|
| 1 | +use futures_util::future::TryFutureExt; |
| 2 | +use futures_util::stream::{Stream, TryStreamExt}; |
| 3 | +use hyper::service::{make_service_fn, service_fn}; |
| 4 | +use hyper::{Body, Request, Response, Server}; |
1 | 5 | use std::convert::Infallible; |
| 6 | +use std::io; |
2 | 7 | use std::net::SocketAddr; |
3 | | -use hyper::{Body, Request, Response, Server}; |
4 | | -use hyper::service::{make_service_fn, service_fn}; |
| 8 | +use tokio::net::{TcpListener, TcpStream}; |
| 9 | +use tokio_rustls::server::TlsStream; |
| 10 | +use tokio_rustls::TlsAcceptor; |
5 | 11 |
|
6 | 12 | async fn hello_world(_req: Request<Body>) -> Result<Response<Body>, Infallible> { |
7 | 13 | Ok(Response::new("Hello, World".into())) |
8 | 14 | } |
9 | 15 |
|
| 16 | +fn error(err: String) -> std::io::Error { |
| 17 | + std::io::Error::new(std::io::ErrorKind::Other, err) |
| 18 | +} |
| 19 | + |
10 | 20 | #[tokio::main] |
11 | | -async fn main() { |
| 21 | +async fn main() -> io::Result<()> { |
12 | 22 | // We'll bind to 127.0.0.1:3000 |
13 | 23 | let addr = SocketAddr::from(([127, 0, 0, 1], 3000)); |
14 | 24 |
|
| 25 | + // Build TLS configuration. |
| 26 | + let tls_cfg = { |
| 27 | + // Load public certificate. |
| 28 | + let mut cert_reader = io::BufReader::new(std::fs::File::open("./ssl_certs/server.crt")?); |
| 29 | + let certs = rustls::internal::pemfile::certs(&mut cert_reader).unwrap(); |
| 30 | + // Load private key. |
| 31 | + let mut key_reader = io::BufReader::new(std::fs::File::open("./ssl_certs/server.key")?); |
| 32 | + // Load and return a single private key. |
| 33 | + let mut keys = rustls::internal::pemfile::pkcs8_private_keys(&mut key_reader).unwrap(); |
| 34 | + // Do not use client certificate authentication. |
| 35 | + let mut cfg = rustls::ServerConfig::new(rustls::NoClientAuth::new()); |
| 36 | + // Select a certificate to use. |
| 37 | + cfg.set_single_cert(certs, keys.remove(0)).unwrap(); |
| 38 | + // Configure ALPN to accept HTTP/2, HTTP/1.1 in that order. |
| 39 | + cfg.set_protocols(&[b"h2".to_vec(), b"http/1.1".to_vec()]); |
| 40 | + std::sync::Arc::new(cfg) |
| 41 | + }; |
| 42 | + |
| 43 | + // Create a TCP listener via tokio. |
| 44 | + let mut tcp = TcpListener::bind(&addr).await?; |
| 45 | + let tls_acceptor = TlsAcceptor::from(tls_cfg); |
| 46 | + // Prepare a long-running future stream to accept and serve clients. |
| 47 | + let incoming_tls_stream = tcp |
| 48 | + .incoming() |
| 49 | + .map_err(|e| error(format!("Incoming failed: {:?}", e))) |
| 50 | + .and_then(move |s| { |
| 51 | + tls_acceptor.accept(s).map_err(|e| { |
| 52 | + println!("[!] Voluntary server halt due to client-connection error..."); |
| 53 | + // Errors could be handled here, instead of server aborting. |
| 54 | + // Ok(None) |
| 55 | + error(format!("TLS Error: {:?}", e)) |
| 56 | + }) |
| 57 | + }); |
| 58 | + |
15 | 59 | // A `Service` is needed for every connection, so this |
16 | 60 | // creates one from our `hello_world` function. |
17 | 61 | let make_svc = make_service_fn(|_conn| async { |
18 | 62 | // service_fn converts our function into a `Service` |
19 | 63 | Ok::<_, Infallible>(service_fn(hello_world)) |
20 | 64 | }); |
21 | 65 |
|
22 | | - let server = Server::bind(&addr).serve(make_svc); |
| 66 | + let server = Server::builder(HyperAcceptor { |
| 67 | + acceptor: Box::pin(incoming_tls_stream), |
| 68 | + }) |
| 69 | + .serve(make_svc); |
23 | 70 |
|
24 | 71 | // Run this server for... forever! |
25 | 72 | if let Err(e) = server.await { |
26 | 73 | eprintln!("server error: {}", e); |
27 | 74 | } |
| 75 | + Ok(()) |
| 76 | +} |
| 77 | + |
| 78 | +struct HyperAcceptor<S> { |
| 79 | + acceptor: core::pin::Pin<Box<S>>, |
| 80 | +} |
| 81 | + |
| 82 | +impl<S> hyper::server::accept::Accept for HyperAcceptor<S> |
| 83 | +where |
| 84 | + S: Stream<Item = Result<TlsStream<TcpStream>, io::Error>>, |
| 85 | +{ |
| 86 | + type Conn = TlsStream<TcpStream>; |
| 87 | + type Error = io::Error; |
| 88 | + |
| 89 | + fn poll_accept( |
| 90 | + mut self: core::pin::Pin<&mut Self>, |
| 91 | + cx: &mut core::task::Context, |
| 92 | + ) -> core::task::Poll<Option<Result<Self::Conn, Self::Error>>> { |
| 93 | + self.acceptor.as_mut().poll_next(cx) |
| 94 | + } |
28 | 95 | } |
0 commit comments