|
19 | 19 | import java.io.IOException; |
20 | 20 | import java.net.InetAddress; |
21 | 21 | import java.net.UnknownHostException; |
| 22 | +import java.security.KeyManagementException; |
| 23 | +import java.security.KeyStoreException; |
| 24 | +import java.security.NoSuchAlgorithmException; |
22 | 25 | import java.util.Iterator; |
23 | 26 | import java.util.Optional; |
24 | 27 | import java.util.concurrent.TimeUnit; |
25 | 28 | import org.apache.hc.client5.http.ConnectionKeepAliveStrategy; |
26 | 29 | import org.apache.hc.client5.http.DnsResolver; |
| 30 | +import org.apache.hc.client5.http.SchemePortResolver; |
27 | 31 | import org.apache.hc.client5.http.classic.HttpClient; |
28 | 32 | import org.apache.hc.client5.http.config.RequestConfig; |
29 | 33 | import org.apache.hc.client5.http.impl.classic.CloseableHttpClient; |
30 | 34 | import org.apache.hc.client5.http.impl.classic.HttpClients; |
| 35 | +import org.apache.hc.client5.http.impl.io.DefaultHttpClientConnectionOperator; |
31 | 36 | import org.apache.hc.client5.http.impl.io.PoolingHttpClientConnectionManager; |
32 | | -import org.apache.hc.client5.http.socket.ConnectionSocketFactory; |
| 37 | +import org.apache.hc.client5.http.impl.io.PoolingHttpClientConnectionManagerBuilder; |
| 38 | +import org.apache.hc.client5.http.io.HttpClientConnectionOperator; |
| 39 | +import org.apache.hc.client5.http.ssl.DefaultClientTlsStrategy; |
| 40 | +import org.apache.hc.client5.http.ssl.TlsSocketStrategy; |
| 41 | +import org.apache.hc.client5.http.ssl.TrustAllStrategy; |
33 | 42 | import org.apache.hc.core5.http.HeaderElement; |
34 | 43 | import org.apache.hc.core5.http.HeaderElements; |
35 | 44 | import org.apache.hc.core5.http.URIScheme; |
36 | | -import org.apache.hc.core5.http.config.Registry; |
37 | 45 | import org.apache.hc.core5.http.config.RegistryBuilder; |
38 | 46 | import org.apache.hc.core5.http.message.MessageSupport; |
39 | 47 | import org.apache.hc.core5.pool.PoolConcurrencyPolicy; |
40 | 48 | import org.apache.hc.core5.pool.PoolReusePolicy; |
| 49 | +import org.apache.hc.core5.ssl.SSLContextBuilder; |
41 | 50 | import org.apache.hc.core5.util.TimeValue; |
42 | 51 | import org.openziti.Ziti; |
43 | 52 | import org.openziti.ZitiContext; |
44 | | -import org.openziti.springboot.client.web.httpclient.ZitiConnectionSocketFactory; |
45 | | -import org.openziti.springboot.client.web.httpclient.ZitiSSLConnectionSocketFactory; |
46 | 53 | import org.springframework.beans.factory.BeanCreationException; |
47 | 54 | import org.springframework.beans.factory.annotation.Qualifier; |
48 | 55 | import org.springframework.beans.factory.annotation.Value; |
@@ -70,9 +77,6 @@ public class ZitiHttpClientConfiguration { |
70 | 77 | // The default time to keep a connection alive. |
71 | 78 | private static final long DEFAULT_KEEP_ALIVE_TIME_MILLIS = 20 * 1000; |
72 | 79 |
|
73 | | - private ZitiConnectionSocketFactory zitiConnectionSocketFactory; |
74 | | - private ZitiSSLConnectionSocketFactory zitiSSLConnectionSocketFactory; |
75 | | - |
76 | 80 | @ConditionalOnProperty(value = "spring.ziti.client.rest-template.enabled", havingValue = "true", matchIfMissing = true) |
77 | 81 | @Bean |
78 | 82 | public RestTemplate zitiRestTemplate(@Qualifier("zitiRestTemplateBuilder") RestTemplateBuilder restTemplateBuilder) { |
@@ -107,42 +111,39 @@ public ZitiContext context(@Value("${spring.ziti.client.identity.file:}") Resour |
107 | 111 | return Ziti.newContext(identityFile.getInputStream(), password.toCharArray()); |
108 | 112 | } |
109 | 113 |
|
110 | | - @ConditionalOnProperty(value = "spring.ziti.client.connection-factory.enabled", havingValue = "true", matchIfMissing = true) |
111 | | - @Bean("zitiConnectionSocketFactory") |
112 | | - public ZitiConnectionSocketFactory connectionSocketFactory(ZitiContext zitiContext) { |
113 | | - if (zitiConnectionSocketFactory == null) { |
114 | | - zitiConnectionSocketFactory = new ZitiConnectionSocketFactory(zitiContext); |
115 | | - } |
116 | | - return zitiConnectionSocketFactory; |
117 | | - } |
118 | | - |
119 | | - @ConditionalOnProperty(value = "spring.ziti.client.ssl-connection-factory.enabled", havingValue = "true", matchIfMissing = true) |
120 | | - @Bean("zitiSSLConnectionSocketFactory") |
