|
| 1 | +use axum::{Extension, middleware::AddExtension}; |
| 2 | +use axum_server::{accept::Accept, tls_rustls::RustlsAcceptor}; |
| 3 | +use futures::future::BoxFuture; |
| 4 | +use tokio::io::{AsyncRead, AsyncWrite}; |
| 5 | +use tokio_rustls::{rustls::pki_types::CertificateDer, server::TlsStream}; |
| 6 | +use tower::Layer as _; |
| 7 | +use tracing::instrument; |
| 8 | + |
| 9 | +#[derive(Clone, Debug)] |
| 10 | +pub struct TlsState { |
| 11 | + pub peer_certificates: Option<Vec<CertificateDer<'static>>>, |
| 12 | +} |
| 13 | + |
| 14 | +#[derive(Clone)] |
| 15 | +pub(crate) struct TlsAcceptor<A> { |
| 16 | + inner: RustlsAcceptor<A>, |
| 17 | +} |
| 18 | + |
| 19 | +impl<A> TlsAcceptor<A> { |
| 20 | + pub(crate) fn new(inner: RustlsAcceptor<A>) -> Self { |
| 21 | + Self { inner } |
| 22 | + } |
| 23 | +} |
| 24 | + |
| 25 | +impl<A, I, S> Accept<I, S> for TlsAcceptor<A> |
| 26 | +where |
| 27 | + A: Accept<I, S> + Clone + Send + 'static, |
| 28 | + A::Stream: AsyncRead + AsyncWrite + Unpin + Send, |
| 29 | + A::Service: Send, |
| 30 | + A::Future: Send, |
| 31 | + I: AsyncRead + AsyncWrite + Unpin + Send + 'static, |
| 32 | + S: Send + 'static, |
| 33 | +{ |
| 34 | + type Future = BoxFuture<'static, std::io::Result<(Self::Stream, Self::Service)>>; |
| 35 | + type Service = AddExtension<A::Service, TlsState>; |
| 36 | + type Stream = TlsStream<A::Stream>; |
| 37 | + |
| 38 | + #[instrument(skip_all)] |
| 39 | + fn accept(&self, stream: I, service: S) -> Self::Future { |
| 40 | + let acceptor = self.inner.clone(); |
| 41 | + |
| 42 | + Box::pin(async move { |
| 43 | + let (stream, service) = acceptor.accept(stream, service).await?; |
| 44 | + let server_conn = stream.get_ref().1; |
| 45 | + let tls_state = TlsState { |
| 46 | + peer_certificates: server_conn.peer_certificates().map(|c| c.to_owned()), |
| 47 | + }; |
| 48 | + |
| 49 | + let service = Extension(tls_state).layer(service); |
| 50 | + |
| 51 | + Ok((stream, service)) |
| 52 | + }) |
| 53 | + } |
| 54 | +} |
0 commit comments