Capture, decrypt, and restream toolkit with compiled-in app modules (RTE, TG4, BBC), on-device MITM proxy, streamd control plane, and www. BBC module.yaml is published (clear streams); other module values stay local.
56 lines
1.6 KiB
Go
56 lines
1.6 KiB
Go
package main
|
|
|
|
import "strings"
|
|
|
|
// CA identity and file names. The legacy names are still honoured when already
|
|
// present on a device, so an existing phone does not need a CA reinject.
|
|
const (
|
|
caCertName = "appproxy-ca.crt"
|
|
caKeyName = "appproxy-ca.key"
|
|
legacyCACertName = "rteproxy-ca.crt"
|
|
legacyCAKeyName = "rteproxy-ca.key"
|
|
caOrganization = "appproxy MITM CA"
|
|
caCommonName = "appproxy"
|
|
)
|
|
|
|
// stringList is a repeatable string flag.
|
|
type stringList []string
|
|
|
|
func (s *stringList) String() string { return strings.Join(*s, ",") }
|
|
|
|
func (s *stringList) Set(v string) error {
|
|
for _, part := range strings.Split(v, ",") {
|
|
part = strings.TrimSpace(part)
|
|
if part != "" {
|
|
*s = append(*s, part)
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
var (
|
|
// matchNeedles (--match) mark extra provider traffic as interesting.
|
|
matchNeedles stringList
|
|
// scoreHosts (--score-host) are this provider's manifest origins.
|
|
scoreHosts stringList
|
|
// scoreDeny (--score-deny) are provider URLs that are never a manifest.
|
|
scoreDeny stringList
|
|
// mitmHosts (--mitm-host) force MITM even when a passthrough rule matches.
|
|
mitmHosts stringList
|
|
)
|
|
|
|
// formatDeny are catalog/analytics URL shapes that are never a manifest for any
|
|
// provider. Provider-specific noise arrives via --score-deny.
|
|
var formatDeny = []string{
|
|
"schedules", "bylistingtime", "maxlistings", "bycallsign",
|
|
"/feed.", "playback_config", "config.json",
|
|
}
|
|
|
|
func denyNeedles() []string {
|
|
out := make([]string, 0, len(formatDeny)+len(scoreDeny))
|
|
out = append(out, formatDeny...)
|
|
for _, d := range scoreDeny {
|
|
out = append(out, strings.ToLower(d))
|
|
}
|
|
return out
|
|
}
|