2023-10-11 19:35:22 +01:00
|
|
|
// Copyright (c) Tailscale Inc & AUTHORS
|
|
|
|
// SPDX-License-Identifier: BSD-3-Clause
|
|
|
|
|
|
|
|
//go:build !ios && !android
|
|
|
|
|
|
|
|
package ipnlocal
|
|
|
|
|
|
|
|
import (
|
2023-11-09 00:05:33 +00:00
|
|
|
"context"
|
2023-11-16 22:53:46 +00:00
|
|
|
"encoding/json"
|
2023-10-11 19:35:22 +01:00
|
|
|
"errors"
|
|
|
|
"fmt"
|
2023-11-16 22:53:46 +00:00
|
|
|
"io"
|
2023-10-26 19:39:20 +01:00
|
|
|
"net"
|
2023-10-11 19:35:22 +01:00
|
|
|
"net/http"
|
2023-11-09 00:05:33 +00:00
|
|
|
"net/netip"
|
2023-11-15 22:40:37 +00:00
|
|
|
"sync"
|
2023-11-09 00:05:33 +00:00
|
|
|
"time"
|
2023-10-11 19:35:22 +01:00
|
|
|
|
|
|
|
"tailscale.com/client/tailscale"
|
|
|
|
"tailscale.com/client/web"
|
2023-11-09 00:05:33 +00:00
|
|
|
"tailscale.com/logtail/backoff"
|
2023-10-26 19:39:20 +01:00
|
|
|
"tailscale.com/net/netutil"
|
2023-11-16 22:53:46 +00:00
|
|
|
"tailscale.com/tailcfg"
|
2023-11-09 00:05:33 +00:00
|
|
|
"tailscale.com/types/logger"
|
|
|
|
"tailscale.com/util/mak"
|
2023-10-11 19:35:22 +01:00
|
|
|
)
|
|
|
|
|
2023-11-03 03:05:40 +00:00
|
|
|
const webClientPort = web.ListenPort
|
|
|
|
|
2023-11-15 22:40:37 +00:00
|
|
|
// webClient holds state for the web interface for managing this
|
|
|
|
// tailscale instance. The web interface is not used by default,
|
|
|
|
// but initialized by calling LocalBackend.WebClientGetOrInit.
|
2023-10-31 18:56:20 +00:00
|
|
|
type webClient struct {
|
2023-11-15 22:40:37 +00:00
|
|
|
mu sync.Mutex // protects webClient fields
|
|
|
|
|
2023-10-31 18:56:20 +00:00
|
|
|
server *web.Server // or nil, initialized lazily
|
2023-10-11 19:35:22 +01:00
|
|
|
|
|
|
|
// lc optionally specifies a LocalClient to use to connect
|
|
|
|
// to the localapi for this tailscaled instance.
|
|
|
|
// If nil, a default is used.
|
|
|
|
lc *tailscale.LocalClient
|
|
|
|
}
|
|
|
|
|
2023-11-15 21:38:57 +00:00
|
|
|
// ConfigureWebClient configures b.web prior to use.
|
|
|
|
// Specifially, it sets b.web.lc to the provided LocalClient.
|
|
|
|
// If provided as nil, b.web.lc is cleared out.
|
|
|
|
func (b *LocalBackend) ConfigureWebClient(lc *tailscale.LocalClient) {
|
2023-11-15 22:40:37 +00:00
|
|
|
b.webClient.mu.Lock()
|
|
|
|
defer b.webClient.mu.Unlock()
|
2023-10-31 18:56:20 +00:00
|
|
|
b.webClient.lc = lc
|
2023-10-11 19:35:22 +01:00
|
|
|
}
|
|
|
|
|
2023-11-15 22:40:37 +00:00
|
|
|
// webClientGetOrInit gets or initializes the web server for managing
|
|
|
|
// this tailscaled instance.
|
|
|
|
// s is always non-nil if err is empty.
