fix: ignore commented nginx auth directives

This commit is contained in:
2026-08-05 12:20:40 +02:00
parent fc349e634c
commit b44a1b9ad9
2 changed files with 71 additions and 4 deletions
@@ -245,6 +245,27 @@ switch (mutation) {
case "nginx-additional-bypass":
changed = original.replace(" location / {", " location /bypass {\n proxy_pass http://127.0.0.1:8080;\n }\n\n location / {");
break;
case "nginx-comment-only-auth":
changed = original.replace(" location / {", ` location /comment-only-auth {
# auth_request /_authenticate;
# auth_request_set $thoth_principal_issuer $upstream_http_x_thoth_principal_issuer;
# auth_request_set $thoth_principal_subject $upstream_http_x_thoth_principal_subject;
# auth_request_set $thoth_principal_display_name $upstream_http_x_thoth_principal_display_name;
# auth_request_set $thoth_is_admin $upstream_http_x_thoth_is_admin;
# proxy_set_header X-Thoth-Principal-Issuer "";
# proxy_set_header X-Thoth-Principal-Subject "";
# proxy_set_header X-Thoth-Principal-Display-Name "";
# proxy_set_header X-Thoth-Is-Admin "";
# proxy_set_header X-Thoth-Trusted-Principal-Issuer $thoth_principal_issuer;
# proxy_set_header X-Thoth-Trusted-Principal-Subject $thoth_principal_subject;
# proxy_set_header X-Thoth-Trusted-Principal-Display-Name $thoth_principal_display_name;
# proxy_set_header X-Thoth-Trusted-Is-Admin $thoth_is_admin;
proxy_set_header X-Comment-Literal "quoted#value"; # preserve the quoted hash
proxy_pass http://127.0.0.1:8080; # active frontend path
}
location / {`);
break;
case "caddy-no-auth":
changed = original.replace("forward_auth auth-gateway:4180 {", "# forward authentication omitted");
break;
@@ -412,6 +433,10 @@ expect_guide_rejected \
"Nginx additional frontend bypass location" verify_reverse_proxy_nginx_guide \
"$root/docs/install/reverse-proxy-nginx.md" docs/install/reverse-proxy-nginx.md nginx-additional-bypass \
"Nginx frontend upstream location bypasses complete authentication contract"
expect_guide_rejected \
"Nginx frontend auth directives only in comments" verify_reverse_proxy_nginx_guide \
"$root/docs/install/reverse-proxy-nginx.md" docs/install/reverse-proxy-nginx.md nginx-comment-only-auth \
"Nginx frontend upstream location bypasses complete authentication contract"
expect_guide_rejected \
"Caddy identity without authentication" verify_reverse_proxy_caddy_guide \
"$root/docs/install/reverse-proxy-caddy.md" docs/install/reverse-proxy-caddy.md caddy-no-auth \