# Include these locations inside the HTTPS server that publishes /dwh/. # The verifier is deliberately reachable only through an internal subrequest. location = /_check_dwh_key { internal; proxy_method GET; proxy_pass http://unix:/run/dwh-auth/verify.sock:/verify; proxy_pass_request_body off; proxy_pass_request_headers off; proxy_set_header Content-Length ""; proxy_set_header X-API-Key $http_x_api_key; } location @dwh_auth_unavailable { return 503; } location /dwh/ { limit_req zone=dwh_auth burst=100 nodelay; auth_request /_check_dwh_key; # Capture the verifier public ID only for an optional sanitized access log. auth_request_set $dwh_key_id $upstream_http_x_dwh_key_id; error_page 500 =503 @dwh_auth_unavailable; # Never forward the credential or verifier identity to the upstream. proxy_set_header X-API-Key ""; # The public ID remains available only to an explicitly sanitized log. proxy_set_header X-DWH-Key-ID ""; proxy_set_header Host $host; proxy_pass http://127.0.0.1:3001/; }