Add the possibility to use TLS

This commit is contained in:
Frédéric Guillot 2017-11-22 11:16:48 -08:00
parent 38941f58cf
commit 199b1fd6c3
2 changed files with 29 additions and 6 deletions

View file

@ -18,6 +18,8 @@ const (
DefaultBatchSize = 10 DefaultBatchSize = 10
DefaultDatabaseMaxConns = 20 DefaultDatabaseMaxConns = 20
DefaultListenAddr = "127.0.0.1:8080" DefaultListenAddr = "127.0.0.1:8080"
DefaultCertFile = ""
DefaultKeyFile = ""
) )
// Config manages configuration parameters. // Config manages configuration parameters.

View file

@ -5,10 +5,12 @@
package server package server
import ( import (
"crypto/tls"
"log" "log"
"net/http" "net/http"
"time" "time"
"github.com/gorilla/mux"
"github.com/miniflux/miniflux2/scheduler" "github.com/miniflux/miniflux2/scheduler"
"github.com/miniflux/miniflux2/config" "github.com/miniflux/miniflux2/config"
@ -18,20 +20,39 @@ import (
// NewServer returns a new HTTP server. // NewServer returns a new HTTP server.
func NewServer(cfg *config.Config, store *storage.Storage, pool *scheduler.WorkerPool, feedHandler *feed.Handler) *http.Server { func NewServer(cfg *config.Config, store *storage.Storage, pool *scheduler.WorkerPool, feedHandler *feed.Handler) *http.Server {
return startServer(cfg, getRoutes(cfg, store, feedHandler, pool))
}
func startServer(cfg *config.Config, handler *mux.Router) *http.Server {
certFile := cfg.Get("CERT_FILE", config.DefaultCertFile)
keyFile := cfg.Get("KEY_FILE", config.DefaultKeyFile)
server := &http.Server{ server := &http.Server{
ReadTimeout: 5 * time.Second, ReadTimeout: 5 * time.Second,
WriteTimeout: 10 * time.Second, WriteTimeout: 10 * time.Second,
IdleTimeout: 60 * time.Second, IdleTimeout: 60 * time.Second,
Addr: cfg.Get("LISTEN_ADDR", config.DefaultListenAddr), Addr: cfg.Get("LISTEN_ADDR", config.DefaultListenAddr),
Handler: getRoutes(cfg, store, feedHandler, pool), Handler: handler,
} }
go func() { if certFile != "" && keyFile != "" {
log.Printf("Listening on %s\n", server.Addr) server.TLSConfig = &tls.Config{
if err := server.ListenAndServe(); err != nil { MinVersion: tls.VersionTLS12,
log.Fatal(err)
} }
}()
go func() {
log.Printf(`Listening on "%s" by using certificate "%s" and key "%s"`, server.Addr, certFile, keyFile)
if err := server.ListenAndServeTLS(certFile, keyFile); err != nil {
log.Fatalln(err)
}
}()
} else {
go func() {
log.Printf(`Listening on "%s" without TLS`, server.Addr)
if err := server.ListenAndServe(); err != nil {
log.Fatalln(err)
}
}()
}
return server return server
} }