1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
//! This crate provides a chroot/sandbox friendly https client.
//!
//! It doesn't depend on any files from the filesystem which would usually
//! cause issues if /etc/resolv.conf or ca-certificates can not be found.
//!
//! # Example
//!
//! ```
//! extern crate chrootable_https;
//! use chrootable_https::{Resolver, Client};
//!
//! let resolver = Resolver::cloudflare();
//! let client = Client::new(resolver);
//!
//! let reply = client.get("https://httpbin.org/anything").expect("request failed");
//! println!("{:#?}", reply);
//! ```

#![warn(unused_extern_crates)]
pub extern crate hyper;
pub extern crate http;
extern crate tokio;
extern crate rustls;
extern crate hyper_rustls;
extern crate webpki_roots;
extern crate ct_logs;
extern crate trust_dns;
extern crate trust_dns_proto;
extern crate futures;
extern crate bytes;
#[macro_use] extern crate serde_derive;
#[macro_use] extern crate failure;
#[macro_use] extern crate log;

#[cfg(unix)]
extern crate resolv_conf;
#[cfg(windows)]
extern crate ipconfig;

pub use hyper::Body;
use http::response::Parts;
pub use http::header;
use hyper_rustls::HttpsConnector;
use hyper::rt::Future;
use hyper::client::connect::HttpConnector;
pub use http::Request;
use bytes::Bytes;

use tokio::runtime::Runtime;
use tokio::prelude::FutureExt;
use futures::{future, Stream};

use std::net::IpAddr;
use std::collections::HashMap;
use std::sync::{Arc, Mutex};
use std::time::Duration;
pub use http::Uri;

mod connector;
pub mod dns;
use self::connector::Connector;
pub use dns::{Resolver, DnsResolver, RecordType};

pub mod errors {
    pub use failure::{Error, ResultExt};
    pub type Result<T> = ::std::result::Result<T, Error>;
}
pub use errors::*;


#[derive(Debug)]
pub struct Client<R: DnsResolver> {
    client: Arc<hyper::Client<HttpsConnector<Connector<HttpConnector>>>>,
    resolver: R,
    records: Arc<Mutex<HashMap<String, IpAddr>>>,
    timeout: Option<Duration>,
}

impl<R: DnsResolver> Client<R> {
    /// Create a new client with a specific dns resolver.
    ///
    /// This bypasses /etc/resolv.conf
    pub fn new(resolver: R) -> Client<R> {
        let records = Arc::new(Mutex::new(HashMap::new()));
        let https = Connector::https(records.clone());
        let client = hyper::Client::builder()
            .keep_alive(false)
            .build::<_, hyper::Body>(https);

        Client {
            client: Arc::new(client),
            resolver,
            records,
            timeout: None,
        }
    }

    /// Set a timeout, default is no timeout
    pub fn timeout(&mut self, timeout: Duration) {
        self.timeout = Some(timeout);
    }

    /// Pre-populate the dns-cache. This function is usually called internally
    pub fn pre_resolve(&self, uri: &Uri) -> Result<()> {
        let host = match uri.host() {
            Some(host) => host,
            None => bail!("url has no host"),
        };

        let record = self.resolver.resolve(&host, RecordType::A)?;
        match record.success()?.into_iter().next() {
            Some(record) => {
                // TODO: make sure we only add the records we want
                let mut cache = self.records.lock().unwrap();
                cache.insert(host.to_string(), record);
            },
            None => bail!("no record found"),
        }
        Ok(())
    }

    /// Shorthand function to do a GET request with [`HttpClient::request`]
    ///
    /// [`HttpClient::request`]: trait.HttpClient.html#tymethod.request
    pub fn get(&self, url: &str) -> Result<Response> {
        let url = url.parse::<Uri>()?;

        let mut request = Request::builder();
        let request = request.uri(url)
               .body(Body::empty())?;

        self.request(request)
    }
}

impl Client<Resolver> {
    /// Create a new client with the system resolver from /etc/resolv.conf
    pub fn with_system_resolver() -> Result<Client<Resolver>> {
        let resolver = Resolver::from_system()?;
        Ok(Client::new(resolver))
    }
}

pub trait HttpClient {
    fn request(&self, request: Request<hyper::Body>) -> Result<Response>;
}

impl<R: DnsResolver> HttpClient for Client<R> {
    fn request(&self, request: Request<hyper::Body>) -> Result<Response> {
        info!("sending request to {:?}", request.uri());
        self.pre_resolve(request.uri())?;

        let client = self.client.clone();
        let timeout = self.timeout.clone();

        let mut rt = Runtime::new()?;
        let fut = client.request(request)
            .and_then(|res| {
                debug!("http response: {:?}", res);
                let (parts, body) = res.into_parts();
                let body = body.concat2();
                (future::ok(parts), body)
            });

        let (parts, body) = match timeout {
            Some(timeout) => rt.block_on(fut.timeout(timeout))?,
            None => rt.block_on(fut)?,
        };

        let body = body.into_bytes();
        let reply = Response::from((parts, body));
        info!("got reply {:?}", reply);
        Ok(reply)
    }
}

#[derive(Debug)]
pub struct Response {
    pub status: u16,
    pub headers: HashMap<String, String>,
    pub cookies: Vec<String>,
    pub body: Bytes,
}

impl From<(Parts, Bytes)> for Response {
    fn from(x: (Parts, Bytes)) -> Response {
        let parts = x.0;
        let body = x.1;

        let cookies = parts.headers.get_all("set-cookie").into_iter()
                        .flat_map(|x| x.to_str().map(|x| x.to_owned()).ok())
                        .collect();

        let mut headers = HashMap::new();

        for (k, v) in parts.headers {
            if let Some(k) = k {
                if let Ok(v) = v.to_str() {
                    let k = String::from(k.as_str());
                    let v = String::from(v);

                    headers.insert(k, v);
                }
            }
        }

        Response {
            status: parts.status.as_u16(),
            headers,
            cookies,
            body,
        }
    }
}


#[cfg(test)]
mod tests {
    use super::*;
    use dns::Resolver;
    use std::time::{Instant, Duration};

    #[test]
    fn verify_200_http() {
        let resolver = Resolver::cloudflare();

        let client = Client::new(resolver);
        let reply = client.get("http://httpbin.org/anything").expect("request failed");
        assert_eq!(reply.status, 200);
    }

    #[test]
    fn verify_200_https() {
        let resolver = Resolver::cloudflare();

        let client = Client::new(resolver);
        let reply = client.get("https://httpbin.org/anything").expect("request failed");
        assert_eq!(reply.status, 200);
    }

    #[test]
    fn verify_200_https_system_resolver() {
        let client = Client::with_system_resolver().expect("failed to create client");
        let reply = client.get("https://httpbin.org/anything").expect("request failed");
        assert_eq!(reply.status, 200);
    }

    #[test]
    fn verify_302() {
        let resolver = Resolver::cloudflare();

        let client = Client::new(resolver);
        let reply = client.get("https://httpbin.org/redirect-to?url=/anything&status=302").expect("request failed");
        assert_eq!(reply.status, 302);
    }

    #[test]
    fn verify_timeout() {
        let resolver = Resolver::cloudflare();

        let mut client = Client::new(resolver);
        client.timeout(Duration::from_millis(250));

        let start = Instant::now();
        let _reply = client.get("http://1.2.3.4").err();
        let end = Instant::now();

        assert!(end.duration_since(start) < Duration::from_secs(1));
    }
}