121 | | - public ZitiSSLConnectionSocketFactory sslConnectionSocketFactory(ZitiContext zitiContext) { |
122 | | - if (zitiSSLConnectionSocketFactory == null) { |
123 | | - zitiSSLConnectionSocketFactory = new ZitiSSLConnectionSocketFactory(zitiContext); |
124 | | - } |
125 | | - return zitiSSLConnectionSocketFactory; |
| 114 | + @ConditionalOnProperty(value = "spring.ziti.client.tls-socket-strategy.enabled", havingValue = "true", matchIfMissing = true) |
| 115 | + @Bean("zitiTlsSocketStrategy") |
| 116 | + public TlsSocketStrategy zitiTlsSocketStrategy() throws NoSuchAlgorithmException, KeyStoreException, KeyManagementException { |
| 117 | + return new DefaultClientTlsStrategy(new SSLContextBuilder().loadTrustMaterial(null, TrustAllStrategy.INSTANCE).build()); |
126 | 118 | } |
127 | 119 |
|
128 | 120 | @ConditionalOnProperty(value = "spring.ziti.client.connection-manager.enabled", havingValue = "true", matchIfMissing = true) |
129 | 121 | @Bean("zitiPoolingConnectionManager") |
130 | 122 | public PoolingHttpClientConnectionManager poolingConnectionManager( |
131 | | - @Qualifier("zitiConnectionSocketFactory") ZitiConnectionSocketFactory zitiConnectionSocketFactory, |
132 | | - @Qualifier("zitiSSLConnectionSocketFactory") ZitiSSLConnectionSocketFactory zitiSSLConnectionSocketFactory, |
133 | 123 | @Qualifier("zitiDnsResolver") DnsResolver zitiDnsResolver, |
| 124 | + @Qualifier("zitiTlsSocketStrategy") TlsSocketStrategy zitiTlsSocketStrategy, |
134 | 125 | @Value("${spring.ziti.client.httpclient.max-total:}") Integer maxTotal, |
135 | 126 | @Value("${spring.ziti.client.httpclient.max-per-route:}") Integer maxPerRoute) { |
136 | 127 |
|
137 | | - final Registry<ConnectionSocketFactory> socketFactoryRegistry = RegistryBuilder.<ConnectionSocketFactory>create() |
138 | | - .register(URIScheme.HTTPS.getId(), zitiSSLConnectionSocketFactory) |
139 | | - .register(URIScheme.HTTP.getId(), zitiConnectionSocketFactory) |
| 128 | + final PoolingHttpClientConnectionManagerBuilder connectionManagerBuilder = new PoolingHttpClientConnectionManagerBuilder() { |
| 129 | + @Override |
| 130 | + protected HttpClientConnectionOperator createConnectionOperator( |
| 131 | + SchemePortResolver schemePortResolver, DnsResolver dnsResolver, TlsSocketStrategy tlsSocketStrategy) { |
| 132 | + return new DefaultHttpClientConnectionOperator( |
| 133 | + proxy -> Ziti.getSocketFactory().createSocket(), |
| 134 | + schemePortResolver, |
| 135 | + dnsResolver, |
| 136 | + RegistryBuilder.<TlsSocketStrategy>create() |
| 137 | + .register(URIScheme.HTTPS.id, tlsSocketStrategy) |
| 138 | + .build()); |
| 139 | + } |
| 140 | + }; |
| 141 | + final PoolingHttpClientConnectionManager poolingConnectionManager = connectionManagerBuilder |
| 142 | + .setDnsResolver(zitiDnsResolver) |
| 143 | + .setTlsSocketStrategy(zitiTlsSocketStrategy) |
| 144 | + .setConnPoolPolicy(PoolReusePolicy.LIFO) |
| 145 | + .setPoolConcurrencyPolicy(PoolConcurrencyPolicy.STRICT) |
140 | 146 | .build(); |
141 | | - |
142 | | - final PoolingHttpClientConnectionManager poolingConnectionManager = |
143 | | - new PoolingHttpClientConnectionManager(socketFactoryRegistry, PoolConcurrencyPolicy.STRICT, PoolReusePolicy.LIFO, |
144 | | - TimeValue.NEG_ONE_MILLISECOND, null, zitiDnsResolver, null); |
145 | | - |
146 | 147 | Optional.ofNullable(maxTotal).ifPresent(poolingConnectionManager::setMaxTotal); |
147 | 148 | Optional.ofNullable(maxPerRoute).ifPresent(poolingConnectionManager::setDefaultMaxPerRoute); |
148 | 149 | return poolingConnectionManager; |
@@ -185,12 +186,6 @@ public CloseableHttpClient httpClient( |
185 | 186 | .build(); |
186 | 187 | } |
187 | 188 |
|
188 | | - @PreDestroy |
189 | | - public void destroy() { |
190 | | - Optional.ofNullable(zitiConnectionSocketFactory).ifPresent(ZitiConnectionSocketFactory::shutdown); |
191 | | - Optional.ofNullable(zitiSSLConnectionSocketFactory).ifPresent(ZitiSSLConnectionSocketFactory::shutdown); |
192 | | - } |
193 | | - |
194 | 189 | @ConditionalOnProperty(value = "spring.ziti.client.dns-resolver.enabled", havingValue = "true", matchIfMissing = true) |
195 | 190 | @Bean("zitiDnsResolver") |
196 | 191 | public static DnsResolver dnsResolver() { |
|
0 commit comments