#!/usr/bin/env bash set -euo pipefail cd "$(dirname "$0")/.." outer=deploy/nginx-authenticated-proxy.conf.example inner=docker/nginx.conf.template # Catches a documented public proxy that forwards client-supplied normalized identity/admin # headers instead of replacing them with claims returned by auth_request. for suffix in Principal-Issuer Principal-Subject Principal-Display-Name Is-Admin; do variable=$(printf '%s' "$suffix" | tr '[:upper:]-' '[:lower:]_') grep -Fq "auth_request_set \$thoth_${variable} \$upstream_http_x_thoth_${variable};" "$outer" if [[ $(grep -Fc "proxy_set_header X-Thoth-${suffix} \"\";" "$outer") -lt 2 ]]; then echo "public proxy does not clear X-Thoth-${suffix} at both ingress hops" >&2 exit 1 fi grep -Fq "proxy_set_header X-Thoth-Trusted-${suffix} \$thoth_${variable};" "$outer" done if rg -n 'proxy_set_header X-Thoth-[^;]+\$http_x_thoth_' "$outer"; then echo "public proxy trusts client-supplied normalized Thoth claims" >&2 exit 1 fi # Catches an included frontend hop that preserves a client normalized claim or drops the original # Host port needed for exact same-origin management checks. for suffix in Principal-Issuer Principal-Subject Principal-Display-Name Is-Admin; do variable=$(printf '%s' "$suffix" | tr '[:upper:]-' '[:lower:]_') grep -Fq "proxy_set_header X-Thoth-${suffix} \$http_x_thoth_trusted_${variable};" "$inner" grep -Fq "proxy_set_header X-Thoth-Trusted-${suffix} \"\";" "$inner" done grep -Fq 'proxy_set_header Host $http_host;' "$inner" if rg -n 'proxy_set_header X-Thoth-(Principal|Is-Admin)[^;]+\$http_x_thoth_(principal|is_admin)' "$inner"; then echo "frontend proxy trusts a client-supplied normalized Thoth claim" >&2 exit 1 fi for config in "$outer" "$inner"; do grep -Fq 'proxy_set_header X-Authenticated-User "";' "$config" done if rg --pcre2 -n 'proxy_set_header X-Authenticated-User\s+(?!"";)' "$outer" "$inner"; then echo "legacy unnormalized identity is forwarded by the proxy chain" >&2 exit 1 fi echo "authenticated proxy identity contract: ok"