fix: harden pi management verification
This commit is contained in:
Executable
+45
@@ -0,0 +1,45 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
outer=deploy/nginx-authenticated-proxy.conf.example
|
||||
inner=docker/nginx.conf.template
|
||||
|
||||
# Catches a documented public proxy that forwards client-supplied normalized identity/admin
|
||||
# headers instead of replacing them with claims returned by auth_request.
|
||||
for suffix in Principal-Issuer Principal-Subject Principal-Display-Name Is-Admin; do
|
||||
variable=$(printf '%s' "$suffix" | tr '[:upper:]-' '[:lower:]_')
|
||||
grep -Fq "auth_request_set \$thoth_${variable} \$upstream_http_x_thoth_${variable};" "$outer"
|
||||
if [[ $(grep -Fc "proxy_set_header X-Thoth-${suffix} \"\";" "$outer") -lt 2 ]]; then
|
||||
echo "public proxy does not clear X-Thoth-${suffix} at both ingress hops" >&2
|
||||
exit 1
|
||||
fi
|
||||
grep -Fq "proxy_set_header X-Thoth-Trusted-${suffix} \$thoth_${variable};" "$outer"
|
||||
done
|
||||
if rg -n 'proxy_set_header X-Thoth-[^;]+\$http_x_thoth_' "$outer"; then
|
||||
echo "public proxy trusts client-supplied normalized Thoth claims" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Catches an included frontend hop that preserves a client normalized claim or drops the original
|
||||
# Host port needed for exact same-origin management checks.
|
||||
for suffix in Principal-Issuer Principal-Subject Principal-Display-Name Is-Admin; do
|
||||
variable=$(printf '%s' "$suffix" | tr '[:upper:]-' '[:lower:]_')
|
||||
grep -Fq "proxy_set_header X-Thoth-${suffix} \$http_x_thoth_trusted_${variable};" "$inner"
|
||||
grep -Fq "proxy_set_header X-Thoth-Trusted-${suffix} \"\";" "$inner"
|
||||
done
|
||||
grep -Fq 'proxy_set_header Host $http_host;' "$inner"
|
||||
if rg -n 'proxy_set_header X-Thoth-(Principal|Is-Admin)[^;]+\$http_x_thoth_(principal|is_admin)' "$inner"; then
|
||||
echo "frontend proxy trusts a client-supplied normalized Thoth claim" >&2
|
||||
exit 1
|
||||
fi
|
||||
for config in "$outer" "$inner"; do
|
||||
grep -Fq 'proxy_set_header X-Authenticated-User "";' "$config"
|
||||
done
|
||||
if rg --pcre2 -n 'proxy_set_header X-Authenticated-User\s+(?!"";)' "$outer" "$inner"; then
|
||||
echo "legacy unnormalized identity is forwarded by the proxy chain" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "authenticated proxy identity contract: ok"
|
||||
Reference in New Issue
Block a user