fix(deploy): reject ambiguous frontend upstream paths
This commit is contained in:
@@ -2,7 +2,6 @@
|
||||
set -eu
|
||||
|
||||
THT_FRONTEND_API_UPSTREAM=${THT_FRONTEND_API_UPSTREAM:-http://core:8787}
|
||||
THT_FRONTEND_API_UPSTREAM=${THT_FRONTEND_API_UPSTREAM%/}
|
||||
if ! /usr/local/bin/validate-frontend-api-upstream "$THT_FRONTEND_API_UPSTREAM"; then
|
||||
echo "Invalid THT_FRONTEND_API_UPSTREAM: expected internal http://core:8787" >&2
|
||||
exit 2
|
||||
|
||||
@@ -32,16 +32,24 @@ if rg -n 'BACKEND_BASE_URL|VITE_BACKEND_URL' docker/frontend-entrypoint.sh docke
|
||||
fi
|
||||
|
||||
upstream_validator=docker/validate-frontend-api-upstream.sh
|
||||
for upstream in http://core:8787 http://core:8787/; do
|
||||
for upstream in http://core:8787; do
|
||||
if ! "$upstream_validator" "$upstream"; then
|
||||
echo "frontend upstream validator rejected $upstream" >&2
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
if grep -Fq 'THT_FRONTEND_API_UPSTREAM=${THT_FRONTEND_API_UPSTREAM%/}' docker/frontend-entrypoint.sh; then
|
||||
echo "frontend entrypoint must not normalize an upstream path component" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
for upstream in \
|
||||
https://core:8787 \
|
||||
http://core:8080 \
|
||||
http://core:8787/ \
|
||||
http://core:8787// \
|
||||
http://core:8787/// \
|
||||
http://core:8787/api \
|
||||
http://user:pass@core:8787 \
|
||||
'http://core:8787?next=evil' \
|
||||
|
||||
@@ -1,7 +1,4 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
case "${1-}" in
|
||||
http://core:8787|http://core:8787/) exit 0 ;;
|
||||
*) exit 2 ;;
|
||||
esac
|
||||
[ "${1-}" = "http://core:8787" ]
|
||||
|
||||
Reference in New Issue
Block a user