Initial commit: Rampart v0.2.0
Multi-layer DDoS protection for Minecraft servers. - rampart-core: Edge node with XDP/eBPF + Rust L7 filtering - rampart-manager: REST API with JWT auth, Redis sync - rampart-cli: CLI tool for operators - velocity-plugin: Domain check, HMAC verify, server registry, load balancer - paper-plugin: Auto-registration, heartbeat, HMAC verify - dashboard: React + Vite web UI for management
This commit is contained in:
commit
cf9608ce5d
159 changed files with 15341 additions and 0 deletions
30
plugins/velocity/.classpath
Normal file
30
plugins/velocity/.classpath
Normal file
|
|
@ -0,0 +1,30 @@
|
|||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<classpath>
|
||||
<classpathentry kind="src" output="bin/main" path="src/main/java">
|
||||
<attributes>
|
||||
<attribute name="gradle_scope" value="main"/>
|
||||
<attribute name="gradle_used_by_scope" value="main,test"/>
|
||||
</attributes>
|
||||
</classpathentry>
|
||||
<classpathentry kind="src" output="bin/test" path="src/test/java">
|
||||
<attributes>
|
||||
<attribute name="gradle_scope" value="test"/>
|
||||
<attribute name="gradle_used_by_scope" value="test"/>
|
||||
<attribute name="test" value="true"/>
|
||||
</attributes>
|
||||
</classpathentry>
|
||||
<classpathentry kind="con" path="org.eclipse.jdt.launching.JRE_CONTAINER/org.eclipse.jdt.internal.debug.ui.launcher.StandardVMType/JavaSE-21/"/>
|
||||
<classpathentry kind="con" path="org.eclipse.buildship.core.gradleclasspathcontainer"/>
|
||||
<classpathentry kind="src" path="bin/generated-sources/annotations">
|
||||
<attributes>
|
||||
<attribute name="optional" value="true"/>
|
||||
</attributes>
|
||||
</classpathentry>
|
||||
<classpathentry kind="src" output="bin/test" path="bin/generated-test-sources/annotations">
|
||||
<attributes>
|
||||
<attribute name="optional" value="true"/>
|
||||
<attribute name="test" value="true"/>
|
||||
</attributes>
|
||||
</classpathentry>
|
||||
<classpathentry kind="output" path="bin/default"/>
|
||||
</classpath>
|
||||
40
plugins/velocity/.factorypath
Normal file
40
plugins/velocity/.factorypath
Normal file
|
|
@ -0,0 +1,40 @@
|
|||
<factorypath>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/org.spongepowered/configurate-hocon/4.1.2/3953a4aef8ff62c72d34e405d6df333f3876592a/configurate-hocon-4.1.2.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/org.slf4j/slf4j-api/2.0.17/d9e58ac9c7779ba3bf8142aff6c830617a7fe60f/slf4j-api-2.0.17.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.velocitypowered/velocity-brigadier/1.0.0-SNAPSHOT/c85456381b9942f529995996793190c091ef57a9/velocity-brigadier-1.0.0-SNAPSHOT.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/adventure-key/4.26.1/6ded614dc07cc6c2da418a8e907ee42325badcda/adventure-key-4.26.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/org.spongepowered/configurate-gson/4.1.2/3e5c7a0ea73e95ce6139fa72f1b6d36eb531ab81/configurate-gson-4.1.2.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.google.j2objc/j2objc-annotations/1.3/ba035118bc8bac37d7eff77700720999acd9986d/j2objc-annotations-1.3.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/org.spongepowered/configurate-yaml/4.1.2/f726180c21ec387be5b8a2e04d916443c4046207/configurate-yaml-4.1.2.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/aopalliance/aopalliance/1.0/235ba8b489512805ac13a8f9ea77a1ca5ebe3e8/aopalliance-1.0.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.google.code.findbugs/jsr305/3.0.2/25ea2e8b0c338a877313bd4672d3fe056ea78f0d/jsr305-3.0.2.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/org.checkerframework/checker-qual/3.42.0/638ec33f363a94d41a4f03c3e7d3dcfba64e402d/checker-qual-3.42.0.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.google.errorprone/error_prone_annotations/2.21.1/6d9b10773b5237df178a7b3c1b4208df7d0e7f94/error_prone_annotations-2.21.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/adventure-text-serializer-json/4.26.1/7f98d4d9105254b1567379629a52236f5ebaf215/adventure-text-serializer-json-4.26.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/adventure-text-serializer-plain/4.26.1/cce5ad32da24b824edc8518535431059340873d5/adventure-text-serializer-plain-4.26.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/option/1.1.0/593fecb9c42688eebc7d8da5d6ea127f4d4c92a2/option-1.1.0.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/adventure-text-serializer-legacy/4.26.1/3267b14ac7fa167b97beb8c114d87d83609847af/adventure-text-serializer-legacy-4.26.