fix: harden DWH Nginx integration gates
This commit is contained in:
@@ -55,6 +55,10 @@ location_block() {
|
||||
' "$file"
|
||||
}
|
||||
|
||||
location_declarations() {
|
||||
effective_lines "$1" | awk "/^location / { print }"
|
||||
}
|
||||
|
||||
contains_exactly_once() {
|
||||
local haystack=$1
|
||||
local needle=$2
|
||||
@@ -70,13 +74,19 @@ contains_line() {
|
||||
check_templates() {
|
||||
local http=$1
|
||||
local location=$2
|
||||
local http_lines auth_lines unavailable_lines dwh_lines
|
||||
local http_lines auth_lines unavailable_lines dwh_lines locations
|
||||
|
||||
[[ -f "$http" && -f "$location" ]] || return 1
|
||||
http_lines=$(effective_lines "$http")
|
||||
auth_lines=$(location_block "$location" '= /_check_dwh_key')
|
||||
unavailable_lines=$(location_block "$location" '@dwh_auth_unavailable')
|
||||
dwh_lines=$(location_block "$location" '/dwh/')
|
||||
locations=$(location_declarations "$location")
|
||||
[[ $(wc -l <<<"$locations") -eq 3 ]] || return 1
|
||||
[[ $(grep -Fxc -- "location = /_check_dwh_key {" <<<"$locations" || true) -eq 1 ]] || return 1
|
||||
[[ $(grep -Fxc -- "location @dwh_auth_unavailable {" <<<"$locations" || true) -eq 1 ]] || return 1
|
||||
[[ $(grep -Fxc -- "location /dwh/ {" <<<"$locations" || true) -eq 1 ]] || return 1
|
||||
|
||||
|
||||
contains_exactly_once "$auth_lines" 'internal;' || return 1
|
||||
contains_exactly_once "$auth_lines" 'proxy_method GET;' || return 1
|
||||
@@ -157,6 +167,24 @@ expect_http_rejected() {
|
||||
! check_templates "$fixture/http.conf" "$fixture/location.conf"
|
||||
}
|
||||
|
||||
expect_postgrest_regex_bypass_rejected() {
|
||||
local fixture="$temp_root/postgrest_regex_bypass"
|
||||
mkdir -- "$fixture"
|
||||
cp -- "$http_template" "$fixture/http.conf"
|
||||
cp -- "$location_template" "$fixture/location.conf"
|
||||
printf "%s\n" "location ~ ^/dwh/ {" " proxy_pass http://127.0.0.1:3001;" "}" >>"$fixture/location.conf"
|
||||
! check_templates "$fixture/http.conf" "$fixture/location.conf"
|
||||
}
|
||||
|
||||
expect_postgrest_duplicate_bypass_rejected() {
|
||||
local fixture="$temp_root/postgrest_duplicate_bypass"
|
||||
mkdir -- "$fixture"
|
||||
cp -- "$http_template" "$fixture/http.conf"
|
||||
cp -- "$location_template" "$fixture/location.conf"
|
||||
printf "%s\n" "location /dwh/ {" " proxy_pass http://127.0.0.1:3001;" "}" >>"$fixture/location.conf"
|
||||
! check_templates "$fixture/http.conf" "$fixture/location.conf"
|
||||
}
|
||||
|
||||
[[ -f "$http_template" ]] || report_fail source_http_exists
|
||||
[[ -f "$location_template" ]] || report_fail source_location_exists
|
||||
check_templates "$http_template" "$location_template" || report_fail source_contract
|
||||
@@ -208,6 +236,12 @@ expect_location_rejected postgrest_bypass 'auth_request /_check_dwh_key;' '# dir
|
||||
|| report_fail negative_postgrest_bypass
|
||||
report_pass negative_postgrest_bypass
|
||||
|
||||
expect_postgrest_regex_bypass_rejected || report_fail negative_postgrest_regex_bypass
|
||||
report_pass negative_postgrest_regex_bypass
|
||||
|
||||
expect_postgrest_duplicate_bypass_rejected || report_fail negative_postgrest_duplicate_bypass
|
||||
report_pass negative_postgrest_duplicate_bypass
|
||||
|
||||
expect_location_rejected failure_mapped_to_success 'error_page 500 =503 @dwh_auth_unavailable;' 'error_page 500 =200 @dwh_auth_unavailable;' \
|
||||
|| report_fail negative_failure_mapped_to_success
|
||||
report_pass negative_failure_mapped_to_success
|
||||
|
||||
Reference in New Issue
Block a user