校园热点 Captive Portal — 拦截 DNS 将学生设备透明重定向到 ClassIntra,支持开机自启与自动恢复
ClassIntra | 文档 | QQ 群
Captive 是 ClassIntra 的配套工具,适用于校园热点场景。当学生设备连接到超脑的移动热点后,无需任何客户端配置,即可在 DNS 层自动将指定教育平台域名重定向到 ClassIntra 服务。
典型使用场景: 教师在课堂上开启电脑热点,学生平板连接后,访问学科网、畅言智慧课堂等平台时自动跳转到 ClassIntra 内网平台。
学生设备(平板/手机)
│
├─ DNS 查询:"spark.changyan.com 的 IP 是什么?"
│ └─ Captive 拦截 → 返回 192.168.137.1(教师电脑热点 IP)
│
└─ HTTPS 请求发往 192.168.137.1:443
└─ Captive 终止 TLS → 转发明文 HTTP 到 localhost:9001(ClassIntra)
教师电脑上运行两个服务:
- DNS 服务器(UDP 53)— 拦截配置的域名,返回热点 IP(
192.168.137.1),其他查询正常转发到上游 DNS - HTTPS 反向代理(TCP 443)— 使用自签名证书终止 TLS,将请求透明转发到本地 ClassIntra 后端
- DNS 层域名拦截 — 学生设备零配置
- HTTPS 反向代理 + TLS 终止
- WebSocket 代理支持
- 开机自动启动(Windows 计划任务)
- 看门狗自动崩溃恢复
- 热点状态监控(断线自动重启)
- 静默后台运行(无弹窗)
- 卸载时完整清理
- 系统: Windows 10 / 11
- 运行时: Node.js >= 18.0.0
- 权限: 管理员(绑定 53 和 443 端口需要)
- 后端: ClassIntra 或其他本地服务运行在
localhost:9001
git clone https://github.com/ClassIntra/captive.git
cd captive
npm install# 方式一:PowerShell(管理员)
New-SelfSignedCertificate -DnsName "spark.changyan.com","ai.changyan.com","www.wjx.cn" -CertStoreLocation "Cert:\LocalMachine\My" -NotAfter (Get-Date).AddYears(5)
# 方式二:OpenSSL
openssl req -x509 -newkey rsa:2048 -keyout certs/key.pem -out certs/cert.pem -days 1825 -nodes -subj "/CN=spark.changyan.com"# 交互模式(可见控制台窗口)
start-hotspot-redirect.bat
# 或直接用 Node.js(需要管理员权限)
node hotspot-redirect.js- 开启电脑移动热点(或让脚本自动开启)
- 学生设备连接热点
- 浏览器访问
https://spark.changyan.com - 接受自签名证书警告
- 请求被转发到本地 ClassIntra(端口 9001)
# 右键 → 以管理员身份运行
install-auto-start.bat会创建两个 Windows 计划任务:
- IR_Hotspot_Redirect — 开机 30 秒后触发,静默模式运行 主任务本身配置了无限运行时间和任务级失败恢复,不再创建第二个周期恢复任务,避免多个看门狗同时运行。
# 右键 → 以管理员身份运行
uninstall-auto-start.bat编辑 hotspot-redirect.js 中的 CONFIG 对象:
const CONFIG = {
interceptDomains: ['spark.changyan.com', 'ai.changyan.com', 'www.wjx.cn'],
hotspotIP: '192.168.137.1', // Windows 热点默认 IP
dnsPort: 53,
httpsPort: 443,
upstreamDNS: '223.5.5.5', // 阿里 DNS
targetHost: 'localhost',
targetPort: 9001, // ClassIntra 后端端口
certDir: path.join(__dirname, 'certs'),
};在 interceptDomains 数组中添加,子域名自动匹配:
interceptDomains: [
'spark.changyan.com', // 畅言智慧课堂
'ai.changyan.com', // 畅言 AI
'www.wjx.cn', // 问卷星
'example.com', // 自定义域名(同时匹配 *.example.com)
],captive/
├── hotspot-redirect.js # 核心:DNS 服务器 + HTTPS 反向代理
├── watchdog.ps1 # 健康监控(每 15 秒检查)
├── watchdog-loop.bat # 外层包装:看门狗崩溃时自动重启
├── start-hotspot-redirect.bat # 主启动脚本(交互 & 静默)
├── stop-hotspot-redirect.bat # 优雅停止
├── start-hotspot.ps1 # WinRT API 启动移动热点
├── install-auto-start.bat # 安装开机自启动
├── uninstall-auto-start.bat # 卸载自启动
├── configure-task-recovery.ps1 # 配置任务无限制运行时间
├── launch-silent.vbs # 计划任务静默启动器
├── debug-start.bat # 调试用简化启动
├── certs/ # TLS 证书(已 gitignore)
├── logs/ # 运行日志(已 gitignore)
└── package.json
Windows 可能有 DNS 服务(SharedAccess/ICS)绑定到 53 端口:
- 必须以管理员身份运行 — 绑定 53 和 443 端口需要管理员权限
- 检查占用者:
Get-NetUDPEndpoint -LocalPort 53 | Select-Object OwningProcess, @{N='Process';E={(Get-Process $_.OwningProcess).ProcessName}}看门狗会监控热点状态并在断线时自动重启。检查热点服务:
Get-Service -Name SharedAccess预期行为。代理使用自签名证书,客户端必须接受警告才能继续。
ClassIntra 或其他后端服务必须在 localhost:9001 上运行。请先启动 ClassIntra 再启动 Captive。
- ClassIntra — 校园内网 WebOS 平台
- ClassIntra 文档 — 完整使用与部署指南