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.google.guava/listenablefuture/9999.0-empty-to-avoid-conflict-with-guava/b421526c5f297295adef1c886e5246c39d4ac629/listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/org.spongepowered/configurate-core/4.1.2/d6728b04738e73847f6a26349cf4368362feab97/configurate-core-4.1.2.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.github.ben-manes.caffeine/caffeine/3.1.8/24795585df8afaf70a2cd534786904ea5889c047/caffeine-3.1.8.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/adventure-text-serializer-commons/4.26.1/ef0ca2d1307415c9700d8e2f04adf283d6da46fa/adventure-text-serializer-commons-4.26.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/examination-api/1.3.0/8a2d185275307f1e2ef2adf7152b9a0d1d44c30b/examination-api-1.3.0.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.google.code.gson/gson/2.10.1/b3add478d4382b78ea20b1671390a858002feb6c/gson-2.10.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/adventure-text-serializer-ansi/4.26.1/7b441092ed57af2445872daa652ba2fce5deba31/adventure-text-serializer-ansi-4.26.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/jakarta.inject/jakarta.inject-api/2.0.1/4c28afe1991a941d7702fe1362c365f0a8641d1e/jakarta.inject-api-2.0.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.moandjiezana.toml/toml4j/0.7.2/a03337911d0bd2c40932aca3946edb30d0e7d0c/toml4j-0.7.2.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.google.inject/guice/6.0.0/9b422c69c4fa1ea95b2615444a94fede9b02fc40/guice-6.0.0.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/examination-string/1.3.0/6f34afef5c54ccce4996bc321abf77518b55b4bd/examination-string-1.3.0.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.google.guava/failureaccess/1.0.1/1dcf1de382a0bf95a3d8b0849546c88bac1292c9/failureaccess-1.0.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/ansi/1.1.1/beeb71e49b25cac87c22975014e74c7b5940d1b7/ansi-1.1.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.typesafe/config/1.4.1/19058a07624a87f90d129af7cd9c68bee94535a9/config-1.4.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/adventure-text-serializer-gson/4.26.1/3523abdae3098630e4ce9e808bb25e3f71ca60d1/adventure-text-serializer-gson-4.26.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.google.guava/guava/31.0.1-jre/119ea2b2bc205b138974d351777b20f02b92704b/guava-31.0.1-jre.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/adventure-text-minimessage/4.26.1/9983d86668d6adba7e600dac20a5e61af703a6c6/adventure-text-minimessage-4.26.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/io.leangen.geantyref/geantyref/1.3.11/bc9c03b53917314d21fe6276aceb08aa84bf80dd/geantyref-1.3.11.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/adventure-text-logger-slf4j/4.26.1/f18d40094ec8f64087f420069f06e024558d74d6/adventure-text-logger-slf4j-4.26.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/org.yaml/snakeyaml/1.33/2cd0a87ff7df953f810c344bdf2fe3340b954c69/snakeyaml-1.33.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/javax.inject/javax.inject/1/6975da39a7040257bd51d21a231b76c915872d38/javax.inject-1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/net.kyori/adventure-api/4.26.1/907ea365968cae9bdd84d19f2c258f65cf5f12a4/adventure-api-4.26.1.jar" enabled="true" runInBatchMode="false"/>
|
||||
<factorypathentry kind="EXTJAR" id="/home/loki/.gradle/caches/modules-2/files-2.1/com.velocitypowered/velocity-api/3.4.0-SNAPSHOT/f8b024e83389b5293b1efa55f1753de8151b79fa/velocity-api-3.4.0-SNAPSHOT.jar" enabled="true" runInBatchMode="false"/>
|
||||
</factorypath>
|
||||
34
plugins/velocity/.project
Normal file
34
plugins/velocity/.project
Normal file
|
|
@ -0,0 +1,34 @@
|
|||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<projectDescription>
|
||||
<name>velocity</name>
|
||||
<comment>Project velocity created by Buildship.</comment>
|
||||
<projects>
|
||||
</projects>
|
||||
<buildSpec>
|
||||
<buildCommand>
|
||||
<name>org.eclipse.jdt.core.javabuilder</name>
|
||||
<arguments>
|
||||
</arguments>
|
||||
</buildCommand>
|
||||
<buildCommand>
|
||||
<name>org.eclipse.buildship.core.gradleprojectbuilder</name>
|
||||
<arguments>
|
||||
</arguments>
|
||||
</buildCommand>
|
||||
</buildSpec>
|
||||
<natures>
|
||||
<nature>org.eclipse.jdt.core.javanature</nature>
|
||||
<nature>org.eclipse.buildship.core.gradleprojectnature</nature>
|
||||
</natures>
|
||||
<filteredResources>
|
||||
<filter>
|
||||
<id>1784566057672</id>
|
||||
<name></name>
|
||||
<type>30</type>
|
||||
<matcher>
|
||||
<id>org.eclipse.core.resources.regexFilterMatcher</id>
|
||||
<arguments>node_modules|\.git|__CREATED_BY_JAVA_LANGUAGE_SERVER__</arguments>
|
||||
</matcher>
|
||||
</filter>
|
||||
</filteredResources>
|
||||
</projectDescription>
|
||||
|
|
@ -0,0 +1,2 @@
|
|||
connection.project.dir=..
