fix: ignore commented nginx auth directives

This commit is contained in:
2026-08-05 12:20:40 +02:00
parent fc349e634c
commit b44a1b9ad9
2 changed files with 71 additions and 4 deletions
+46 -4
View File
@@ -639,6 +639,48 @@ verify_reverse_proxy_nginx_guide() {
const fs = require("fs");
const source = fs.readFileSync(process.argv[2], "utf8");
const block = [...source.matchAll(/```nginx\n([\s\S]*?)```/g)].map((match) => match[1]).join("\n");
function stripNginxComments(text) {
let effective = "";
let quote = null;
let escaped = false;
let comment = false;
for (const character of text) {
if (comment) {
if (character === "\n") {
effective += character;
comment = false;
}
continue;
}
if (escaped) {
effective += character;
escaped = false;
continue;
}
if (character === "\\") {
effective += character;
escaped = true;
continue;
}
if (quote !== null) {
effective += character;
if (character === quote) quote = null;
continue;
}
if (character === '"' || character === "'") {
effective += character;
quote = character;
continue;
}
if (character === "#") {
comment = true;
continue;
}
effective += character;
}
return effective;
}
const effectiveBlock = stripNginxComments(block);
const tokens = [
"listen 443 ssl;", "ssl_certificate ", "ssl_certificate_key ",
"location = /_authenticate {", "internal;", "proxy_pass http://auth-gateway:4180/verify;",
@@ -646,13 +688,13 @@ const tokens = [
"proxy_http_version 1.1;", "proxy_buffering off;", "proxy_cache off;",
"proxy_read_timeout 3600s;",
];
if (/127\.0\.0\.1:8787|\bcore:8787\b/.test(block) || !block.includes("http://127.0.0.1:8080")) {
if (/127\.0\.0\.1:8787|\bcore:8787\b/.test(effectiveBlock) || !effectiveBlock.includes("http://127.0.0.1:8080")) {
throw new Error("Nginx proxy must forward only to frontend on 127.0.0.1:8080");
}
for (const token of tokens) {
if (!block.includes(token)) throw new Error(`Nginx proxy lacks structural token: ${token}`);
if (!effectiveBlock.includes(token)) throw new Error(`Nginx proxy lacks structural token: ${token}`);
}
if (/proxy_set_header\s+X-Thoth-Trusted-[^;]+\$http_/i.test(block)) {
if (/proxy_set_header\s+X-Thoth-Trusted-[^;]+\$http_/i.test(effectiveBlock)) {
throw new Error("Nginx proxy trusts a client-supplied identity header");
}
const identities = [
@@ -681,7 +723,7 @@ function nginxLocations(text) {
}
return locations;
}
const locations = nginxLocations(block);
const locations = nginxLocations(effectiveBlock);
const authLocations = locations.filter((location) => location.selector === "= /_authenticate");
if (authLocations.length !== 1) {
throw new Error("Nginx proxy must define exactly one authentication location");