client_server_test.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661
  1. // Copyright 2013 The Gorilla WebSocket Authors. All rights reserved.
  2. // Use of this source code is governed by a BSD-style
  3. // license that can be found in the LICENSE file.
  4. package websocket
  5. import (
  6. "bytes"
  7. "crypto/tls"
  8. "crypto/x509"
  9. "encoding/base64"
  10. "encoding/binary"
  11. "io"
  12. "io/ioutil"
  13. "net"
  14. "net/http"
  15. "net/http/cookiejar"
  16. "net/http/httptest"
  17. "net/url"
  18. "reflect"
  19. "strings"
  20. "testing"
  21. "time"
  22. )
  23. var cstUpgrader = Upgrader{
  24. Subprotocols: []string{"p0", "p1"},
  25. ReadBufferSize: 1024,
  26. WriteBufferSize: 1024,
  27. EnableCompression: true,
  28. Error: func(w http.ResponseWriter, r *http.Request, status int, reason error) {
  29. http.Error(w, reason.Error(), status)
  30. },
  31. }
  32. var cstDialer = Dialer{
  33. Subprotocols: []string{"p1", "p2"},
  34. ReadBufferSize: 1024,
  35. WriteBufferSize: 1024,
  36. HandshakeTimeout: 30 * time.Second,
  37. }
  38. type cstHandler struct{ *testing.T }
  39. type cstServer struct {
  40. *httptest.Server
  41. URL string
  42. }
  43. const (
  44. cstPath = "/a/b"
  45. cstRawQuery = "x=y"
  46. cstRequestURI = cstPath + "?" + cstRawQuery
  47. )
  48. func newServer(t *testing.T) *cstServer {
  49. var s cstServer
  50. s.Server = httptest.NewServer(cstHandler{t})
  51. s.Server.URL += cstRequestURI
  52. s.URL = makeWsProto(s.Server.URL)
  53. return &s
  54. }
  55. func newTLSServer(t *testing.T) *cstServer {
  56. var s cstServer
  57. s.Server = httptest.NewTLSServer(cstHandler{t})
  58. s.Server.URL += cstRequestURI
  59. s.URL = makeWsProto(s.Server.URL)
  60. return &s
  61. }
  62. func (t cstHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  63. if r.URL.Path != cstPath {
  64. t.Logf("path=%v, want %v", r.URL.Path, cstPath)
  65. http.Error(w, "bad path", http.StatusBadRequest)
  66. return
  67. }
  68. if r.URL.RawQuery != cstRawQuery {
  69. t.Logf("query=%v, want %v", r.URL.RawQuery, cstRawQuery)
  70. http.Error(w, "bad path", http.StatusBadRequest)
  71. return
  72. }
  73. subprotos := Subprotocols(r)
  74. if !reflect.DeepEqual(subprotos, cstDialer.Subprotocols) {
  75. t.Logf("subprotols=%v, want %v", subprotos, cstDialer.Subprotocols)
  76. http.Error(w, "bad protocol", http.StatusBadRequest)
  77. return
  78. }
  79. ws, err := cstUpgrader.Upgrade(w, r, http.Header{"Set-Cookie": {"sessionID=1234"}})
  80. if err != nil {
  81. t.Logf("Upgrade: %v", err)
  82. return
  83. }
  84. defer ws.Close()
  85. if ws.Subprotocol() != "p1" {
  86. t.Logf("Subprotocol() = %s, want p1", ws.Subprotocol())
  87. ws.Close()
  88. return
  89. }
  90. op, rd, err := ws.NextReader()
  91. if err != nil {
  92. t.Logf("NextReader: %v", err)
  93. return
  94. }
  95. wr, err := ws.NextWriter(op)
  96. if err != nil {
  97. t.Logf("NextWriter: %v", err)
  98. return
  99. }
  100. if _, err = io.Copy(wr, rd); err != nil {
  101. t.Logf("NextWriter: %v", err)
  102. return
  103. }
  104. if err := wr.Close(); err != nil {
  105. t.Logf("Close: %v", err)
  106. return
  107. }
  108. }
  109. func makeWsProto(s string) string {
  110. return "ws" + strings.TrimPrefix(s, "http")
  111. }
  112. func sendRecv(t *testing.T, ws *Conn) {
  113. const message = "Hello World!"