|
||||
eclipse.preferences.version=1
|
||||
|
|
@ -0,0 +1,4 @@
|
|||
eclipse.preferences.version=1
|
||||
org.eclipse.jdt.apt.aptEnabled=true
|
||||
org.eclipse.jdt.apt.genSrcDir=bin/generated-sources/annotations
|
||||
org.eclipse.jdt.apt.genTestSrcDir=bin/generated-test-sources/annotations
|
||||
2
plugins/velocity/.settings/org.eclipse.jdt.core.prefs
Normal file
2
plugins/velocity/.settings/org.eclipse.jdt.core.prefs
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
eclipse.preferences.version=1
|
||||
org.eclipse.jdt.core.compiler.processAnnotations=enabled
|
||||
1
plugins/velocity/bin/default/velocity-plugin.json
Normal file
1
plugins/velocity/bin/default/velocity-plugin.json
Normal file
|
|
@ -0,0 +1 @@
|
|||
{"id":"rampart","name":"Rampart","version":"0.1.0","description":"HMAC hostname verification + domain whitelist + Redis server registry for Rampart","authors":["loki"],"dependencies":[],"main":"me.rampart.velocity.RampartVelocity"}
|
||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
BIN
plugins/velocity/bin/main/me/rampart/velocity/ServerRouter.class
Normal file
BIN
plugins/velocity/bin/main/me/rampart/velocity/ServerRouter.class
Normal file
Binary file not shown.
37
plugins/velocity/build.gradle.kts
Normal file
37
plugins/velocity/build.gradle.kts
Normal file
|
|
@ -0,0 +1,37 @@
|
|||
plugins {
|
||||
id("java")
|
||||
id("com.gradleup.shadow") version "9.0.0-beta2"
|
||||
}
|
||||
|
||||
repositories {
|
||||
mavenCentral()
|
||||
maven("https://papermc.io/repo/repository/maven-public/")
|
||||
}
|
||||
|
||||
dependencies {
|
||||
compileOnly("com.velocitypowered:velocity-api:3.4.0-SNAPSHOT")
|
||||
annotationProcessor("com.velocitypowered:velocity-api:3.4.0-SNAPSHOT")
|
||||
|
||||
implementation("redis.clients:jedis:5.2.0")
|
||||
|
||||
testImplementation("org.junit.jupiter:junit-jupiter:5.11.4")
|
||||
testImplementation("org.slf4j:slf4j-api:2.0.16")
|
||||
testRuntimeOnly("org.slf4j:slf4j-simple:2.0.16")
|
||||
testRuntimeOnly("org.junit.platform:junit-platform-launcher")
|
||||
}
|
||||
|
||||
tasks.withType<Test> {
|
||||
useJUnitPlatform()
|
||||
}
|
||||
|
||||
tasks {
|
||||
shadowJar {
|
||||
archiveBaseName.set("rampart-velocity")
|
||||
archiveClassifier.set("")
|
||||
archiveVersion.set(project.property("version").toString())
|
||||
}
|
||||
|
||||
build {
|
||||
dependsOn(shadowJar)
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,56 @@
|
|||
package me.rampart.velocity;
|
||||
|
||||
import com.velocitypowered.api.event.Subscribe;
|
||||
import com.velocitypowered.api.event.connection.LoginEvent;
|
||||
import net.kyori.adventure.text.Component;
|
||||
import org.slf4j.Logger;
|
||||
|
||||
import java.net.InetSocketAddress;
|
||||
import java.util.List;
|
||||
|
||||
public class DomainCheckListener {
|
||||
|
||||
private final Logger logger;
|
||||
private final List<String> allowedDomains;
|
||||
|
||||
public DomainCheckListener(Logger logger, List<String> allowedDomains) {
|
||||
this.logger = logger;
|
||||
this.allowedDomains = allowedDomains;
|
||||
}
|
||||
|
||||
@Subscribe
|
||||
public void onLogin(LoginEvent event) {
|
||||
if (allowedDomains.isEmpty()) return;
|
||||
|
||||
var player = event.getPlayer();
|
||||
String hostname = player.getVirtualHost()
|
||||
.map(InetSocketAddress::getHostString)
|
||||
.orElse("");
|
||||
|
||||
if (hostname.isEmpty()) {
|
||||
event.setResult(LoginEvent.ComponentResult.denied(
|
||||
Component.text("Connection rejected: no hostname")
|
||||
));
|
||||
return;
|
||||
}
|
||||
|
||||
String clean = hostname.split("\0")[0];
|
||||
|
||||
if (DomainCheckUtil.isIpAddress(clean)) {
|
||||
