// Package main implements a minimal mock server for POST /v1/nodes/:id/connect. // Returns a fixed sing-box config JSON per §3.1 contract (ARCHITECTURE.md). // // Usage: // // go run ./cmd/mockserver [-addr :8081] [-token ] // // 注:mock 联调;待 #5/#6 真实 connect 接口就绪后切换为真实后端。 // tsk_nuoKSM4Vt-zK (M6) package main import ( "encoding/json" "flag" "log" "net/http" "regexp" "strings" ) // connectConfig is the canonical sing-box config per §3.1. // Fields match the nodes table columns: reality_public_key / reality_short_id / hy2_password. // In production the API renders these per-user from the nodes table. // Placeholders here are mock values for integration testing only. const connectConfig = `{"log":{"level":"warn","timestamp":true},"inbounds":[{"type":"tun","tag":"tun-in","address":["172.19.0.1/30"],"mtu":9000,"auto_route":true,"strict_route":true,"stack":"system"}],"outbounds":[{"type":"vless","tag":"reality-out","server":"18.136.60.128","server_port":11443,"uuid":"ffffffff-ffff-ffff-ffff-ffffffffffff","flow":"xtls-rprx-vision","tls":{"enabled":true,"server_name":"www.apple.com","utls":{"enabled":true,"fingerprint":"chrome"},"reality":{"enabled":true,"public_key":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa","short_id":"deadbeef"}}},{"type":"hysteria2","tag":"hy2-out","server":"18.136.60.128","server_port":443,"password":"mock-hy2-password","tls":{"enabled":true,"insecure":true,"alpn":["h3"]}},{"type":"urltest","tag":"auto","outbounds":["reality-out","hy2-out"],"url":"https://www.gstatic.com/generate_204","interval":"3m","tolerance":50},{"type":"block","tag":"block"},{"type":"direct","tag":"direct"}],"route":{"rules":[{"ip_cidr":["10.0.0.0/8","172.16.0.0/12","192.168.0.0/16","127.0.0.0/8"],"outbound":"direct"}],"final":"auto","auto_detect_interface":true},"dns":{"servers":[{"tag":"remote","type":"tls","server":"8.8.8.8","detour":"auto"},{"tag":"local","type":"udp","server":"223.5.5.5"}],"final":"remote","strategy":"ipv4_only"}}` var reConnect = regexp.MustCompile(`^/v1/nodes/[^/]+/connect$`) func jsonErr(w http.ResponseWriter, status int, code, zh, en string) { w.Header().Set("Content-Type", "application/json") w.WriteHeader(status) _ = json.NewEncoder(w).Encode(map[string]string{ "code": code, "message_zh": zh, "message_en": en, }) } // makeHandler returns the HTTP handler for the mock connect server. // token may be empty to skip auth checking (useful in test environments). func makeHandler(token string) http.HandlerFunc { return func(w http.ResponseWriter, r *http.Request) { if !reConnect.MatchString(r.URL.Path) { http.NotFound(w, r) return } if r.Method != http.MethodPost { w.Header().Set("Allow", "POST") http.Error(w, "method not allowed", http.StatusMethodNotAllowed) return } if token != "" { got := strings.TrimPrefix(r.Header.Get("Authorization"), "Bearer ") if got != token { jsonErr(w, http.StatusUnauthorized, "unauthorized", "鉴权失败", "Unauthorized") return } } var body struct { DeviceID string `json:"device_id"` } if err := json.NewDecoder(r.Body).Decode(&body); err != nil || strings.TrimSpace(body.DeviceID) == "" { jsonErr(w, http.StatusBadRequest, "bad_request", "缺少 device_id", "Missing device_id") return } w.Header().Set("Content-Type", "application/json") _, _ = w.Write([]byte(connectConfig)) } } func main() { addr := flag.String("addr", ":8081", "listen address") token := flag.String("token", "", "required Bearer token (empty = skip auth check)") flag.Parse() log.Printf("[mock] pangolin connect server on %s auth=%v", *addr, *token != "") if err := http.ListenAndServe(*addr, makeHandler(*token)); err != nil { log.Fatal(err) } }