Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
62f46c3a49 | ||
|
|
6748bbd637 | ||
|
|
fd7d7ed205 |
@@ -40,9 +40,8 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for pixa needs:
|
|||||||
|
|
||||||
- **Port:** pixa listens on container port `8080`.
|
- **Port:** pixa listens on container port `8080`.
|
||||||
- **Volume:** container path `/var/lib/pixa`, where pixa keeps its
|
- **Volume:** container path `/var/lib/pixa`, where pixa keeps its
|
||||||
database and cache. upaas bind-mounts the host path it is given and
|
database and cache. Creating the host directory when it is missing is
|
||||||
does not create it, so the host directory must exist before the first
|
upaas's job, tracked in https://git.eeqj.de/sneak/upaas/issues/235.
|
||||||
deploy.
|
|
||||||
- **Environment variables:**
|
- **Environment variables:**
|
||||||
- `PIXA_SIGNING_KEY` (required): secret for signed and encrypted URLs
|
- `PIXA_SIGNING_KEY` (required): secret for signed and encrypted URLs
|
||||||
and login, 32+ characters, for example from
|
and login, 32+ characters, for example from
|
||||||
@@ -58,10 +57,6 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for pixa needs:
|
|||||||
`healthy`. The probe uses the port from `PORT` (default `8080`), so a
|
`healthy`. The probe uses the port from `PORT` (default `8080`), so a
|
||||||
port changed only in a mounted config file is not seen by it: change
|
port changed only in a mounted config file is not seen by it: change
|
||||||
the port with `PORT`.
|
the port with `PORT`.
|
||||||
- **First run:** create the host directory, owned by root or by uid
|
|
||||||
`65532` and gid `65532`. The server runs as the container's `pixad`
|
|
||||||
user, which has that uid and gid, and the container gives the
|
|
||||||
directory to `pixad` when it starts.
|
|
||||||
|
|
||||||
## Rationale
|
## Rationale
|
||||||
|
|
||||||
@@ -243,7 +238,7 @@ variables set by the file's `env:` section are checked the same way.
|
|||||||
| `PIXA_UPSTREAM_FETCH_TIMEOUT` | `upstream_fetch_timeout` | Time allowed for one fetch from an upstream host; default `30s` |
|
| `PIXA_UPSTREAM_FETCH_TIMEOUT` | `upstream_fetch_timeout` | Time allowed for one fetch from an upstream host; default `30s` |
|
||||||
| `PIXA_UPSTREAM_MAX_RESPONSE_SIZE` | `upstream_max_response_size` | Largest upstream response accepted, in bytes; default 50 MiB |
|
| `PIXA_UPSTREAM_MAX_RESPONSE_SIZE` | `upstream_max_response_size` | Largest upstream response accepted, in bytes; default 50 MiB |
|
||||||
| `PIXA_DOWNSTREAM_TIMEOUT` | `downstream_timeout` | Time allowed for answering one client request; default `60s` |
|
| `PIXA_DOWNSTREAM_TIMEOUT` | `downstream_timeout` | Time allowed for answering one client request; default `60s` |
|
||||||
| `PIXA_ACCESS_CONTROL_ALLOW_ORIGIN` | `access_control_allow_origin` | CORS origin allowed to read responses: `*` or one origin; default `*` |
|
| `PIXA_ACCESS_CONTROL_ALLOW_ORIGIN` | `access_control_allow_origin` | CORS origin allowed to read image responses: `*` or one origin; default `*` |
|
||||||
| `PIXA_METRICS_USERNAME` | `metrics.username` | Username for `/metrics`, which is served only when both are set |
|
| `PIXA_METRICS_USERNAME` | `metrics.username` | Username for `/metrics`, which is served only when both are set |
|
||||||
| `PIXA_METRICS_PASSWORD` | `metrics.password` | Password for `/metrics`; set together with the username |
|
| `PIXA_METRICS_PASSWORD` | `metrics.password` | Password for `/metrics`; set together with the username |
|
||||||
| `PIXA_SENTRY_DSN` | `sentry_dsn` | Sentry DSN for error reporting; empty disables it |
|
| `PIXA_SENTRY_DSN` | `sentry_dsn` | Sentry DSN for error reporting; empty disables it |
|
||||||
@@ -252,8 +247,9 @@ variables set by the file's `env:` section are checked the same way.
|
|||||||
|
|
||||||
Key settings in more detail:
|
Key settings in more detail:
|
||||||
|
|
||||||
- `access_control_allow_origin` — the origin a browser lets read pixa's
|
- `access_control_allow_origin` — the origin a browser lets read the responses
|
||||||
responses, sent as the CORS `Access-Control-Allow-Origin` header: `*`, the
|
of the image routes, `/v1/image/` and `/v1/e/`, sent as the CORS
|
||||||
|
`Access-Control-Allow-Origin` header; no other route sends it. `*`, the
|
||||||
default, is any site; otherwise one `http` or `https` origin such as
|
default, is any site; otherwise one `http` or `https` origin such as
|
||||||
`https://example.com`, whose host is a lowercase host name (letters,
|
`https://example.com`, whose host is a lowercase host name (letters,
|
||||||
digits, hyphens and dots, with a letter in its last part) or an IP address
|
digits, hyphens and dots, with a letter in its last part) or an IP address
|
||||||
|
|||||||
@@ -29,6 +29,19 @@ P2: security: referer blacklist
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-09-29 only the image routes send CORS headers (closes #98): the CORS
|
||||||
|
middleware, with the `access_control_allow_origin` origin, moved from the
|
||||||
|
router root onto a `/v1` subrouter holding `/v1/image/` and `/v1/e/`, where it
|
||||||
|
still answers a preflight `OPTIONS` request; the login and URL generator
|
||||||
|
pages, `/metrics` and the other routes send no `Access-Control-Allow-Origin`;
|
||||||
|
documented in `README.md` and `config.example.yml`.