logger.warn("Direct IP connect blocked from {} (hostname: {})",
|
||||
player.getRemoteAddress(), clean);
|
||||
event.setResult(LoginEvent.ComponentResult.denied(
|
||||
Component.text("Direct IP connections are not allowed")
|
||||
));
|
||||
return;
|
||||
}
|
||||
|
||||
if (!DomainCheckUtil.isDomainAllowed(clean, allowedDomains)) {
|
||||
logger.warn("Domain not allowed from {} (hostname: {})",
|
||||
player.getRemoteAddress(), clean);
|
||||
event.setResult(LoginEvent.ComponentResult.denied(
|
||||
Component.text("This domain is not allowed")
|
||||
));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,33 @@
|
|||
package me.rampart.velocity;
|
||||
|
||||
import java.util.List;
|
||||
|
||||
public class DomainCheckUtil {
|
||||
|
||||
public static boolean isIpAddress(String hostname) {
|
||||
if (hostname == null || hostname.isEmpty()) return false;
|
||||
|
||||
if (hostname.chars().allMatch(c -> c == '.' || Character.isDigit(c))) {
|
||||
String[] parts = hostname.split("\\.");
|
||||
if (parts.length == 4) {
|
||||
try {
|
||||
for (String p : parts) {
|
||||
int val = Integer.parseInt(p);
|
||||
if (val < 0 || val > 255) return false;
|
||||
}
|
||||
return true;
|
||||
} catch (NumberFormatException e) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
public static boolean isDomainAllowed(String hostname, List<String> allowedDomains) {
|
||||
if (allowedDomains == null || allowedDomains.isEmpty()) return true;
|
||||
String clean = hostname.split("\0")[0];
|
||||
return allowedDomains.stream()
|
||||
.anyMatch(d -> clean.equals(d) || clean.endsWith("." + d));
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,107 @@
|
|||
package me.rampart.velocity;
|
||||
|
||||
import com.velocitypowered.api.event.Subscribe;
|
||||
import com.velocitypowered.api.event.connection.LoginEvent;
|
||||
import net.kyori.adventure.text.Component;
|
||||
import org.slf4j.Logger;
|
||||
|
||||
import javax.crypto.Mac;
|
||||
import javax.crypto.spec.SecretKeySpec;
|
||||
import java.security.InvalidKeyException;
|
||||
import java.security.NoSuchAlgorithmException;
|
||||
|
||||
public class HmacCheckListener {
|
||||
|
||||
private static final String SHIELD_SEPARATOR = "\0shield\0";
|
||||
private static final String HMAC_ALGO = "HmacSHA256";
|
||||
private static final int HEX_SIG_LENGTH = 64;
|
||||
|
||||
private final Logger logger;
|
||||
private final byte[] secret;
|
||||
|
||||
public HmacCheckListener(Logger logger, String secret) {
|
||||
this.logger = logger;
|
||||
this.secret = secret.getBytes();
|
||||
}
|
||||
|
||||
@Subscribe
|
||||
public void onLogin(LoginEvent event) {
|
||||
var player = event.getPlayer();
|
||||
var vh = player.getVirtualHost();
|
||||
if (vh.isEmpty()) {
|
||||
event.setResult(LoginEvent.ComponentResult.denied(
|
||||
Component.text("Connection rejected: no virtual host")
|
||||
));
|
||||
return;
|
||||
}
|
||||
|
||||
String raw = vh.get().getHostString();
|
||||
if (raw == null || raw.isEmpty()) {
|
||||
event.setResult(LoginEvent.ComponentResult.denied(
|
||||
Component.text("Connection rejected: empty hostname")
|
||||
));
|
||||
return;
|
||||
}
|
||||
|
||||
int sepIdx = raw.indexOf(SHIELD_SEPARATOR);
|
||||
if (sepIdx < 0) {
|
||||
event.setResult(LoginEvent.ComponentResult.denied(
|
||||
Component.text("Connection rejected: unsigned connection")
|
||||
));
|
||||
return;
|
||||
}
|
||||
|
||||
String domain = raw.substring(0, sepIdx);
|
||||
String sig = raw.substring(sepIdx + SHIELD_SEPARATOR.length());
|
||||
|
||||
if (sig.length() != HEX_SIG_LENGTH) {
|
||||
logger.warn("Invalid HMAC signature length from {}: got {}, expected {}",
|
||||
