| Component | Runtime Configuration | Status |
|---|---|---|
| ingress.base_domain | *.tunnel.dolazythings.my.id | Active |
| auth.provider | Corporate SSO (OAuth2 / PAT) | Enforced |
| engine.transport | WebSocket Multiplexer (Asyncio Future Engine) | Active |
| security.hardened | One-Time Handshake Ticket (30s TTL) + Anti-SSRF | Enforced |
| server.network | 0.0.0.0:8999 (HTTP/WS) | Online |
README.md
plain text
lazy-tunnel
High-performance reverse HTTP and WebSocket gateway. Exposes local loopback services to arbitrary public wildcard endpoints using corporate SSO authentication.
# 1. Exchange corporate access token for JWT session
curl -s -X POST https://tunnel.dolazythings.my.id/auth/token-login \
-H "Content-Type: application/json" \
-d '{"token": "$AUTH_TOKEN"}' | jq -r .access_token
# 2. Request single-use handshake ticket (30-second TTL)
curl -s -X POST https://tunnel.dolazythings.my.id/auth/tunnel-ticket \
-H "Authorization: Bearer $JWT" | jq -r .ticket
# 3. Establish persistent WebSocket bridge
python3 client_example/client.py --server https://tunnel.dolazythings.my.id --port 3000
Client connections are isolated strictly to 127.0.0.1 to prevent internal network traversal. Replay attacks are mitigated by single-use ticket consumption upon handshake.