package caddyatprotoauth import ( "net" "net/http" "strings" ) // getRequestScheme infers the protocol scheme of the incoming request. func getRequestScheme(r *http.Request) string { if r.TLS != nil || r.Header.Get("X-Forwarded-Proto") == "https" { return "https" } return "http" } // getRequestHost safely extracts the hostname, stripping the port and handling IPv6 literals. func getRequestHost(r *http.Request) string { host, _, err := net.SplitHostPort(r.Host) if err != nil { // Fallback if there is no port or if it's malformed return r.Host } return host } // matchDomain checks if the host matches the allowed pattern. // Supports exact matches and wildcard prefix matches (e.g., *.example.com). func matchDomain(host, pattern string) bool { if host == pattern { return true } if strings.HasPrefix(pattern, "*.") { suffix := pattern[1:] // e.g., ".example.com" return strings.HasSuffix(host, suffix) } return false } // isAllowedDomain checks if the host is allowed by the configured domains. func checkAllowedDomain(host string, allowedDomains []string) bool { for _, allowed := range allowedDomains { if matchDomain(host, allowed) { return true } } return false }