player.getRemoteAddress(), sig.length(), HEX_SIG_LENGTH);
|
||||
event.setResult(LoginEvent.ComponentResult.denied(
|
||||
Component.text("Connection rejected: invalid signature")
|
||||
));
|
||||
return;
|
||||
}
|
||||
|
||||
String expected = hmacHex(domain);
|
||||
if (expected == null) {
|
||||
event.setResult(LoginEvent.ComponentResult.denied(
|
||||
Component.text("Connection rejected: internal error")
|
||||
));
|
||||
return;
|
||||
}
|
||||
|
||||
if (!constantTimeEquals(sig, expected)) {
|
||||
logger.warn("HMAC verification failed for {} (domain: {})",
|
||||
player.getRemoteAddress(), domain);
|
||||
event.setResult(LoginEvent.ComponentResult.denied(
|
||||
Component.text("Connection rejected: invalid signature")
|
||||
));
|
||||
}
|
||||
}
|
||||
|
||||
private String hmacHex(String data) {
|
||||
try {
|
||||
Mac mac = Mac.getInstance(HMAC_ALGO);
|
||||
mac.init(new SecretKeySpec(secret, HMAC_ALGO));
|
||||
byte[] raw = mac.doFinal(data.getBytes());
|
||||
StringBuilder sb = new StringBuilder(raw.length * 2);
|
||||
for (byte b : raw) {
|
||||
sb.append(String.format("%02x", b & 0xFF));
|
||||
}
|
||||
return sb.toString();
|
||||
} catch (NoSuchAlgorithmException | InvalidKeyException e) {
|
||||
logger.error("HMAC error", e);
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
private boolean constantTimeEquals(String a, String b) {
|
||||
if (a.length() != b.length()) return false;
|
||||
int result = 0;
|
||||
for (int i = 0; i < a.length(); i++) {
|
||||
result |= a.charAt(i) ^ b.charAt(i);
|
||||
}
|
||||
return result == 0;
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,64 @@
|
|||
package me.rampart.velocity;
|
||||
|
||||
import com.google.inject.Inject;
|
||||
import com.velocitypowered.api.event.EventManager;
|
||||
import com.velocitypowered.api.plugin.Plugin;
|
||||
import com.velocitypowered.api.proxy.ProxyServer;
|
||||
import org.slf4j.Logger;
|
||||
|
||||
import java.util.Arrays;
|
||||
import java.util.Collections;
|
||||
import java.util.List;
|
||||
|
||||
@Plugin(
|
||||
id = "rampart",
|
||||
name = "Rampart",
|
||||
version = "0.1.0",
|
||||
description = "HMAC hostname verification + domain whitelist + Redis server registry for Rampart",
|
||||
authors = {"loki"}
|
||||
)
|
||||
public class RampartVelocity {
|
||||
|
||||
private final Logger logger;
|
||||
private final ServerRegistry serverRegistry;
|
||||
|
||||
@Inject
|
||||
public RampartVelocity(ProxyServer server, Logger logger) {
|
||||
this.logger = logger;
|
||||
|
||||
String secret = System.getenv("RAMPART_HMAC_SECRET");
|
||||
List<String> allowed = loadDomainWhitelist();
|
||||
|
||||
if (!allowed.isEmpty()) {
|
||||
logger.info("Domain whitelist: {} domains loaded", allowed.size());
|
||||
server.getEventManager().register(this, new DomainCheckListener(logger, allowed));
|
||||
} else {
|
||||
logger.warn("RAMPART_ALLOWED_DOMAINS not set — domain check disabled");
|
||||
}
|
||||
|
||||
if (secret != null && !secret.isEmpty()) {
|
||||
logger.info("HMAC verification enabled");
|
||||
server.getEventManager().register(this, new HmacCheckListener(logger, secret));
|
||||
} else {
|
||||
logger.warn("RAMPART_HMAC_SECRET not set — HMAC verification disabled");
|
||||
}
|
||||
|
||||
String redisUrl = System.getenv("RAMPART_REDIS_URL");
|
||||
if (redisUrl == null || redisUrl.isEmpty()) {
|
||||
redisUrl = "redis://127.0.0.1:6379/0";
|
||||
}
|
||||
|
||||
serverRegistry = new ServerRegistry(server, logger, redisUrl);
|
||||
serverRegistry.startSync();
|
||||
logger.info("Server registry sync started with Redis at {}", redisUrl);
|
||||
}
|
||||
|
||||
