From 07fae7ecf9f93e3e9e862c92c3b09b5152d8e5f1 Mon Sep 17 00:00:00 2001
From: Monviech <79600909+Monviech@users.noreply.github.com>
Date: Sun, 29 Sep 2024 09:11:58 +0200
Subject: [PATCH] www/caddy: Add redir directive to HTTP Handler (#4263)
* www/caddy: Directive can be chosen in HTTP Handler, redir added to create HTTP redirects.
* www/caddy: Disable reverse_proxy specific fields when redir is chosen, these fields do not generate anything in the config even when they have been filled out. The disable property makes that clearer to the user. Unhide directive from advanced mode so its easier to create basic redirects. Clean up style names for consistency.
* www/caddy: HandleDirective does not need default in template
---
www/caddy/Makefile | 3 +-
www/caddy/pkg-descr | 4 ++
.../OPNsense/Caddy/forms/dialogHandle.xml | 41 +++++++++++--------
.../Caddy/forms/dialogReverseProxy.xml | 4 +-
.../mvc/app/models/OPNsense/Caddy/Caddy.xml | 10 ++++-
.../views/OPNsense/Caddy/reverse_proxy.volt | 20 ++++++---
.../templates/OPNsense/Caddy/Caddyfile | 17 +++++++-
7 files changed, 71 insertions(+), 28 deletions(-)
diff --git a/www/caddy/Makefile b/www/caddy/Makefile
index 00b7379f0..259bea8b2 100644
--- a/www/caddy/Makefile
+++ b/www/caddy/Makefile
@@ -1,6 +1,5 @@
PLUGIN_NAME= caddy
-PLUGIN_VERSION= 1.7.1
-PLUGIN_REVISION= 1
+PLUGIN_VERSION= 1.7.2
PLUGIN_DEPENDS= caddy-custom
PLUGIN_COMMENT= Modern Reverse Proxy with Automatic HTTPS, Dynamic DNS and Layer4 Routing
PLUGIN_MAINTAINER= cedrik@pischem.com
diff --git a/www/caddy/pkg-descr b/www/caddy/pkg-descr
index 47d8458bb..b6dc9e1bd 100644
--- a/www/caddy/pkg-descr
+++ b/www/caddy/pkg-descr
@@ -13,6 +13,10 @@ DOC: https://docs.opnsense.org/manual/how-tos/caddy.html
Plugin Changelog
================
+1.7.2
+
+* Add: Directive in HTTP Handler can be chosen, "reverse_proxy" and "redir"
+
1.7.1
* Add: Frontend HTTP Version can be selected in General Settings, can be used to disable QUIC protocol
diff --git a/www/caddy/src/opnsense/mvc/app/controllers/OPNsense/Caddy/forms/dialogHandle.xml b/www/caddy/src/opnsense/mvc/app/controllers/OPNsense/Caddy/forms/dialogHandle.xml
index 6cbba6939..43e3fa997 100644
--- a/www/caddy/src/opnsense/mvc/app/controllers/OPNsense/Caddy/forms/dialogHandle.xml
+++ b/www/caddy/src/opnsense/mvc/app/controllers/OPNsense/Caddy/forms/dialogHandle.xml
@@ -37,7 +37,7 @@
handle.HandleType
dropdown
-
+
true
@@ -45,7 +45,7 @@
text
any
-
+
true
@@ -69,17 +69,13 @@
header
-
- true
+
- handle.header
-
+ handle.HandleDirective
+
dropdown
- select_multiple
- 5
-
- true
+
header
@@ -89,14 +85,26 @@
handle.HttpVersion
dropdown
+
true
+
+ handle.header
+
+ dropdown
+ select_multiple
+ 5
+
+
+ true
+
handle.HttpKeepalive
text
120
+
true
@@ -113,7 +121,7 @@
true
192.168.1.1
-
+
handle.ToPort
@@ -126,13 +134,14 @@
handle.ToPath
text
-
+
true
handle.PassiveHealthFailDuration
text
+
true
@@ -140,28 +149,28 @@
handle.HttpTlsInsecureSkipVerify
checkbox
-
+
handle.HttpTlsTrustedCaCerts
dropdown
-
+
handle.HttpTlsServerName
text
-
+
handle.HttpNtlm
checkbox
-
+
diff --git a/www/caddy/src/opnsense/mvc/app/controllers/OPNsense/Caddy/forms/dialogReverseProxy.xml b/www/caddy/src/opnsense/mvc/app/controllers/OPNsense/Caddy/forms/dialogReverseProxy.xml
index 5cba4c1a2..46642786b 100644
--- a/www/caddy/src/opnsense/mvc/app/controllers/OPNsense/Caddy/forms/dialogReverseProxy.xml
+++ b/www/caddy/src/opnsense/mvc/app/controllers/OPNsense/Caddy/forms/dialogReverseProxy.xml
@@ -39,7 +39,7 @@
reverse.CustomCertificate
dropdown
-
+
@@ -53,7 +53,7 @@
reverse.DnsChallenge
checkbox
-
+
