fix: harden pi management verification

This commit is contained in:
2026-08-05 01:00:13 +02:00
parent d6b4a08a02
commit 55926c75f8
12 changed files with 502 additions and 25 deletions
+13 -5
View File
@@ -6,7 +6,7 @@ server {
location = /health {
proxy_pass ${THT_FRONTEND_API_UPSTREAM}/health;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header Host $http_host;
proxy_cache off;
}
@@ -14,13 +14,21 @@ server {
# The trailing slash replaces the matched /api/ prefix before the private hop.
proxy_pass ${THT_FRONTEND_API_UPSTREAM}/;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# Trusted only when AUTH_MODE=upstream and this frontend port is reachable solely
# from the authenticated host proxy documented in deploy/.
proxy_set_header X-Authenticated-User $http_x_authenticated_user;
# Public normalized claims are discarded by mapping only the private-hop values from the
# authenticated host proxy. Private-hop headers are then cleared before reaching core.
proxy_set_header X-Authenticated-User "";
proxy_set_header X-Thoth-Principal-Issuer $http_x_thoth_trusted_principal_issuer;
proxy_set_header X-Thoth-Principal-Subject $http_x_thoth_trusted_principal_subject;
proxy_set_header X-Thoth-Principal-Display-Name $http_x_thoth_trusted_principal_display_name;
proxy_set_header X-Thoth-Is-Admin $http_x_thoth_trusted_is_admin;
proxy_set_header X-Thoth-Trusted-Principal-Issuer "";
proxy_set_header X-Thoth-Trusted-Principal-Subject "";
proxy_set_header X-Thoth-Trusted-Principal-Display-Name "";
proxy_set_header X-Thoth-Trusted-Is-Admin "";
proxy_buffering off;
proxy_cache off;
proxy_read_timeout 3600s;
+1
View File
@@ -7,6 +7,7 @@ nginx_config=docker/nginx.conf.template
for setting in \
'proxy_pass ${THT_FRONTEND_API_UPSTREAM}/;' \
'proxy_http_version 1.1;' \
'proxy_set_header Host $http_host;' \
'proxy_buffering off;' \
'proxy_read_timeout 3600s;'; do
if ! grep -Fq "$setting" "$nginx_config"; then