fix: harden pi management verification
This commit is contained in:
@@ -6,7 +6,7 @@ server {
|
||||
location = /health {
|
||||
proxy_pass ${THT_FRONTEND_API_UPSTREAM}/health;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_cache off;
|
||||
}
|
||||
|
||||
@@ -14,13 +14,21 @@ server {
|
||||
# The trailing slash replaces the matched /api/ prefix before the private hop.
|
||||
proxy_pass ${THT_FRONTEND_API_UPSTREAM}/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
# Trusted only when AUTH_MODE=upstream and this frontend port is reachable solely
|
||||
# from the authenticated host proxy documented in deploy/.
|
||||
proxy_set_header X-Authenticated-User $http_x_authenticated_user;
|
||||
# Public normalized claims are discarded by mapping only the private-hop values from the
|
||||
# authenticated host proxy. Private-hop headers are then cleared before reaching core.
|
||||
proxy_set_header X-Authenticated-User "";
|
||||
proxy_set_header X-Thoth-Principal-Issuer $http_x_thoth_trusted_principal_issuer;
|
||||
proxy_set_header X-Thoth-Principal-Subject $http_x_thoth_trusted_principal_subject;
|
||||
proxy_set_header X-Thoth-Principal-Display-Name $http_x_thoth_trusted_principal_display_name;
|
||||
proxy_set_header X-Thoth-Is-Admin $http_x_thoth_trusted_is_admin;
|
||||
proxy_set_header X-Thoth-Trusted-Principal-Issuer "";
|
||||
proxy_set_header X-Thoth-Trusted-Principal-Subject "";
|
||||
proxy_set_header X-Thoth-Trusted-Principal-Display-Name "";
|
||||
proxy_set_header X-Thoth-Trusted-Is-Admin "";
|
||||
proxy_buffering off;
|
||||
proxy_cache off;
|
||||
proxy_read_timeout 3600s;
|
||||
|
||||
@@ -7,6 +7,7 @@ nginx_config=docker/nginx.conf.template
|
||||
for setting in \
|
||||
'proxy_pass ${THT_FRONTEND_API_UPSTREAM}/;' \
|
||||
'proxy_http_version 1.1;' \
|
||||
'proxy_set_header Host $http_host;' \
|
||||
'proxy_buffering off;' \
|
||||
'proxy_read_timeout 3600s;'; do
|
||||
if ! grep -Fq "$setting" "$nginx_config"; then
|
||||
|
||||
Reference in New Issue
Block a user