diff --git a/www/caddy/src/opnsense/mvc/app/models/OPNsense/Caddy/Caddy.xml b/www/caddy/src/opnsense/mvc/app/models/OPNsense/Caddy/Caddy.xml
index c4ae85caf..c663b3960 100644
--- a/www/caddy/src/opnsense/mvc/app/models/OPNsense/Caddy/Caddy.xml
+++ b/www/caddy/src/opnsense/mvc/app/models/OPNsense/Caddy/Caddy.xml
@@ -1,7 +1,7 @@
//Pischem/caddy
Caddy Reverse Proxy
- 1.3.1
+ 1.3.2
@@ -325,6 +325,14 @@
Y
+
+ Y
+ reverse_proxy
+
+ reverse_proxy
+ redir
+
+
Y
,
diff --git a/www/caddy/src/opnsense/mvc/app/views/OPNsense/Caddy/reverse_proxy.volt b/www/caddy/src/opnsense/mvc/app/views/OPNsense/Caddy/reverse_proxy.volt
index 2473da5bf..ee1b2f5ab 100644
--- a/www/caddy/src/opnsense/mvc/app/views/OPNsense/Caddy/reverse_proxy.volt
+++ b/www/caddy/src/opnsense/mvc/app/views/OPNsense/Caddy/reverse_proxy.volt
@@ -313,20 +313,29 @@
}
});
- // Show TLS options based on chosen protocol
$("#handle\\.HttpTls").change(function() {
if ($(this).val() === "0") {
- $(".HttpTls").closest('tr').hide();
+ $(".style_tls").closest('tr').hide();
} else {
- $(".HttpTls").closest('tr').show();
+ $(".style_tls").closest('tr').show();
+ }
+ });
+
+ $("#handle\\.HandleDirective").change(function() {
+ if ($(this).val() === "redir") {
+ $(".style_reverse_proxy").prop('disabled', true);
+ $("#handle\\.header").selectpicker('refresh');
+ } else {
+ $(".style_reverse_proxy").prop('disabled', false);
+ $("#handle\\.header").selectpicker('refresh');
}
});
$("#reverse\\.DisableTls").change(function() {
if ($(this).val() === "1") {
- $(".DisableTls").closest('tr').hide();
+ $(".style_tls").closest('tr').hide();
} else {
- $(".DisableTls").closest('tr').show();
+ $(".style_tls").closest('tr').show();
}
});
@@ -468,6 +477,7 @@
| {{ lang._('Handler') }} |
{{ lang._('Path') }} |
{{ lang._('HTTP Headers') }} |
+ {{ lang._('Directive') }} |
{{ lang._('Protocol') }} |
{{ lang._('Upstream Domain') }} |
{{ lang._('Upstream Port') }} |
diff --git a/www/caddy/src/opnsense/service/templates/OPNsense/Caddy/Caddyfile b/www/caddy/src/opnsense/service/templates/OPNsense/Caddy/Caddyfile
index a710e61ed..0fd8fc9fd 100644
--- a/www/caddy/src/opnsense/service/templates/OPNsense/Caddy/Caddyfile
+++ b/www/caddy/src/opnsense/service/templates/OPNsense/Caddy/Caddyfile
@@ -384,10 +384,11 @@ http://{{ domain }} {
{% if handle.ForwardAuth|default("0") == "1" %}
{% include "OPNsense/Caddy/includeAuthProvider" %}
{% endif %}
- {% if handle.ToPath|default("") != "" %}
+ {% if handle.HandleDirective == "reverse_proxy" and handle.ToPath|default("") != "" %}
rewrite * {{ handle.ToPath }}{uri}
{% endif %}
- reverse_proxy {% for domain in handle.ToDomain.split(',') %}
+ {% if handle.HandleDirective == "reverse_proxy" %}
+ {{ handle.HandleDirective }} {% for domain in handle.ToDomain.split(',') %}
{# Check if the domain is IPv6 and wrap in square brackets if necessary #}
{% set is_ipv6 = (':' in domain and domain.count(':') >= 2) %}
{# For each domain/IP, append the port if it's specified, followed by a space #}
@@ -430,6 +431,18 @@ http://{{ domain }} {
}
{% endif %}
}
+ {% else %}
+ {% set protocol = 'https://' if handle.HttpTls == "1" else 'http://' %}
+ {% set domain = handle.ToDomain.split(',')[0] %}
+ {% set is_ipv6 = (':' in domain and domain.count(':') >= 2) %}
+ {% set formatted_domain = ('[' ~ domain ~ ']') if is_ipv6 else domain %}
+ {% if handle.ToPort %}
+ {% set domain_with_port = formatted_domain ~ ':' ~ handle.ToPort %}
+ {% else %}
+ {% set domain_with_port = formatted_domain %}
+ {% endif %}
+ {{ handle.HandleDirective }} {{ protocol }}{{ domain_with_port }}{{ handle.ToPath|default("{uri}") }}
+ {% endif %}
}
{% endmacro %}