  114. if err := ws.SetWriteDeadline(time.Now().Add(time.Second)); err != nil {
  115. t.Fatalf("SetWriteDeadline: %v", err)
  116. }
  117. if err := ws.WriteMessage(TextMessage, []byte(message)); err != nil {
  118. t.Fatalf("WriteMessage: %v", err)
  119. }
  120. if err := ws.SetReadDeadline(time.Now().Add(time.Second)); err != nil {
  121. t.Fatalf("SetReadDeadline: %v", err)
  122. }
  123. _, p, err := ws.ReadMessage()
  124. if err != nil {
  125. t.Fatalf("ReadMessage: %v", err)
  126. }
  127. if string(p) != message {
  128. t.Fatalf("message=%s, want %s", p, message)
  129. }
  130. }
  131. func TestProxyDial(t *testing.T) {
  132. s := newServer(t)
  133. defer s.Close()
  134. surl, _ := url.Parse(s.Server.URL)
  135. cstDialer := cstDialer // make local copy for modification on next line.
  136. cstDialer.Proxy = http.ProxyURL(surl)
  137. connect := false
  138. origHandler := s.Server.Config.Handler
  139. // Capture the request Host header.
  140. s.Server.Config.Handler = http.HandlerFunc(
  141. func(w http.ResponseWriter, r *http.Request) {
  142. if r.Method == "CONNECT" {
  143. connect = true
  144. w.WriteHeader(http.StatusOK)
  145. return
  146. }
  147. if !connect {
  148. t.Log("connect not received")
  149. http.Error(w, "connect not received", http.StatusMethodNotAllowed)
  150. return
  151. }
  152. origHandler.ServeHTTP(w, r)
  153. })
  154. ws, _, err := cstDialer.Dial(s.URL, nil)
  155. if err != nil {
  156. t.Fatalf("Dial: %v", err)
  157. }
  158. defer ws.Close()
  159. sendRecv(t, ws)
  160. }
  161. func TestProxyAuthorizationDial(t *testing.T) {
  162. s := newServer(t)
  163. defer s.Close()
  164. surl, _ := url.Parse(s.Server.URL)
  165. surl.User = url.UserPassword("username", "password")
  166. cstDialer := cstDialer // make local copy for modification on next line.
  167. cstDialer.Proxy = http.ProxyURL(surl)
  168. connect := false
  169. origHandler := s.Server.Config.Handler
  170. // Capture the request Host header.
  171. s.Server.Config.Handler = http.HandlerFunc(
  172. func(w http.ResponseWriter, r *http.Request) {
  173. proxyAuth := r.Header.Get("Proxy-Authorization")
  174. expectedProxyAuth := "Basic " + base64.StdEncoding.EncodeToString([]byte("username:password"))
  175. if r.Method == "CONNECT" && proxyAuth == expectedProxyAuth {
  176. connect = true
  177. w.WriteHeader(http.StatusOK)
  178. return
  179. }
  180. if !connect {
  181. t.Log("connect with proxy authorization not received")
  182. http.Error(w, "connect with proxy authorization not received", http.StatusMethodNotAllowed)
  183. return
  184. }
  185. origHandler.ServeHTTP(w, r)
  186. })
  187. ws, _, err := cstDialer.Dial(s.URL, nil)
  188. if err != nil {
  189. t.Fatalf("Dial: %v", err)
  190. }
  191. defer ws.Close()
  192. sendRecv(t, ws)
  193. }
  194. func TestDial(t *testing.T) {
  195. s := newServer(t)
  196. defer s.Close()
  197. ws, _, err := cstDialer.Dial(s.URL, nil)
  198. if err != nil {
  199. t.Fatalf("Dial: %v", err)
  200. }
  201. defer ws.Close()
  202. sendRecv(t, ws)
  203. }
  204. func TestDialCookieJar(t *testing.T) {
  205. s := newServer(t)
  206. defer s.Close()
  207. jar, _ := cookiejar.New(nil)
  208. d := cstDialer
  209. d.Jar = jar
  210. u, _ := url.Parse(s.URL)
  211. switch u.Scheme {
  212. case "ws":
  213. u.Scheme = "http"
  214. case "wss":
  215. u.Scheme = "https"
  216. }
  217. cookies := []*http.Cookie{{Name: "gorilla", Value: "ws", Path: "/"}}
  218. d.Jar.SetCookies(u, cookies)
  219. ws, _, err := d.Dial(s.URL, nil)
  220. if err != nil {
  221. t.Fatalf("Dial: %v", err)
  222. }
  223. defer ws.Close()
  224. var gorilla string
  225. var sessionID string
  226. for _, c := range d.Jar.Cookies(u) {
  227. if c.Name == "gorilla" {
  228. gorilla = c.Value
  229. }
  230. if c.Name == "sessionID" {
  231. sessionID = c.Value
  232. }
  233. }
  234. if gorilla != "ws" {
  235. t.Error("Cookie not present in jar.")
