Error(err)
  63. return
  64. }
  65. certModel, err := model.FirstOrCreateCert(c.Param("name"), payload.GetKeyType())
  66. if err != nil {
  67. logger.Error(err)
  68. return
  69. }
  70. certInfo, _ := cert.GetCertInfo(certModel.SSLCertificatePath)
  71. if certInfo != nil {
  72. payload.Resource = certModel.Resource
  73. payload.NotBefore = certInfo.NotBefore
  74. }
  75. logChan := make(chan string, 1)
  76. errChan := make(chan error, 1)
  77. log := &cert.Logger{}
  78. log.SetCertModel(&certModel)
  79. go cert.IssueCert(payload, logChan, errChan)
  80. go handleIssueCertLogChan(ws, log, logChan)
  81. // block, until errChan closes
  82. for err = range errChan {
  83. log.Error(err)
  84. // Save logs to db
  85. log.Exit()
  86. err = ws.WriteJSON(IssueCertResponse{
  87. Status: Error,
  88. Message: err.Error(),
  89. })
  90. if err != nil {
  91. logger.Error(err)
  92. return
  93. }
  94. return
  95. }
  96. certDirName := strings.Join(payload.ServerName, "_") + "_" + string(payload.GetKeyType())
  97. sslCertificatePath := nginx.GetConfPath("ssl", certDirName, "fullchain.cer")
  98. sslCertificateKeyPath := nginx.GetConfPath("ssl", certDirName, "private.key")
  99. err = certModel.Updates(&model.Cert{
  100. Domains: payload.ServerName,
  101. SSLCertificatePath: sslCertificatePath,
  102. SSLCertificateKeyPath: sslCertificateKeyPath,
  103. AutoCert: model.AutoCertEnabled,
  104. KeyType: payload.KeyType,
  105. ChallengeMethod: payload.ChallengeMethod,
  106. DnsCredentialID: payload.DNSCredentialID,
  107. Resource: payload.Resource,
  108. })
  109. if err != nil {
  110. logger.Error(err)
  111. err = ws.WriteJSON(IssueCertResponse{
  112. Status: Error,
  113. Message: err.Error(),
  114. })
  115. return
  116. }
  117. // Save logs to db
  118. log.Exit()
  119. err = ws.WriteJSON(IssueCertResponse{
  120. Status: Success,
  121. Message: "Issued certificate successfully",
  122. SSLCertificate: sslCertificatePath,
  123. SSLCertificateKey: sslCertificateKeyPath,
  124. KeyType: payload.GetKeyType(),
  125. })
  126. if err != nil {
  127. logger.Error(err)
  128. return
  129. }
  130. }