fix: isolate DWH authentication subrequest headers
This commit is contained in:
@@ -62,6 +62,7 @@ grep -Eq '^f[[:space:]]+/var/lib/dwh-auth/\.writer\.lock[[:space:]]+0640[[:space
|
||||
grep -Fq 'auth_request /_check_dwh_key;' "$location" || die "DWH auth subrequest is missing"
|
||||
grep -Fq 'proxy_method GET;' "$location" || die "auth method is not GET"
|
||||
grep -Fq 'proxy_pass_request_body off;' "$location" || die "auth body is not disabled"
|
||||
grep -Fq 'proxy_pass_request_headers off;' "$location" || die "auth request headers are not restricted"
|
||||
grep -Fq 'proxy_set_header Content-Length "";' "$location" || die "auth body length is not cleared"
|
||||
grep -Fq 'proxy_set_header X-API-Key $http_x_api_key;' "$location" || die "key is not forwarded to auth"
|
||||
grep -Fq 'proxy_set_header X-API-Key "";' "$location" || die "key is not cleared upstream"
|
||||
|
||||
Reference in New Issue
Block a user