An entry of allowlist_hosts or referer_blocklist that is neither a host name (letters, digits, hyphens and dots, with at most one leading dot) nor an IP address now aborts startup naming the setting and the entry, so a `*.` wildcard or a port no longer loads and silently matches nothing. README.md, config.example.yml and the TODO.md entry now say the Referer check comes before the signature, the cache and the upstream fetch, since maintenance mode answers first; config.example.yml says the list does not cover the login and generator pages. Model: opus-5-5
This commit is contained in:
@@ -177,11 +177,12 @@ path under `/v1/` answers 200, in maintenance mode too.
|
||||
the image's `ETag`; 400 for a URL or parameter that is not valid; 401 for a
|
||||
missing or wrong signature, a missing `exp` or an `exp` in the past; 403 when
|
||||
the request's `Referer` names a host in `referer_blocklist`, checked before
|
||||
anything else; 403 when the upstream host, or a host it redirects to, is
|
||||
`localhost`, ends in `.localhost` or `.local`, or has an address in a blocked
|
||||
network (see `blocked_networks`); 502 when the upstream answered with an error
|
||||
status, and for 5 minutes after that for the same source URL; 503 when pixa is
|
||||
busy or in maintenance mode; 500 for any other failure.
|
||||
the signature, the cache and the upstream fetch; 403 when the upstream host,
|
||||
or a host it redirects to, is `localhost`, ends in `.localhost` or `.local`,
|
||||
or has an address in a blocked network (see `blocked_networks`); 502 when the
|
||||
upstream answered with an error status, and for 5 minutes after that for the
|
||||
same source URL; 503 when pixa is busy or in maintenance mode; 500 for any
|
||||
other failure.
|
||||
- `GET` or `HEAD` `/v1/e/<token>/<name>` — an image through an encrypted URL
|
||||
(see Encrypted URLs). Needs: nothing but the URL. Answers: 200; 304 when
|
||||
`If-None-Match` matches the image's `ETag`; 400 for a token that does not
|
||||
@@ -394,6 +395,11 @@ and the URL is
|
||||
- **Suffix match**: `.example.com` — matches `cdn.example.com`,
|
||||
`images.example.com`, and `example.com`
|
||||
|
||||
An IP address is matched exactly; write an IPv6 address without brackets. An
|
||||
entry that is neither a host name (letters, digits, hyphens and dots, with at
|
||||
most one leading dot) nor an IP address, such as one with a port or a `*.`
|
||||
wildcard, aborts startup.
|
||||
|
||||
### Configuration
|
||||
|
||||
Every setting can be given as an environment variable, in a YAML config
|
||||
@@ -461,11 +467,12 @@ Key settings in more detail:
|
||||
- `allowlist_hosts` — list of allowed upstream hosts
|
||||
- `referer_blocklist` — list of hosts whose pages may not show pixa's images, to
|
||||
stop other sites hotlinking them. Entries are written and matched as for
|
||||
`allowlist_hosts` (see Allowlist patterns); one that is not a bare host aborts
|
||||
startup. A request to `/v1/image/` or `/v1/e/` whose `Referer` header names a
|
||||
listed host is refused with 403 before anything else is done for it, so it
|
||||
fetches nothing from the upstream host, and it is refused even when the image
|
||||
is cached. A request with no `Referer`, or one that does not parse as a URL
|
||||
`allowlist_hosts` (see Allowlist patterns), and an entry that is neither a
|
||||
host name nor an IP address aborts startup. A request to `/v1/image/` or
|
||||
`/v1/e/` whose `Referer` header names a listed host is refused with 403 before
|
||||
its signature or token is checked and before the cache or the upstream host is
|
||||
used, so it fetches nothing, and it is refused even when the image is cached.
|
||||
A request with no `Referer`, or one that does not parse as a URL
|
||||
with a host, is served, as many clients send none. So this is easily got
|
||||
around: a site whose pages send no `Referer` (for example with
|
||||
`Referrer-Policy: no-referrer`) is not stopped. It does not apply to the login
|
||||
|
||||
Reference in New Issue
Block a user