fix: harden pi management verification
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
# Host nginx example. The auth service MUST authenticate every request and return a stable
|
||||
# identity in X-Authenticated-User. ThothII itself remains on 127.0.0.1:8080.
|
||||
# Host nginx example. The auth service MUST authenticate every request and return only the
|
||||
# normalized X-Thoth-* identity/admin claims below. ThothII remains on 127.0.0.1:8080.
|
||||
server {
|
||||
listen 443 ssl;
|
||||
server_name thoth.example.test;
|
||||
@@ -13,12 +13,33 @@ server {
|
||||
proxy_pass_request_body off;
|
||||
proxy_set_header Content-Length "";
|
||||
proxy_set_header X-Original-URI $request_uri;
|
||||
proxy_set_header X-Authenticated-User "";
|
||||
proxy_set_header X-Thoth-Principal-Issuer "";
|
||||
proxy_set_header X-Thoth-Principal-Subject "";
|
||||
proxy_set_header X-Thoth-Principal-Display-Name "";
|
||||
proxy_set_header X-Thoth-Is-Admin "";
|
||||
proxy_set_header X-Thoth-Trusted-Principal-Issuer "";
|
||||
proxy_set_header X-Thoth-Trusted-Principal-Subject "";
|
||||
proxy_set_header X-Thoth-Trusted-Principal-Display-Name "";
|
||||
proxy_set_header X-Thoth-Trusted-Is-Admin "";
|
||||
}
|
||||
|
||||
location / {
|
||||
auth_request /_authenticate;
|
||||
auth_request_set $authenticated_user $upstream_http_x_authenticated_user;
|
||||
proxy_set_header X-Authenticated-User $authenticated_user;
|
||||
auth_request_set $thoth_principal_issuer $upstream_http_x_thoth_principal_issuer;
|
||||
auth_request_set $thoth_principal_subject $upstream_http_x_thoth_principal_subject;
|
||||
auth_request_set $thoth_principal_display_name $upstream_http_x_thoth_principal_display_name;
|
||||
auth_request_set $thoth_is_admin $upstream_http_x_thoth_is_admin;
|
||||
# Clear public normalized claims and carry auth_request results over the private hop.
|
||||
proxy_set_header X-Authenticated-User "";
|
||||
proxy_set_header X-Thoth-Principal-Issuer "";
|
||||
proxy_set_header X-Thoth-Principal-Subject "";
|
||||
proxy_set_header X-Thoth-Principal-Display-Name "";
|
||||
proxy_set_header X-Thoth-Is-Admin "";
|
||||
proxy_set_header X-Thoth-Trusted-Principal-Issuer $thoth_principal_issuer;
|
||||
proxy_set_header X-Thoth-Trusted-Principal-Subject $thoth_principal_subject;
|
||||
proxy_set_header X-Thoth-Trusted-Principal-Display-Name $thoth_principal_display_name;
|
||||
proxy_set_header X-Thoth-Trusted-Is-Admin $thoth_is_admin;
|
||||
proxy_set_header X-Forwarded-Proto https;
|
||||
proxy_set_header Host $host;
|
||||
proxy_pass http://127.0.0.1:8080;
|
||||
|
||||
Reference in New Issue
Block a user