From 62ec29ff92edf47dd8fe088e628f38d36542f8f8 Mon Sep 17 00:00:00 2001 From: User Date: Fri, 21 Aug 2026 02:50:27 +0200 Subject: [PATCH] fix: isolate DWH authentication subrequest headers --- deploy/dwh-auth/nginx-dwh-location.conf.example | 6 ++++-- scripts/test-dwh-auth-build-contract.sh | 1 + 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/deploy/dwh-auth/nginx-dwh-location.conf.example b/deploy/dwh-auth/nginx-dwh-location.conf.example index 6d472405..9989ed05 100644 --- a/deploy/dwh-auth/nginx-dwh-location.conf.example +++ b/deploy/dwh-auth/nginx-dwh-location.conf.example @@ -5,6 +5,7 @@ location = /_check_dwh_key { proxy_method GET; proxy_pass http://unix:/run/dwh-auth/verify.sock:/verify; proxy_pass_request_body off; + proxy_pass_request_headers off; proxy_set_header Content-Length ""; proxy_set_header X-API-Key $http_x_api_key; } @@ -16,12 +17,13 @@ location @dwh_auth_unavailable { location /dwh/ { limit_req zone=dwh_auth burst=100 nodelay; auth_request /_check_dwh_key; + # Capture the verifier public ID only for an optional sanitized access log. auth_request_set $dwh_key_id $upstream_http_x_dwh_key_id; error_page 500 =503 @dwh_auth_unavailable; - # Never forward the credential. Only the verifier's public identity may - # reach the upstream for audit/rate attribution. + # Never forward the credential or verifier identity to the upstream. proxy_set_header X-API-Key ""; + # The public ID remains available only to an explicitly sanitized log. proxy_set_header X-DWH-Key-ID ""; proxy_set_header Host $host; proxy_pass http://127.0.0.1:3001; diff --git a/scripts/test-dwh-auth-build-contract.sh b/scripts/test-dwh-auth-build-contract.sh index ecb591b6..e44cb068 100755 --- a/scripts/test-dwh-auth-build-contract.sh +++ b/scripts/test-dwh-auth-build-contract.sh @@ -62,6 +62,7 @@ grep -Eq '^f[[:space:]]+/var/lib/dwh-auth/\.writer\.lock[[:space:]]+0640[[:space grep -Fq 'auth_request /_check_dwh_key;' "$location" || die "DWH auth subrequest is missing" grep -Fq 'proxy_method GET;' "$location" || die "auth method is not GET" grep -Fq 'proxy_pass_request_body off;' "$location" || die "auth body is not disabled" +grep -Fq 'proxy_pass_request_headers off;' "$location" || die "auth request headers are not restricted" grep -Fq 'proxy_set_header Content-Length "";' "$location" || die "auth body length is not cleared" grep -Fq 'proxy_set_header X-API-Key $http_x_api_key;' "$location" || die "key is not forwarded to auth" grep -Fq 'proxy_set_header X-API-Key "";' "$location" || die "key is not cleared upstream"