fix: harden pi management verification

This commit is contained in:
2026-08-05 01:00:13 +02:00
parent d6b4a08a02
commit 55926c75f8
12 changed files with 502 additions and 25 deletions
+25 -4
View File
@@ -1,5 +1,5 @@
# Host nginx example. The auth service MUST authenticate every request and return a stable
# identity in X-Authenticated-User. ThothII itself remains on 127.0.0.1:8080.
# Host nginx example. The auth service MUST authenticate every request and return only the
# normalized X-Thoth-* identity/admin claims below. ThothII remains on 127.0.0.1:8080.
server {
listen 443 ssl;
server_name thoth.example.test;
@@ -13,12 +13,33 @@ server {
proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-Original-URI $request_uri;
proxy_set_header X-Authenticated-User "";
proxy_set_header X-Thoth-Principal-Issuer "";
proxy_set_header X-Thoth-Principal-Subject "";
proxy_set_header X-Thoth-Principal-Display-Name "";
proxy_set_header X-Thoth-Is-Admin "";
proxy_set_header X-Thoth-Trusted-Principal-Issuer "";
proxy_set_header X-Thoth-Trusted-Principal-Subject "";
proxy_set_header X-Thoth-Trusted-Principal-Display-Name "";
proxy_set_header X-Thoth-Trusted-Is-Admin "";
}
location / {
auth_request /_authenticate;
auth_request_set $authenticated_user $upstream_http_x_authenticated_user;
proxy_set_header X-Authenticated-User $authenticated_user;
auth_request_set $thoth_principal_issuer $upstream_http_x_thoth_principal_issuer;
auth_request_set $thoth_principal_subject $upstream_http_x_thoth_principal_subject;
auth_request_set $thoth_principal_display_name $upstream_http_x_thoth_principal_display_name;
auth_request_set $thoth_is_admin $upstream_http_x_thoth_is_admin;
# Clear public normalized claims and carry auth_request results over the private hop.
proxy_set_header X-Authenticated-User "";
proxy_set_header X-Thoth-Principal-Issuer "";
proxy_set_header X-Thoth-Principal-Subject "";
proxy_set_header X-Thoth-Principal-Display-Name "";
proxy_set_header X-Thoth-Is-Admin "";
proxy_set_header X-Thoth-Trusted-Principal-Issuer $thoth_principal_issuer;
proxy_set_header X-Thoth-Trusted-Principal-Subject $thoth_principal_subject;
proxy_set_header X-Thoth-Trusted-Principal-Display-Name $thoth_principal_display_name;
proxy_set_header X-Thoth-Trusted-Is-Admin $thoth_is_admin;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header Host $host;
proxy_pass http://127.0.0.1:8080;