|
|
|
|
func (b *LocalBackend) webClientGetOrInit() (s *web.Server, err error) {
|
2023-11-02 16:55:01 +00:00
|
|
|
if !b.ShouldRunWebClient() {
|
2023-11-15 22:40:37 +00:00
|
|
|
return nil, errors.New("web client not enabled for this device")
|
2023-10-11 19:35:22 +01:00
|
|
|
}
|
|
|
|
|
2023-11-15 22:40:37 +00:00
|
|
|
b.webClient.mu.Lock()
|
|
|
|
defer b.webClient.mu.Unlock()
|
2023-10-31 18:56:20 +00:00
|
|
|
if b.webClient.server != nil {
|
2023-11-15 22:40:37 +00:00
|
|
|
return b.webClient.server, nil
|
2023-10-11 19:35:22 +01:00
|
|
|
}
|
|
|
|
|
2023-11-15 22:40:37 +00:00
|
|
|
b.logf("webClientGetOrInit: initializing web ui")
|
2023-10-31 18:56:20 +00:00
|
|
|
if b.webClient.server, err = web.NewServer(web.ServerOpts{
|
2023-11-02 22:19:16 +00:00
|
|
|
Mode: web.ManageServerMode,
|
2023-10-31 18:56:20 +00:00
|
|
|
LocalClient: b.webClient.lc,
|
2023-10-11 19:35:22 +01:00
|
|
|
Logf: b.logf,
|
2023-11-16 22:53:46 +00:00
|
|
|
NewAuthURL: b.newWebClientAuthURL,
|
|
|
|
WaitAuthURL: b.waitWebClientAuthURL,
|
2023-10-11 19:35:22 +01:00
|
|
|
}); err != nil {
|
2023-11-15 22:40:37 +00:00
|
|
|
return nil, fmt.Errorf("web.NewServer: %w", err)
|
2023-10-11 19:35:22 +01:00
|
|
|
}
|
|
|
|
|
2023-11-15 22:40:37 +00:00
|
|
|
b.logf("webClientGetOrInit: started web ui")
|
|
|
|
return b.webClient.server, nil
|
2023-10-11 19:35:22 +01:00
|
|
|
}
|
|
|
|
|
2023-10-31 18:56:20 +00:00
|
|
|
// WebClientShutdown shuts down any running b.webClient servers and
|
|
|
|
// clears out b.webClient state (besides the b.webClient.lc field,
|
|
|
|
// which is left untouched because required for future web startups).
|
|
|
|
// WebClientShutdown obtains the b.mu lock.
|
2023-11-15 22:40:37 +00:00
|
|
|
func (b *LocalBackend) webClientShutdown() {
|
2023-10-11 19:35:22 +01:00
|
|
|
b.mu.Lock()
|
2023-11-14 20:07:51 +00:00
|
|
|
for ap, ln := range b.webClientListeners {
|
2023-11-09 00:05:33 +00:00
|
|
|
ln.Close()
|
2023-11-14 20:07:51 +00:00
|
|
|
delete(b.webClientListeners, ap)
|
2023-11-09 00:05:33 +00:00
|
|
|
}
|
2023-11-15 22:40:37 +00:00
|
|
|
b.mu.Unlock()
|
|
|
|
|
|
|
|
b.webClient.mu.Lock() // webClient struct uses its own mutext
|
|
|
|
server := b.webClient.server
|
|
|
|
b.webClient.server = nil
|
|
|
|
b.webClient.mu.Unlock() // release lock before shutdown
|
2023-10-31 18:56:20 +00:00
|
|
|
if server != nil {
|
|
|
|
server.Shutdown()
|
2023-11-02 22:19:16 +00:00
|
|
|
b.logf("WebClientShutdown: shut down web ui")
|
2023-10-11 19:35:22 +01:00
|
|
|
}
|
|
|
|
}
|
2023-10-26 19:39:20 +01:00
|
|
|
|
|
|
|
// handleWebClientConn serves web client requests.
|
|
|
|
func (b *LocalBackend) handleWebClientConn(c net.Conn) error {
|
2023-11-15 22:40:37 +00:00
|
|
|
webServer, err := b.webClientGetOrInit()
|
|
|
|
if err != nil {
|
2023-10-26 19:39:20 +01:00
|
|
|
return err
|
|
|
|
}
|
2023-11-15 22:40:37 +00:00
|
|
|
s := http.Server{Handler: webServer}
|
2023-10-26 19:39:20 +01:00
|
|
|
return s.Serve(netutil.NewOneConnListener(c, nil))
|
|
|
|
}
|
2023-11-09 00:05:33 +00:00
|
|
|
|
|
|
|
// updateWebClientListenersLocked creates listeners on the web client port (5252)
|
|
|
|
// for each of the local device's Tailscale IP addresses. This is needed to properly
|
|
|
|
// route local traffic when using kernel networking mode.
