fix: harden pi management verification
This commit is contained in:
@@ -152,7 +152,11 @@ import it into the maintenance shell. Explicitly export the non-secret source an
|
||||
before running the commands below.
|
||||
|
||||
Configure the portal proxy so the frontend and `/api` share one origin. It authenticates first and
|
||||
forwards the trusted identity expected by `AUTH_MODE=upstream`; it is the only public listener.
|
||||
clears client identity headers, carries auth-request claims over the private hop as
|
||||
`X-Thoth-Trusted-*`, and lets the frontend proxy inject only the normalized
|
||||
`X-Thoth-Principal-Issuer`, `X-Thoth-Principal-Subject`, `X-Thoth-Principal-Display-Name`, and
|
||||
`X-Thoth-Is-Admin` claims expected by `AUTH_MODE=upstream`; it is the only public listener. Use
|
||||
`deploy/nginx-authenticated-proxy.conf.example` as the forwarding contract.
|
||||
From a trusted maintenance shell:
|
||||
|
||||
```sh
|
||||
|
||||
Reference in New Issue
Block a user