fix(deploy): reject ambiguous frontend upstream paths

This commit is contained in:
2026-08-04 16:02:25 +02:00
parent 87b0fda3f6
commit a248fb46d0
3 changed files with 10 additions and 6 deletions
+9 -1
View File
@@ -32,16 +32,24 @@ if rg -n 'BACKEND_BASE_URL|VITE_BACKEND_URL' docker/frontend-entrypoint.sh docke
fi
upstream_validator=docker/validate-frontend-api-upstream.sh
for upstream in http://core:8787 http://core:8787/; do
for upstream in http://core:8787; do
if ! "$upstream_validator" "$upstream"; then
echo "frontend upstream validator rejected $upstream" >&2
exit 1
fi
done
if grep -Fq 'THT_FRONTEND_API_UPSTREAM=${THT_FRONTEND_API_UPSTREAM%/}' docker/frontend-entrypoint.sh; then
echo "frontend entrypoint must not normalize an upstream path component" >&2
exit 1
fi
for upstream in \
https://core:8787 \
http://core:8080 \
http://core:8787/ \
http://core:8787// \
http://core:8787/// \
http://core:8787/api \
http://user:pass@core:8787 \
'http://core:8787?next=evil' \