private List<String> loadDomainWhitelist() {
|
||||
String env = System.getenv("RAMPART_ALLOWED_DOMAINS");
|
||||
if (env == null || env.isEmpty()) return Collections.emptyList();
|
||||
return Arrays.stream(env.split(","))
|
||||
.map(String::trim)
|
||||
.filter(s -> !s.isEmpty())
|
||||
.toList();
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,142 @@
|
|||
package me.rampart.velocity;
|
||||
|
||||
import com.velocitypowered.api.proxy.ProxyServer;
|
||||
import com.velocitypowered.api.proxy.server.RegisteredServer;
|
||||
import com.velocitypowered.api.proxy.server.ServerInfo;
|
||||
import org.slf4j.Logger;
|
||||
import redis.clients.jedis.Jedis;
|
||||
|
||||
import java.net.InetSocketAddress;
|
||||
import java.util.ArrayList;
|
||||
import java.util.List;
|
||||
import java.util.Objects;
|
||||
import java.util.Optional;
|
||||
import java.util.Set;
|
||||
import java.util.concurrent.TimeUnit;
|
||||
import java.util.concurrent.atomic.AtomicInteger;
|
||||
import java.util.stream.Collectors;
|
||||
|
||||
public class ServerRegistry {
|
||||
|
||||
private final ProxyServer proxyServer;
|
||||
private final Logger logger;
|
||||
private final String redisUrl;
|
||||
private final AtomicInteger counter = new AtomicInteger(0);
|
||||
private volatile List<RegisteredServer> cachedServers = new ArrayList<>();
|
||||
|
||||
public ServerRegistry(ProxyServer proxyServer, Logger logger, String redisUrl) {
|
||||
this.proxyServer = proxyServer;
|
||||
this.logger = logger;
|
||||
this.redisUrl = redisUrl;
|
||||
}
|
||||
|
||||
public void startSync() {
|
||||
loadAndUpdateServers();
|
||||
proxyServer.getScheduler()
|
||||
.buildTask(this, this::loadAndUpdateServers)
|
||||
.repeat(30, TimeUnit.SECONDS)
|
||||
.schedule();
|
||||
}
|
||||
|
||||
void loadAndUpdateServers() {
|
||||
List<ServerInfo> redisServers = loadServersFromRedis();
|
||||
Set<String> redisNames = redisServers.stream()
|
||||
.map(ServerInfo::getName)
|
||||
.collect(Collectors.toSet());
|
||||
Set<String> registeredNames = proxyServer.getAllServers().stream()
|
||||
.map(s -> s.getServerInfo().getName())
|
||||
.collect(Collectors.toSet());
|
||||
|
||||
int registered = 0;
|
||||
int unregistered = 0;
|
||||
|
||||
for (ServerInfo info : redisServers) {
|
||||
if (!registeredNames.contains(info.getName())) {
|
||||
proxyServer.registerServer(info);
|
||||
registered++;
|
||||
}
|
||||
}
|
||||
|
||||
for (String name : registeredNames) {
|
||||
if (!redisNames.contains(name)) {
|
||||
proxyServer.getServer(name).ifPresent(s ->
|
||||
proxyServer.unregisterServer(s.getServerInfo()));
|
||||
unregistered++;
|
||||
}
|
||||
}
|
||||
|
||||
List<RegisteredServer> servers = redisServers.stream()
|
||||
.map(info -> proxyServer.getServer(info.getName()).orElse(null))
|
||||
.filter(Objects::nonNull)
|
||||
.collect(Collectors.toList());
|
||||
|
||||
cachedServers = servers;
|
||||
|
||||
logger.info("Server sync complete: {} registered, {} unregistered, {} online",
|
||||
registered, unregistered, servers.size());
|
||||
}
|
||||
|
||||
List<ServerInfo> loadServersFromRedis() {
|
||||
List<ServerInfo> servers = new ArrayList<>();
|
||||
try (Jedis jedis = new Jedis(redisUrl)) {
|
||||
Set<String> keys = jedis.keys("rampart:servers:*");
|
||||
for (String key : keys) {
|
||||
String json = jedis.get(key);
|
||||
if (json == null || json.isEmpty()) continue;
|
||||
try {
|
||||
String name = extractJsonString(json, "name");
|
||||
String ip = extractJsonString(json, "ip");
|
||||
if (name == null || ip == null) continue;
|
||||
int port = extractJsonInt(json, "port");
|
||||
if (port <= 0) continue;
|
||||
String status = extractJsonString(json, "status");
