mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-09-17 21:52:38 +00:00
fix(quickproxy): reject Exclude entries outside their rule's URLPrefix
Tests / Unit Tests (push) Failing after 5s
Tests / Integration Tests (push) Failing after 23s
Build , Vet Test, and Lint / Build (push) Successful in 52s
Build , Vet Test, and Lint / Run Vet Tests (1.24.x) (push) Successful in 55s
Build , Vet Test, and Lint / Run Vet Tests (1.23.x) (push) Successful in 56s
Build , Vet Test, and Lint / Lint Code (push) Successful in 1m4s
Tests / Unit Tests (push) Failing after 5s
Tests / Integration Tests (push) Failing after 23s
Build , Vet Test, and Lint / Build (push) Successful in 52s
Build , Vet Test, and Lint / Run Vet Tests (1.24.x) (push) Successful in 55s
Build , Vet Test, and Lint / Run Vet Tests (1.23.x) (push) Successful in 56s
Build , Vet Test, and Lint / Lint Code (push) Successful in 1m4s
An Exclude entry only ever matches requests that already fall under its rule's URLPrefix, so one written without that prefix (e.g. "/health" on a rule for "/api") silently never triggered. Validate that each Exclude entry itself starts with the rule's URLPrefix, failing NewService instead of accepting a no-op config.
This commit is contained in:
@@ -28,9 +28,11 @@ type Rule struct {
|
||||
Target string
|
||||
|
||||
// Exclude is a list of URL path prefixes that this rule should not
|
||||
// proxy, even though they fall under URLPrefix. Each entry must start
|
||||
// with "/". A request matching an Exclude prefix is treated as if this
|
||||
// rule didn't match at all: matching continues against any other
|
||||
// proxy, even though they fall under URLPrefix. Each entry is a full
|
||||
// path from root and must itself start with URLPrefix (e.g. rule
|
||||
// URLPrefix "/api" excluding a subpath must use "/api/health", not
|
||||
// "/health"). A request matching an Exclude prefix is treated as if
|
||||
// this rule didn't match at all: matching continues against any other
|
||||
// configured rule, falling back if none match. This is typically used
|
||||
// to carve out paths (e.g. "/health") from a catch-all "/" rule so
|
||||
// they're served by the fallback handler instead of being proxied.
|
||||
@@ -122,6 +124,9 @@ func NewService(rules []Rule, opts ...Option) (*Service, error) {
|
||||
if !strings.HasPrefix(ex, "/") {
|
||||
return nil, fmt.Errorf("quickproxy: exclude prefix %q for rule %q must start with /", ex, r.URLPrefix)
|
||||
}
|
||||
if !strings.HasPrefix(ex, r.URLPrefix) {
|
||||
return nil, fmt.Errorf("quickproxy: exclude prefix %q for rule %q must itself start with the rule's URLPrefix", ex, r.URLPrefix)
|
||||
}
|
||||
}
|
||||
|
||||
compiled = append(compiled, compiledRule{
|
||||
|
||||
@@ -26,10 +26,16 @@ func TestNewService_Validation(t *testing.T) {
|
||||
{"bad exclude prefix", []Rule{
|
||||
{URLPrefix: "/", Target: "http://localhost:1", Exclude: []string{"health"}},
|
||||
}, true},
|
||||
{"exclude outside rule's URLPrefix", []Rule{
|
||||
{URLPrefix: "/api", Target: "http://localhost:1", Exclude: []string{"/health"}},
|
||||
}, true},
|
||||
{"valid", []Rule{{URLPrefix: "/api", Target: "http://localhost:1"}}, false},
|
||||
{"valid with exclude", []Rule{
|
||||
{URLPrefix: "/", Target: "http://localhost:1", Exclude: []string{"/health"}},
|
||||
}, false},
|
||||
{"valid with nested exclude", []Rule{
|
||||
{URLPrefix: "/api", Target: "http://localhost:1", Exclude: []string{"/api/health"}},
|
||||
}, false},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
|
||||
Reference in New Issue
Block a user