fix: honor an installation HTTP private-host allowlist for Evidence
This commit is contained in:
@@ -436,7 +436,7 @@ async function setupFixtures(ctx) {
|
||||
read_timeout_ms: 30001,
|
||||
max_bytes: 65536,
|
||||
max_redirects: 2,
|
||||
allow_private_hosts: false,
|
||||
allow_private_hosts: true,
|
||||
max_cache_bytes: 65536,
|
||||
},
|
||||
}),
|
||||
@@ -765,6 +765,7 @@ async function writeInstallationFiles(ctx) {
|
||||
`THT_WS_P2_DWH_DWH_API_KEY_SOURCE=${ctx.secretPaths.dwh}`,
|
||||
`THT_WS_P2_DWH_EVIDENCE_SIGNED_URLS_SOURCE=${ctx.secretPaths.signed}`,
|
||||
`THT_WS_P2_FILESYSTEM_DWH_API_KEY_SOURCE=${ctx.secretPaths.filesystemDwh}`,
|
||||
`THT_EVIDENCE_PRIVATE_HOST_ALLOWLIST=host.docker.internal`,
|
||||
].join("\n") + "\n";
|
||||
await atomicWrite(operatorEnvPath, operatorEnv);
|
||||
await atomicWrite(join(ctx.run.root, "installation", "pi-auth.json"), JSON.stringify({ fixture: true }));
|
||||
|
||||
@@ -201,6 +201,8 @@ function createProductionService(): WorkspacePreprocessingService {
|
||||
});
|
||||
return new WorkspacePreprocessingService({
|
||||
dataRoot: config.dataRoot ?? "/data",
|
||||
httpPrivateHostAllowlist: (process.env.THT_EVIDENCE_PRIVATE_HOST_ALLOWLIST ?? "")
|
||||
.split(",").map((value) => value.trim()).filter((value) => value.length > 0),
|
||||
acquireActiveRuntime: async (workspaceId) => {
|
||||
const active = await renderActiveWorkspaceRuntime({
|
||||
workspaceId,
|
||||
|
||||
Reference in New Issue
Block a user