|
||||
if (!"online".equals(status)) continue;
|
||||
servers.add(new ServerInfo(name, InetSocketAddress.createUnresolved(ip, port)));
|
||||
} catch (Exception e) {
|
||||
logger.warn("Failed to parse server data for key {}: {}", key, e.getMessage());
|
||||
}
|
||||
}
|
||||
} catch (Exception e) {
|
||||
logger.warn("Failed to connect to Redis at {}: {}", redisUrl, e.getMessage());
|
||||
}
|
||||
return servers;
|
||||
}
|
||||
|
||||
public Optional<RegisteredServer> getNextServer() {
|
||||
List<RegisteredServer> servers = cachedServers;
|
||||
if (servers.isEmpty()) return Optional.empty();
|
||||
int index = Math.abs(counter.getAndIncrement() % servers.size());
|
||||
return Optional.ofNullable(servers.get(index));
|
||||
}
|
||||
|
||||
public List<RegisteredServer> getCachedServers() {
|
||||
return cachedServers;
|
||||
}
|
||||
|
||||
private static String extractJsonString(String json, String key) {
|
||||
String search = "\"" + key + "\":\"";
|
||||
int start = json.indexOf(search);
|
||||
if (start < 0) return null;
|
||||
start += search.length();
|
||||
int end = json.indexOf("\"", start);
|
||||
if (end < 0) return null;
|
||||
return json.substring(start, end);
|
||||
}
|
||||
|
||||
private static int extractJsonInt(String json, String key) {
|
||||
String search = "\"" + key + "\":";
|
||||
int start = json.indexOf(search);
|
||||
if (start < 0) return -1;
|
||||
start += search.length();
|
||||
int end = start;
|
||||
while (end < json.length() && Character.isDigit(json.charAt(end))) {
|
||||
end++;
|
||||
}
|
||||
if (end == start) return -1;
|
||||
try {
|
||||
return Integer.parseInt(json.substring(start, end));
|
||||
} catch (NumberFormatException e) {
|
||||
return -1;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,18 @@
|
|||
package me.rampart.velocity;
|
||||
|
||||
import com.velocitypowered.api.proxy.server.RegisteredServer;
|
||||
|
||||
import java.util.Optional;
|
||||
|
||||
public class ServerRouter {
|
||||
|
||||
private final ServerRegistry registry;
|
||||
|
||||
public ServerRouter(ServerRegistry registry) {
|
||||
this.registry = registry;
|
||||
}
|
||||
|
||||
public Optional<RegisteredServer> routeServer(String domain) {
|
||||
return registry.getNextServer();
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,144 @@
|
|||
package me.rampart.velocity;
|
||||
|
||||
import org.junit.jupiter.api.Test;
|
||||
|
||||
import javax.crypto.Mac;
|
||||
import javax.crypto.spec.SecretKeySpec;
|
||||
import java.security.InvalidKeyException;
|
||||
import java.security.NoSuchAlgorithmException;
|
||||
import java.util.List;
|
||||
|
||||
import static org.junit.jupiter.api.Assertions.*;
|
||||
|
||||
public class RampartVelocityTest {
|
||||
|
||||
@Test
|
||||
void hmacProduces64HexChars() {
|
||||
String sig = hmacHex("play.example.com", "test_secret");
|
||||
assertNotNull(sig);
|
||||
assertEquals(64, sig.length());
|
||||
assertTrue(sig.matches("[0-9a-f]{64}"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void hmacSameInputSameOutput() {
|
||||
String a = hmacHex("play.example.com", "secret");
|
||||
String b = hmacHex("play.example.com", "secret");
|
||||
assertEquals(a, b);
|
||||
}
|
||||
|
||||
@Test
|
||||
void hmacDifferentSecretDifferentOutput() {
|
||||
String a = hmacHex("play.example.com", "secret1");
|
||||
String b = hmacHex("play.example.com", "secret2");
|
||||
assertNotEquals(a, b);
|
||||
}
|
||||
|
||||
@Test
|
||||
void hmacDifferentInputDifferentOutput() {
|
||||
String a = hmacHex("play.example.com", "secret");
|
||||
String b = hmacHex("hub.example.com", "secret");
|
||||
assertNotEquals(a, b);
