should be non-breaking now ;)

This commit is contained in:
Scott McKendry
2026-07-30 07:06:54 +12:00
parent cce0eaa974
commit c5bccd0b7b
4 changed files with 79 additions and 33 deletions
+22 -8
View File
@@ -345,6 +345,19 @@ func (controller *ProxyController) getHeader(c *gin.Context, header string) (str
return val, strings.TrimSpace(val) != ""
}
func getRequestPath(uri string) (string, error) {
parsedURI, err := url.ParseRequestURI(uri)
if err != nil {
return "", err
}
if parsedURI.Path == "" {
return "/", nil
}
return parsedURI.Path, nil
}
func (controller *ProxyController) useBrowserResponse(proxyCtx ProxyContext) bool {
// If it's nginx we need non-browser response
if proxyCtx.ProxyType == Nginx {
@@ -390,16 +403,11 @@ func (controller *ProxyController) getForwardAuthContext(c *gin.Context) (ProxyC
return ProxyContext{}, errors.New("x-forwarded-uri not found")
}
parsedURI, err := url.ParseRequestURI(uri)
path, err := getRequestPath(uri)
if err != nil {
return ProxyContext{}, fmt.Errorf("invalid x-forwarded-uri: %w", err)
}
if parsedURI.Path == "" {
parsedURI.Path = "/"
}
proto, ok := controller.getHeader(c, "x-forwarded-proto")
if !ok {
@@ -413,7 +421,7 @@ func (controller *ProxyController) getForwardAuthContext(c *gin.Context) (ProxyC
return ProxyContext{
Host: host,
Proto: proto,
Path: parsedURI.Path,
Path: path,
Method: method,
Type: ForwardAuth,
}, nil
@@ -445,6 +453,9 @@ func (controller *ProxyController) getAuthRequestContext(c *gin.Context) (ProxyC
}
path := url.Path
if path == "" {
path = "/"
}
method := c.Request.Method
return ProxyContext{
@@ -472,7 +483,10 @@ func (controller *ProxyController) getExtAuthzContext(c *gin.Context) (ProxyCont
}
// We get the path from the query string
path := c.Query("path")
path, err := getRequestPath(c.Query("path"))
if err != nil {
return ProxyContext{}, fmt.Errorf("invalid path: %w", err)
}
// For envoy we need to support every method
method := c.Request.Method
@@ -347,6 +347,16 @@ func TestProxyController(t *testing.T) {
assert.Equal(t, http.StatusOK, recorder.Code)
},
},
{
description: "Ensure path allow ACL ignores query strings for nginx auth request",
middlewares: []gin.HandlerFunc{},
run: func(t *testing.T, router *gin.Engine, recorder *httptest.ResponseRecorder) {
req := httptest.NewRequest("GET", "/api/auth/nginx", nil)
req.Header.Set("x-original-url", "https://path-allow.example.com/admin?path=/allowed")
router.ServeHTTP(recorder, req)
assert.Equal(t, http.StatusUnauthorized, recorder.Code)
},
},
{
description: "Ensure path allow ACL works on nginx auth request",
middlewares: []gin.HandlerFunc{},
@@ -357,6 +367,17 @@ func TestProxyController(t *testing.T) {
assert.Equal(t, http.StatusOK, recorder.Code)
},
},
{
description: "Ensure path allow ACL ignores query strings for envoy ext authz",
middlewares: []gin.HandlerFunc{},
run: func(t *testing.T, router *gin.Engine, recorder *httptest.ResponseRecorder) {
req := httptest.NewRequest("HEAD", "/api/auth/envoy?path=/admin%3Fpath%3D/allowed", nil)
req.Host = "path-allow.example.com"
req.Header.Set("x-forwarded-proto", "https")
router.ServeHTTP(recorder, req)
assert.Equal(t, http.StatusUnauthorized, recorder.Code)
},
},
{
description: "Ensure path allow ACL works on envoy ext authz",
middlewares: []gin.HandlerFunc{},