fix: harden pi management verification
This commit is contained in:
@@ -152,7 +152,11 @@ import it into the maintenance shell. Explicitly export the non-secret source an
|
||||
before running the commands below.
|
||||
|
||||
Configure the portal proxy so the frontend and `/api` share one origin. It authenticates first and
|
||||
forwards the trusted identity expected by `AUTH_MODE=upstream`; it is the only public listener.
|
||||
clears client identity headers, carries auth-request claims over the private hop as
|
||||
`X-Thoth-Trusted-*`, and lets the frontend proxy inject only the normalized
|
||||
`X-Thoth-Principal-Issuer`, `X-Thoth-Principal-Subject`, `X-Thoth-Principal-Display-Name`, and
|
||||
`X-Thoth-Is-Admin` claims expected by `AUTH_MODE=upstream`; it is the only public listener. Use
|
||||
`deploy/nginx-authenticated-proxy.conf.example` as the forwarding contract.
|
||||
From a trusted maintenance shell:
|
||||
|
||||
```sh
|
||||
|
||||
@@ -137,7 +137,11 @@ docker compose exec core /opt/venv/bin/tht doctor --json
|
||||
```
|
||||
|
||||
Se si abilita l'overlay production, il proxy autenticato TLS deve essere l'unico listener pubblico
|
||||
e deve iniettare `X-Authenticated-User`; non esporre direttamente la porta pubblicata da nginx.
|
||||
e deve sostituire gli header client con i claim restituiti dal proprio `auth_request`. L'esempio
|
||||
usa header `X-Thoth-Trusted-*` soltanto sul collegamento privato; nginx frontend li converte nei
|
||||
claim normalizzati `X-Thoth-Principal-Issuer`, `X-Thoth-Principal-Subject`,
|
||||
`X-Thoth-Principal-Display-Name` e `X-Thoth-Is-Admin` attesi dal core. Non esporre direttamente
|
||||
la porta pubblicata da nginx.
|
||||
|
||||
Se il server deve essere raggiungibile da altri host, sostituire `COMPOSE_FILE` con
|
||||
`compose.yaml:deploy/compose.production.yaml`, configurare il proxy autenticato e impostare
|
||||
|
||||
Reference in New Issue
Block a user