  236. }
  237. if sessionID != "1234" {
  238. t.Error("Set-Cookie not received from the server.")
  239. }
  240. sendRecv(t, ws)
  241. }
  242. func TestDialTLS(t *testing.T) {
  243. s := newTLSServer(t)
  244. defer s.Close()
  245. certs := x509.NewCertPool()
  246. for _, c := range s.TLS.Certificates {
  247. roots, err := x509.ParseCertificates(c.Certificate[len(c.Certificate)-1])
  248. if err != nil {
  249. t.Fatalf("error parsing server's root cert: %v", err)
  250. }
  251. for _, root := range roots {
  252. certs.AddCert(root)
  253. }
  254. }
  255. d := cstDialer
  256. d.TLSClientConfig = &tls.Config{RootCAs: certs}
  257. ws, _, err := d.Dial(s.URL, nil)
  258. if err != nil {
  259. t.Fatalf("Dial: %v", err)
  260. }
  261. defer ws.Close()
  262. sendRecv(t, ws)
  263. }
  264. func xTestDialTLSBadCert(t *testing.T) {
  265. // This test is deactivated because of noisy logging from the net/http package.
  266. s := newTLSServer(t)
  267. defer s.Close()
  268. ws, _, err := cstDialer.Dial(s.URL, nil)
  269. if err == nil {
  270. ws.Close()
  271. t.Fatalf("Dial: nil")
  272. }
  273. }
  274. func TestDialTLSNoVerify(t *testing.T) {
  275. s := newTLSServer(t)
  276. defer s.Close()
  277. d := cstDialer
  278. d.TLSClientConfig = &tls.Config{InsecureSkipVerify: true}
  279. ws, _, err := d.Dial(s.URL, nil)
  280. if err != nil {
  281. t.Fatalf("Dial: %v", err)
  282. }
  283. defer ws.Close()
  284. sendRecv(t, ws)
  285. }
  286. func TestDialTimeout(t *testing.T) {
  287. s := newServer(t)
  288. defer s.Close()
  289. d := cstDialer
  290. d.HandshakeTimeout = -1
  291. ws, _, err := d.Dial(s.URL, nil)
  292. if err == nil {
  293. ws.Close()
  294. t.Fatalf("Dial: nil")
  295. }
  296. }
  297. // requireDeadlineNetConn fails the current test when Read or Write are called
  298. // with no deadline.
  299. type requireDeadlineNetConn struct {
  300. t *testing.T
  301. c net.Conn
  302. readDeadlineIsSet bool
  303. writeDeadlineIsSet bool
  304. }
  305. func (c *requireDeadlineNetConn) SetDeadline(t time.Time) error {
  306. c.writeDeadlineIsSet = !t.Equal(time.Time{})
  307. c.readDeadlineIsSet = c.writeDeadlineIsSet
  308. return c.c.SetDeadline(t)
  309. }
  310. func (c *requireDeadlineNetConn) SetReadDeadline(t time.Time) error {
  311. c.readDeadlineIsSet = !t.Equal(time.Time{})
  312. return c.c.SetDeadline(t)
  313. }
  314. func (c *requireDeadlineNetConn) SetWriteDeadline(t time.Time) error {
  315. c.writeDeadlineIsSet = !t.Equal(time.Time{})
  316. return c.c.SetDeadline(t)
  317. }
  318. func (c *requireDeadlineNetConn) Write(p []byte) (int, error) {
  319. if !c.writeDeadlineIsSet {
  320. c.t.Fatalf("write with no deadline")
  321. }
  322. return c.c.Write(p)
  323. }
  324. func (c *requireDeadlineNetConn) Read(p []byte) (int, error) {
  325. if !c.readDeadlineIsSet {
  326. c.t.Fatalf("read with no deadline")
  327. }
  328. return c.c.Read(p)
  329. }
  330. func (c *requireDeadlineNetConn) Close() error { return c.c.Close() }
  331. func (c *requireDeadlineNetConn) LocalAddr() net.Addr { return c.c.LocalAddr() }
  332. func (c *requireDeadlineNetConn) RemoteAddr() net.Addr { return c.c.RemoteAddr() }
  333. func TestHandshakeTimeout(t *testing.T) {
  334. s := newServer(t)
  335. defer s.Close()
  336. d := cstDialer
  337. d.NetDial = func(n, a string) (net.Conn, error) {
  338. c, err := net.Dial(n, a)
  339. return &requireDeadlineNetConn{c: c, t: t}, err
  340. }
  341. ws, _, err := d.Dial(s.URL, nil)
  342. if err != nil {
  343. t.Fatal("Dial:", err)
  344. }
  345. ws.Close()
  346. }
  347. func TestDialBadScheme(t *testing.T) {
  348. s := newServer(t)
  349. defer s.Close()
  350. ws, _, err := cstDialer.Dial(s.Server.URL, nil)
  351. if err == nil {
  352. ws.Close()
  353. t.Fatalf("Dial: nil")
  354. }
  355. }
  356. func TestDialBadOrigin(t *testing.T) {
  357. s := newServer(t)
  358. defer s.Close()
  359. ws, resp, err := cstDialer.Dial(s.URL, http.Header{"Origin": {"bad"}})
  360. if err == nil {
  361. ws.Close()
  362. t.Fatalf("Dial: nil")
  363. }
  364. if resp == nil {
  365. t.Fatalf("resp=nil, err=%v", err)
  366. }
  367. if resp.StatusCode != http.StatusForbidden {
  368. t.Fatalf("status=%d, want %d", resp.StatusCode, http.StatusForbidden)
  369. }
  370. }
  371. func TestDialBadHeader(t *testing.T) {
  372. s := newServer(t)
  373. defer s.Close()
  374. for _, k := range []string{"Upgrade",
  375. "Connection",
  376. "Sec-Websocket-Key",
  377. "Sec-Websocket-Version",
  378. "Sec-Websocket-Protocol"} {
  379. h := http.Header{}
  380. h.Set(k, "bad")
  381. ws, _, err := cstDialer.Dial(s.URL, http.Header{"Origin": {"bad"}})
  382. if err == nil {
  383. ws.Close()
  384. t.Errorf("Dial with header %s returned nil", k)
  385. }
  386. }
  387. }
  388. func TestBadMethod(t *testing.T) {
  389. s := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
  390. ws, err := cstUpgrader.Upgrade(w, r, nil)
  391. if err == nil {
  392. t.Errorf("handshake succeeded, expect fail")
  393. ws.Close()
  394. }
  395. }))
  396. defer s.Close()
  397. req, err := http.NewRequest("POST", s.URL, strings.NewReader(""))
  398. if err != nil {
  399. t.Fatalf("NewRequest returned error %v", err)
  400. }
  401. req.Header.Set("Connection", "upgrade")
  402. req.Header.Set("Upgrade", "websocket")
  403. req.Header.Set("Sec-Websocket-Version", "13")
  404. resp, err := http.DefaultClient.Do(req)
  405. if err != nil {
  406. t.Fatalf("Do returned error %v", err)
  407. }
  408. resp.Body.Close()
  409. if resp.StatusCode != http.StatusMethodNotAllowed {
  410. t.Errorf("Status = %d, want %d", resp.StatusCode, http.StatusMethodNotAllowed)
  411. }
  412. }
  413. func TestHandshake(t *testing.T) {
  414. s := newServer(t)
  415. defer s.Close()
  416. ws, resp, err := cstDialer.Dial(s.URL, http.Header{"Origin": {s.URL}})
  417. if err != nil {
  418. t.Fatalf("Dial: %v", err)
  419. }
  420. defer ws.Close()
  421. var sessionID string
  422. for _, c := range resp.Cookies() {
  423. if c.Name == "sessionID" {
  424. sessionID = c.Value
  425. }
  426. }
  427. if sessionID != "1234" {
  428. t.Error("Set-Cookie not received from the server.")
  429. }
  430. if ws.Subprotocol() != "p1" {
  431. t.Errorf("ws.Subprotocol() = %s, want p1", ws.Subprotocol())
  432. }
  433. sendRecv(t, ws)
  434. }
  435. func TestRespOnBadHandshake(t *testing.T) {
  436. const expectedStatus = http.StatusGone
  437. const expectedBody = "This is the response body."
  438. s := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
  439. w.WriteHeader(expectedStatus)
  440. io.WriteString(w, expectedBody)
  441. }))
  442. defer s.Close()
  443. ws, resp, err := cstDialer.Dial(makeWsProto(s.URL), nil)
  444. if err == nil {
  445. ws.Close()
  446. t.Fatalf("Dial: nil")
  447. }
  448. if resp == nil {
  449. t.Fatalf("resp=nil, err=%v", err)
  450. }
  451. if resp.StatusCode != expectedStatus {
  452. t.Errorf("resp.StatusCode=%d, want %d", resp.StatusCode, expectedStatus)
  453. }
  454. p, err := ioutil.ReadAll(resp.Body)
  455. if err != nil {
  456. t.Fatalf("ReadFull(resp.Body) returned error %v", err)
  457. }
  458. if string(p) != expectedBody {
  459. t.Errorf("resp.Body=%s, want %s", p, expectedBody)
  460. }
  461. }
  462. // TestHostHeader confirms that the host header provided in the call to Dial is
  463. // sent to the server.
  464. func TestHostHeader(t *testing.T) {
  465. s := newServer(t)
  466. defer s.Close()
  467. specifiedHost := make(chan string, 1)
  468. origHandler := s.Server.Config.Handler
  469. // Capture the request Host header.
  470. s.Server.Config.Handler = http.HandlerFunc(
  471. func(w http.ResponseWriter, r *http.Request) {
  472. specifiedHost <- r.Host
  473. origHandler.ServeHTTP(w, r)
  474. })
  475. ws, _, err := cstDialer.Dial(s.URL, http.Header{"Host": {"testhost"}})
  476. if err != nil {
  477. t.Fatalf("Dial: %v", err)
  478. }
  479. defer ws.Close()
  480. if gotHost := <-specifiedHost; gotHost != "testhost" {
  481. t.Fatalf("gotHost = %q, want \"testhost\"", gotHost)
  482. }
  483. sendRecv(t, ws)
  484. }
  485. func TestDialCompression(t *testing.T) {
  486. s := newServer(t)
  487. defer s.Close()
  488. dialer := cstDialer
  489. dialer.EnableCompression = true
  490. ws, _, err := dialer.Dial(s.URL, nil)
  491. if err != nil {
  492. t.Fatalf("Dial: %v", err)
  493. }
  494. defer ws.Close()
  495. sendRecv(t, ws)
  496. }
  497. func TestSocksProxyDial(t *testing.T) {
  498. s := newServer(t)
  499. defer s.Close()
  500. proxyListener, err := net.Listen("tcp", "127.0.0.1:0")
  501. if err != nil {
  502. t.Fatalf("listen failed: %v", err)
  503. }
  504. defer proxyListener.Close()
  505. go func() {
  506. c1, err := proxyListener.Accept()
  507. if err != nil {
  508. t.Errorf("proxy accept failed: %v", err)
  509. return
  510. }
  511. defer c1.Close()
  512. c1.SetDeadline(time.Now().Add(30 * time.Second))
  513. buf := make([]byte, 32)
  514. if _, err := io.ReadFull(c1, buf[:3]); err != nil {
  515. t.Errorf("read failed: %v", err)
  516. return
  517. }
  518. if want := []byte{5, 1, 0}; !bytes.Equal(want, buf[:len(want)]) {
  519. t.Errorf("read %x, want %x", buf[:len(want)], want)
  520. }
  521. if _, err := c1.Write([]byte{5, 0}); err != nil {
  522. t.Errorf("write failed: %v", err)
  523. return
  524. }
  525. if _, err := io.ReadFull(c1, buf[:10]); err != nil {
  526. t.Errorf("read failed: %v", err)
  527. return
  528. }
  529. if want := []byte{5, 1, 0, 1}; !bytes.Equal(want, buf[:len(want)]) {
  530. t.Errorf("read %x, want %x", buf[:len(want)], want)
  531. return
  532. }
  533. buf[1] = 0
  534. if _, err := c1.Write(buf[:10]); err != nil {
  535. t.Errorf("write failed: %v", err)
  536. return
  537. }
  538. ip := net.IP(buf[4:8])
  539. port := binary.BigEndian.Uint16(buf[8:10])
  540. c2, err := net.DialTCP("tcp", nil, &net.TCPAddr{IP: ip, Port: int(port)})
  541. if err != nil {
  542. t.Errorf("dial failed; %v", err)
  543. return
  544. }
  545. defer c2.Close()
  546. done := make(chan struct{})
  547. go func() {
  548. io.Copy(c1, c2)
  549. close(done)
  550. }()
  551. io.Copy(c2, c1)
  552. <-done
  553. }()
  554. purl, err := url.Parse("socks5://" + proxyListener.Addr().String())
  555. if err != nil {
  556. t.Fatalf("parse failed: %v", err)
  557. }
  558. cstDialer := cstDialer // make local copy for modification on next line.
  559. cstDialer.Proxy = http.ProxyURL(purl)
  560. ws, _, err := cstDialer.Dial(s.URL, nil)
  561. if err != nil {
  562. t.Fatalf("Dial: %v", err)
  563. }
  564. defer ws.Close()
  565. sendRecv(t, ws)
  566. }