1459
This commit is contained in:
1 parent
4ab47a3e47
commit
ba016efbe8
21 files changed
+921
-72
No files matched your search
@@ -29,29 +29,15 @@ server {
|
||||
access_log /var/log/nginx/write-server-access.log;
|
||||
error_log /var/log/nginx/write-server-error.log;
|
||||
|
||||
# 静态文件(登录页、Service Worker、htpasswd 验证)
|
||||
# 静态文件(Service Worker)
|
||||
location /sw.js {
|
||||
alias /etc/nginx/sw.js;
|
||||
add_header Content-Type application/javascript;
|
||||
add_header Cache-Control "no-cache, no-store";
|
||||
}
|
||||
|
||||
location /login.html {
|
||||
alias /etc/nginx/login.html;
|
||||
add_header Cache-Control "no-cache, no-store";
|
||||
}
|
||||
|
||||
location /auth/check {
|
||||
auth_basic "Write Server";
|
||||
auth_basic_user_file /etc/nginx/.htpasswd;
|
||||
return 200 'ok';
|
||||
add_header Content-Type text/plain;
|
||||
}
|
||||
|
||||
# 所有其他请求通过 auth_request 验证
|
||||
# 所有请求代理到 write-server
|
||||
location / {
|
||||
auth_request /auth/internal;
|
||||
|
||||
proxy_pass http://write-server:8016;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
@@ -66,22 +52,6 @@ server {
|
||||
proxy_send_timeout 60s;
|
||||
proxy_read_timeout 120s;
|
||||
client_max_body_size 50m;
|
||||
|
||||
error_page 401 = @login;
|
||||
}
|
||||
|
||||
location = /auth/internal {
|
||||
internal;
|
||||
proxy_pass http://write-server:8016/api/stats;
|
||||
proxy_set_header Authorization $http_authorization;
|
||||
proxy_pass_request_body off;
|
||||
proxy_set_header Content-Length "";
|
||||
}
|
||||
|
||||
location @login {
|
||||
internal;
|
||||
add_header WWW-Authenticate "";
|
||||
return 302 /login.html;
|
||||
}
|
||||
|
||||
location ~ /\. {
|
||||
|
||||
+12
-11
@@ -1,14 +1,18 @@
|
||||
const CACHE = 'v1';
|
||||
const LOGIN = '/login.html';
|
||||
const EXPIRE_MS = 3 * 60 * 60 * 1000; // 3小时
|
||||
const LOGIN = '/login';
|
||||
const EXPIRE_MS = 3 * 60 * 60 * 1000;
|
||||
|
||||
self.addEventListener('install', () => self.skipWaiting());
|
||||
|
||||
self.addEventListener('activate', e => e.waitUntil(self.clients.claim()));
|
||||
|
||||
self.addEventListener('fetch', e => {
|
||||
const req = e.request;
|
||||
if (req.url.includes('/login.html') || req.url.includes('/auth/')) {
|
||||
const url = new URL(req.url);
|
||||
|
||||
// 登录页、静态资源不拦截
|
||||
if (url.pathname === '/login' || url.pathname.startsWith('/_next/') ||
|
||||
url.pathname.endsWith('.js') || url.pathname.endsWith('.css') ||
|
||||
url.pathname.endsWith('.ico') || url.pathname.endsWith('.woff2')) {
|
||||
e.respondWith(fetch(req));
|
||||
return;
|
||||
}
|
||||
@@ -18,16 +22,13 @@ self.addEventListener('fetch', e => {
|
||||
const tokenTime = self.__auth_time || 0;
|
||||
|
||||
if (!token || (Date.now() - tokenTime > EXPIRE_MS)) {
|
||||
// token 过期或不存在,重定向到登录页
|
||||
if (token) {
|
||||
self.__auth_token = null;
|
||||
self.__auth_time = 0;
|
||||
}
|
||||
self.__auth_token = null;
|
||||
self.__auth_time = 0;
|
||||
return Response.redirect(LOGIN, 302);
|
||||
}
|
||||
|
||||
const headers = new Headers(req.headers);
|
||||
headers.set('Authorization', 'Basic ' + token);
|
||||
headers.set('X-Auth-User', token);
|
||||
const res = await fetch(new Request(req, { headers }));
|
||||
|
||||
if (res.status === 401) {
|
||||
@@ -35,11 +36,11 @@ self.addEventListener('fetch', e => {
|
||||
self.__auth_time = 0;
|
||||
return Response.redirect(LOGIN, 302);
|
||||
}
|
||||
|
||||
return res;
|
||||
})());
|
||||
});
|
||||
|
||||
// 接收页面发来的 token
|
||||
self.addEventListener('message', e => {
|
||||
if (e.data && e.data.type === 'SET_TOKEN') {
|
||||
self.__auth_token = e.data.token;
|
||||
|
||||
Reference in new issue
Block a user