fix: harden DWH Nginx integration gates

This commit is contained in:
User
2026-08-21 03:37:01 +02:00
parent 1b18a0fb25
commit d0f7e0497d
2 changed files with 156 additions and 12 deletions
+35 -1
View File
@@ -55,6 +55,10 @@ location_block() {
' "$file"
}
location_declarations() {
effective_lines "$1" | awk "/^location / { print }"
}
contains_exactly_once() {
local haystack=$1
local needle=$2
@@ -70,13 +74,19 @@ contains_line() {
check_templates() {
local http=$1
local location=$2
local http_lines auth_lines unavailable_lines dwh_lines
local http_lines auth_lines unavailable_lines dwh_lines locations
[[ -f "$http" && -f "$location" ]] || return 1
http_lines=$(effective_lines "$http")
auth_lines=$(location_block "$location" '= /_check_dwh_key')
unavailable_lines=$(location_block "$location" '@dwh_auth_unavailable')
dwh_lines=$(location_block "$location" '/dwh/')
locations=$(location_declarations "$location")
[[ $(wc -l <<<"$locations") -eq 3 ]] || return 1
[[ $(grep -Fxc -- "location = /_check_dwh_key {" <<<"$locations" || true) -eq 1 ]] || return 1
[[ $(grep -Fxc -- "location @dwh_auth_unavailable {" <<<"$locations" || true) -eq 1 ]] || return 1
[[ $(grep -Fxc -- "location /dwh/ {" <<<"$locations" || true) -eq 1 ]] || return 1
contains_exactly_once "$auth_lines" 'internal;' || return 1
contains_exactly_once "$auth_lines" 'proxy_method GET;' || return 1
@@ -157,6 +167,24 @@ expect_http_rejected() {
! check_templates "$fixture/http.conf" "$fixture/location.conf"
}
expect_postgrest_regex_bypass_rejected() {
local fixture="$temp_root/postgrest_regex_bypass"
mkdir -- "$fixture"
cp -- "$http_template" "$fixture/http.conf"
cp -- "$location_template" "$fixture/location.conf"
printf "%s\n" "location ~ ^/dwh/ {" " proxy_pass http://127.0.0.1:3001;" "}" >>"$fixture/location.conf"
! check_templates "$fixture/http.conf" "$fixture/location.conf"
}
expect_postgrest_duplicate_bypass_rejected() {
local fixture="$temp_root/postgrest_duplicate_bypass"
mkdir -- "$fixture"
cp -- "$http_template" "$fixture/http.conf"
cp -- "$location_template" "$fixture/location.conf"
printf "%s\n" "location /dwh/ {" " proxy_pass http://127.0.0.1:3001;" "}" >>"$fixture/location.conf"
! check_templates "$fixture/http.conf" "$fixture/location.conf"
}
[[ -f "$http_template" ]] || report_fail source_http_exists
[[ -f "$location_template" ]] || report_fail source_location_exists
check_templates "$http_template" "$location_template" || report_fail source_contract
@@ -208,6 +236,12 @@ expect_location_rejected postgrest_bypass 'auth_request /_check_dwh_key;' '# dir
|| report_fail negative_postgrest_bypass
report_pass negative_postgrest_bypass
expect_postgrest_regex_bypass_rejected || report_fail negative_postgrest_regex_bypass
report_pass negative_postgrest_regex_bypass
expect_postgrest_duplicate_bypass_rejected || report_fail negative_postgrest_duplicate_bypass
report_pass negative_postgrest_duplicate_bypass
expect_location_rejected failure_mapped_to_success 'error_page 500 =503 @dwh_auth_unavailable;' 'error_page 500 =200 @dwh_auth_unavailable;' \
|| report_fail negative_failure_mapped_to_success
report_pass negative_failure_mapped_to_success