|
||||
}
|
||||
|
||||
@Test
|
||||
void constantTimeEqualsSame() {
|
||||
assertTrue(constantTimeEquals("abcdef", "abcdef"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void constantTimeEqualsDifferent() {
|
||||
assertFalse(constantTimeEquals("abcdef", "abcdeg"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void constantTimeEqualsDifferentLength() {
|
||||
assertFalse(constantTimeEquals("abc", "abcd"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void constantTimeEqualsEmpty() {
|
||||
assertTrue(constantTimeEquals("", ""));
|
||||
}
|
||||
|
||||
@Test
|
||||
void constantTimeEqualsNullSafety() {
|
||||
assertFalse(constantTimeEquals(null, "a"));
|
||||
assertFalse(constantTimeEquals("a", null));
|
||||
}
|
||||
|
||||
@Test
|
||||
void domainCheckRejectsIpv4() {
|
||||
assertTrue(DomainCheckUtil.isIpAddress("192.168.1.1"));
|
||||
assertTrue(DomainCheckUtil.isIpAddress("0.0.0.0"));
|
||||
assertTrue(DomainCheckUtil.isIpAddress("255.255.255.255"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void domainCheckAllowsDomains() {
|
||||
assertTrue(DomainCheckUtil.isDomainAllowed("play.example.com", List.of("example.com")));
|
||||
assertTrue(DomainCheckUtil.isDomainAllowed("mc.example.com", List.of("example.com")));
|
||||
assertFalse(DomainCheckUtil.isIpAddress("play.example.com"));
|
||||
assertFalse(DomainCheckUtil.isIpAddress("localhost"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void domainCheckRejectsInvalidIp() {
|
||||
assertFalse(DomainCheckUtil.isIpAddress("256.1.2.3"));
|
||||
assertFalse(DomainCheckUtil.isIpAddress("1.2.3.4.5"));
|
||||
assertFalse(DomainCheckUtil.isIpAddress("abc.def.ghi.jkl"));
|
||||
assertFalse(DomainCheckUtil.isIpAddress(""));
|
||||
assertFalse(DomainCheckUtil.isIpAddress(null));
|
||||
}
|
||||
|
||||
@Test
|
||||
void domainCheckSubdomainMatch() {
|
||||
assertTrue(DomainCheckUtil.isDomainAllowed("play.example.com", List.of("example.com")));
|
||||
assertTrue(DomainCheckUtil.isDomainAllowed("survival.hub.example.com", List.of("example.com")));
|
||||
}
|
||||
|
||||
@Test
|
||||
void domainCheckExactMatch() {
|
||||
assertTrue(DomainCheckUtil.isDomainAllowed("example.com", List.of("example.com")));
|
||||
}
|
||||
|
||||
@Test
|
||||
void domainCheckNoMatch() {
|
||||
assertFalse(DomainCheckUtil.isDomainAllowed("evil.com", List.of("example.com")));
|
||||
}
|
||||
|
||||
@Test
|
||||
void domainCheckEmptyWhitelistAllowsAll() {
|
||||
assertTrue(DomainCheckUtil.isDomainAllowed("anything.com", List.of()));
|
||||
assertTrue(DomainCheckUtil.isDomainAllowed("192.168.1.1", List.of()));
|
||||
}
|
||||
|
||||
// --- HMAC utility (mirrors HmacCheckListener) ---
|
||||
|
||||
private String hmacHex(String data, String secret) {
|
||||
try {
|
||||
Mac mac = Mac.getInstance("HmacSHA256");
|
||||
mac.init(new SecretKeySpec(secret.getBytes(), "HmacSHA256"));
|
||||
byte[] raw = mac.doFinal(data.getBytes());
|
||||
StringBuilder sb = new StringBuilder(raw.length * 2);
|
||||
for (byte b : raw) {
|
||||
sb.append(String.format("%02x", b & 0xFF));
|
||||
}
|
||||
return sb.toString();
|
||||
} catch (NoSuchAlgorithmException | InvalidKeyException e) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
// --- constant-time equals (mirrors HmacCheckListener) ---
|
||||
|
||||
private boolean constantTimeEquals(String a, String b) {
|
||||
if (a == null || b == null) return false;
|
||||
if (a.length() != b.length()) return false;
|
||||
int result = 0;
|
||||
for (int i = 0; i < a.length(); i++) {
|
||||
result |= a.charAt(i) ^ b.charAt(i);
|
||||
}
|
||||
return result == 0;
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue