31 lines
1.0 KiB
Plaintext
31 lines
1.0 KiB
Plaintext
# Include these locations inside the HTTPS server that publishes /dwh/.
|
|
# The verifier is deliberately reachable only through an internal subrequest.
|
|
location = /_check_dwh_key {
|
|
internal;
|
|
proxy_method GET;
|
|
proxy_pass http://unix:/run/dwh-auth/verify.sock:/verify;
|
|
proxy_pass_request_body off;
|
|
proxy_pass_request_headers off;
|
|
proxy_set_header Content-Length "";
|
|
proxy_set_header X-API-Key $http_x_api_key;
|
|
}
|
|
|
|
location @dwh_auth_unavailable {
|
|
return 503;
|
|
}
|
|
|
|
location /dwh/ {
|
|
limit_req zone=dwh_auth burst=100 nodelay;
|
|
auth_request /_check_dwh_key;
|
|
# Capture the verifier public ID only for an optional sanitized access log.
|
|
auth_request_set $dwh_key_id $upstream_http_x_dwh_key_id;
|
|
error_page 500 =503 @dwh_auth_unavailable;
|
|
|
|
# Never forward the credential or verifier identity to the upstream.
|
|
proxy_set_header X-API-Key "";
|
|
# The public ID remains available only to an explicitly sanitized log.
|
|
proxy_set_header X-DWH-Key-ID "";
|
|
proxy_set_header Host $host;
|
|
proxy_pass http://127.0.0.1:3001;
|
|
}
|