fix: harden pi management verification

This commit is contained in:
2026-08-05 01:00:13 +02:00
parent d6b4a08a02
commit 55926c75f8
12 changed files with 502 additions and 25 deletions
+5 -1
View File
@@ -152,7 +152,11 @@ import it into the maintenance shell. Explicitly export the non-secret source an
before running the commands below.
Configure the portal proxy so the frontend and `/api` share one origin. It authenticates first and
forwards the trusted identity expected by `AUTH_MODE=upstream`; it is the only public listener.
clears client identity headers, carries auth-request claims over the private hop as
`X-Thoth-Trusted-*`, and lets the frontend proxy inject only the normalized
`X-Thoth-Principal-Issuer`, `X-Thoth-Principal-Subject`, `X-Thoth-Principal-Display-Name`, and
`X-Thoth-Is-Admin` claims expected by `AUTH_MODE=upstream`; it is the only public listener. Use
`deploy/nginx-authenticated-proxy.conf.example` as the forwarding contract.
From a trusted maintenance shell:
```sh
+5 -1
View File
@@ -137,7 +137,11 @@ docker compose exec core /opt/venv/bin/tht doctor --json
```
Se si abilita l'overlay production, il proxy autenticato TLS deve essere l'unico listener pubblico
e deve iniettare `X-Authenticated-User`; non esporre direttamente la porta pubblicata da nginx.
e deve sostituire gli header client con i claim restituiti dal proprio `auth_request`. L'esempio
usa header `X-Thoth-Trusted-*` soltanto sul collegamento privato; nginx frontend li converte nei
claim normalizzati `X-Thoth-Principal-Issuer`, `X-Thoth-Principal-Subject`,
`X-Thoth-Principal-Display-Name` e `X-Thoth-Is-Admin` attesi dal core. Non esporre direttamente
la porta pubblicata da nginx.
Se il server deve essere raggiungibile da altri host, sostituire `COMPOSE_FILE` con
`compose.yaml:deploy/compose.production.yaml`, configurare il proxy autenticato e impostare