|
|
|
|
func (b *LocalBackend) updateWebClientListenersLocked() {
|
|
|
|
if b.netMap == nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
addrs := b.netMap.GetAddresses()
|
2024-02-25 15:57:11 +00:00
|
|
|
for i := range addrs.Len() {
|
2023-11-09 00:05:33 +00:00
|
|
|
addrPort := netip.AddrPortFrom(addrs.At(i).Addr(), webClientPort)
|
|
|
|
if _, ok := b.webClientListeners[addrPort]; ok {
|
|
|
|
continue // already listening
|
|
|
|
}
|
|
|
|
|
|
|
|
sl := b.newWebClientListener(context.Background(), addrPort, b.logf)
|
|
|
|
mak.Set(&b.webClientListeners, addrPort, sl)
|
|
|
|
|
|
|
|
go sl.Run()
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// newWebClientListener returns a listener for local connections to the built-in web client
|
|
|
|
// used to manage this Tailscale instance.
|
|
|
|
func (b *LocalBackend) newWebClientListener(ctx context.Context, ap netip.AddrPort, logf logger.Logf) *localListener {
|
|
|
|
ctx, cancel := context.WithCancel(ctx)
|
|
|
|
return &localListener{
|
|
|
|
b: b,
|
|
|
|
ap: ap,
|
|
|
|
ctx: ctx,
|
|
|
|
cancel: cancel,
|
|
|
|
logf: logf,
|
|
|
|
|
|
|
|
handler: b.handleWebClientConn,
|
|
|
|
bo: backoff.NewBackoff("webclient-listener", logf, 30*time.Second),
|
|
|
|
}
|
|
|
|
}
|
2023-11-16 22:53:46 +00:00
|
|
|
|
|
|
|
// newWebClientAuthURL talks to the control server to create a new auth
|
|
|
|
// URL that can be used to validate a browser session to manage this
|
|
|
|
// tailscaled instance via the web client.
|
|
|
|
func (b *LocalBackend) newWebClientAuthURL(ctx context.Context, src tailcfg.NodeID) (*tailcfg.WebClientAuthResponse, error) {
|
|
|
|
return b.doWebClientNoiseRequest(ctx, "", src)
|
|
|
|
}
|
|
|
|
|
|
|
|
// waitWebClientAuthURL connects to the control server and blocks
|
|
|
|
// until the associated auth URL has been completed by its user,
|
|
|
|
// or until ctx is canceled.
|
|
|
|
func (b *LocalBackend) waitWebClientAuthURL(ctx context.Context, id string, src tailcfg.NodeID) (*tailcfg.WebClientAuthResponse, error) {
|
|
|
|
return b.doWebClientNoiseRequest(ctx, id, src)
|
|
|
|
}
|
|
|
|
|
|
|
|
// doWebClientNoiseRequest handles making the "/machine/webclient"
|
|
|
|
// noise requests to the control server for web client user auth.
|
|
|
|
//
|
|
|
|
// It either creates a new control auth URL or waits for an existing
|
|
|
|
// one to be completed, based on the presence or absence of the
|
|
|
|
// provided id value.
|
|
|
|
func (b *LocalBackend) doWebClientNoiseRequest(ctx context.Context, id string, src tailcfg.NodeID) (*tailcfg.WebClientAuthResponse, error) {
|
|
|
|
nm := b.NetMap()
|
|
|
|
if nm == nil || !nm.SelfNode.Valid() {
|
|
|
|
return nil, errors.New("[unexpected] no self node")
|
|
|
|
}
|
|
|
|
dst := nm.SelfNode.ID()
|
|
|
|
var noiseURL string
|
|
|
|
if id != "" {
|
|
|
|
noiseURL = fmt.Sprintf("https://unused/machine/webclient/wait/%d/to/%d/%s", src, dst, id)
|
|
|
|
} else {
|
|
|
|
noiseURL = fmt.Sprintf("https://unused/machine/webclient/init/%d/to/%d", src, dst)
|
|
|
|
}
|
|
|
|
|
|
|
|
req, err := http.NewRequestWithContext(ctx, "POST", noiseURL, nil)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
resp, err := b.DoNoiseRequest(req)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
body, _ := io.ReadAll(resp.Body)
|
|
|
|
resp.Body.Close()
|
|
|
|
if resp.StatusCode != http.StatusOK {
|
|
|
|
return nil, fmt.Errorf("failed request: %s", body)
|
|
|
|
}
|
|
|
|
var authResp *tailcfg.WebClientAuthResponse
|
|
|
|
if err := json.Unmarshal(body, &authResp); err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
return authResp, nil
|
|
|
|
}
|