fix: isolate DWH authentication subrequest headers

This commit is contained in:
User
2026-08-21 02:50:27 +02:00
parent 87606c73c1
commit 62ec29ff92
2 changed files with 5 additions and 2 deletions
@@ -5,6 +5,7 @@ location = /_check_dwh_key {
proxy_method GET;
proxy_pass http://unix:/run/dwh-auth/verify.sock:/verify;
proxy_pass_request_body off;
proxy_pass_request_headers off;
proxy_set_header Content-Length "";
proxy_set_header X-API-Key $http_x_api_key;
}
@@ -16,12 +17,13 @@ location @dwh_auth_unavailable {
location /dwh/ {
limit_req zone=dwh_auth burst=100 nodelay;
auth_request /_check_dwh_key;
# Capture the verifier public ID only for an optional sanitized access log.
auth_request_set $dwh_key_id $upstream_http_x_dwh_key_id;
error_page 500 =503 @dwh_auth_unavailable;
# Never forward the credential. Only the verifier's public identity may
# reach the upstream for audit/rate attribution.
# Never forward the credential or verifier identity to the upstream.
proxy_set_header X-API-Key "";
# The public ID remains available only to an explicitly sanitized log.
proxy_set_header X-DWH-Key-ID "";
proxy_set_header Host $host;
proxy_pass http://127.0.0.1:3001;
+1
View File
@@ -62,6 +62,7 @@ grep -Eq '^f[[:space:]]+/var/lib/dwh-auth/\.writer\.lock[[:space:]]+0640[[:space
grep -Fq 'auth_request /_check_dwh_key;' "$location" || die "DWH auth subrequest is missing"
grep -Fq 'proxy_method GET;' "$location" || die "auth method is not GET"
grep -Fq 'proxy_pass_request_body off;' "$location" || die "auth body is not disabled"
grep -Fq 'proxy_pass_request_headers off;' "$location" || die "auth request headers are not restricted"
grep -Fq 'proxy_set_header Content-Length "";' "$location" || die "auth body length is not cleared"
grep -Fq 'proxy_set_header X-API-Key $http_x_api_key;' "$location" || die "key is not forwarded to auth"
grep -Fq 'proxy_set_header X-API-Key "";' "$location" || die "key is not cleared upstream"