46 lines
2.0 KiB
Bash
Executable File
46 lines
2.0 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
cd "$(dirname "$0")/.."
|
|
|
|
outer=deploy/nginx-authenticated-proxy.conf.example
|
|
inner=docker/nginx.conf.template
|
|
|
|
# Catches a documented public proxy that forwards client-supplied normalized identity/admin
|
|
# headers instead of replacing them with claims returned by auth_request.
|
|
for suffix in Principal-Issuer Principal-Subject Principal-Display-Name Is-Admin; do
|
|
variable=$(printf '%s' "$suffix" | tr '[:upper:]-' '[:lower:]_')
|
|
grep -Fq "auth_request_set \$thoth_${variable} \$upstream_http_x_thoth_${variable};" "$outer"
|
|
if [[ $(grep -Fc "proxy_set_header X-Thoth-${suffix} \"\";" "$outer") -lt 2 ]]; then
|
|
echo "public proxy does not clear X-Thoth-${suffix} at both ingress hops" >&2
|
|
exit 1
|
|
fi
|
|
grep -Fq "proxy_set_header X-Thoth-Trusted-${suffix} \$thoth_${variable};" "$outer"
|
|
done
|
|
if rg -n 'proxy_set_header X-Thoth-[^;]+\$http_x_thoth_' "$outer"; then
|
|
echo "public proxy trusts client-supplied normalized Thoth claims" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Catches an included frontend hop that preserves a client normalized claim or drops the original
|
|
# Host port needed for exact same-origin management checks.
|
|
for suffix in Principal-Issuer Principal-Subject Principal-Display-Name Is-Admin; do
|
|
variable=$(printf '%s' "$suffix" | tr '[:upper:]-' '[:lower:]_')
|
|
grep -Fq "proxy_set_header X-Thoth-${suffix} \$http_x_thoth_trusted_${variable};" "$inner"
|
|
grep -Fq "proxy_set_header X-Thoth-Trusted-${suffix} \"\";" "$inner"
|
|
done
|
|
grep -Fq 'proxy_set_header Host $http_host;' "$inner"
|
|
if rg -n 'proxy_set_header X-Thoth-(Principal|Is-Admin)[^;]+\$http_x_thoth_(principal|is_admin)' "$inner"; then
|
|
echo "frontend proxy trusts a client-supplied normalized Thoth claim" >&2
|
|
exit 1
|
|
fi
|
|
for config in "$outer" "$inner"; do
|
|
grep -Fq 'proxy_set_header X-Authenticated-User "";' "$config"
|
|
done
|
|
if rg --pcre2 -n 'proxy_set_header X-Authenticated-User\s+(?!"";)' "$outer" "$inner"; then
|
|
echo "legacy unnormalized identity is forwarded by the proxy chain" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "authenticated proxy identity contract: ok"
|