|
||||||
|
- 2026-09-29 the container makes `/var/lib/pixa` usable by itself (closes
|
||||||
|
#159): `deploy/docker-entrypoint.sh` creates the directory if it is missing,
|
||||||
|
gives the directory and everything in it to `pixad` when the directory or one
|
||||||
|
of its top-level entries belongs to another user or group, sets its mode to
|
||||||
|
`750`, then runs the server as `pixad`; data left by an earlier run under
|
||||||
|
another uid is taken over this way; "Running under upaas" in `README.md` no
|
||||||
|
longer tells the operator to create or chown the host directory.
|
||||||
- 2026-09-29 variant content types kept in memory (closes #70):
|
- 2026-09-29 variant content types kept in memory (closes #70):
|
||||||
`Cache.metaCache` holds the content types of up to 10,000 variants in an LRU
|
`Cache.metaCache` holds the content types of up to 10,000 variants in an LRU
|
||||||
(`github.com/hashicorp/golang-lru/v2`), filled by `StoreVariant` and by
|
(`github.com/hashicorp/golang-lru/v2`), filled by `StoreVariant` and by
|
||||||
|
|||||||
+3
-2
@@ -103,8 +103,9 @@ upstream_max_response_size: 52428800
|
|||||||
# longer than upstream_fetch_timeout plus 20 seconds.
|
# longer than upstream_fetch_timeout plus 20 seconds.
|
||||||
downstream_timeout: 60s
|
downstream_timeout: 60s
|
||||||
|
|
||||||
# The origin a browser lets read pixa's responses, sent as the CORS
|
# The origin a browser lets read the responses of the image routes,
|
||||||
# Access-Control-Allow-Origin header: "*" (the default) is any site;
|
# /v1/image/ and /v1/e/, sent as the CORS Access-Control-Allow-Origin
|
||||||
|
# header; no other route sends it. "*" (the default) is any site;
|
||||||
# otherwise one http or https origin such as https://example.com, whose
|
# otherwise one http or https origin such as https://example.com, whose
|
||||||
# host is a lowercase host name (letters, digits, hyphens and dots, with a
|
# host is a lowercase host name (letters, digits, hyphens and dots, with a
|
||||||
# letter in its last part) or an IP address (IPv6 in brackets, in its
|
# letter in its last part) or an IP address (IPv6 in brackets, in its
|
||||||
|
|||||||
@@ -1,14 +1,22 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# deploy/docker-entrypoint.sh: the Docker image's ENTRYPOINT. It runs as
|
# deploy/docker-entrypoint.sh: the Docker image's ENTRYPOINT. It runs as
|
||||||
# root only to give /var/lib/pixa to pixad: a host directory
|
# root only to make /var/lib/pixa usable by pixad: a host directory
|
||||||
# bind-mounted there keeps its host owner, often root, and pixad could
|
# bind-mounted there keeps its host owner, often root, and data from an
|
||||||
# not write to it. The server itself always runs as pixad.
|
# earlier run may belong to another uid. The server itself always runs
|
||||||
|
# as pixad.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
main() {
|
main() {
|
||||||
if [ "$(stat -c %U /var/lib/pixa)" != pixad ]; then
|
mkdir -p /var/lib/pixa
|
||||||
chown pixad:pixad /var/lib/pixa
|
# Only the directory and its top-level entries are checked, so a
|
||||||
|
# normal start does not walk the cache. -depth gives each directory
|
||||||
|
# to pixad after its contents, so a start stopped part way leaves
|
||||||
|
# something at the top for the next start to find; -h changes a
|
||||||
|
# symlink itself, never the file it points to.
|
||||||
|
if [ -n "$(find /var/lib/pixa -maxdepth 1 \( ! -user pixad -o ! -group pixad \))" ]; then
|
||||||
|
find /var/lib/pixa -depth -exec chown -h pixad:pixad {} +
|
||||||
fi
|
fi
|
||||||
|
chmod 750 /var/lib/pixa
|
||||||
exec su-exec pixad /usr/local/bin/pixad "$@"
|
exec su-exec pixad /usr/local/bin/pixad "$@"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,64 @@
|
|||||||
|
package server
|
||||||
|
|
||||||
|
import (
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// TestCORSOnlyOnImageRoutes verifies that the image routes answer with the
|
||||||
|
// configured access_control_allow_origin, a preflight request included, and
|
||||||
|
// that the login and URL generator pages send no Access-Control-Allow-Origin,
|
||||||
|
// so no other site can read them. /metrics is left out: its middleware
|
||||||
|
// registers with the process-wide Prometheus registry, which only one test
|
||||||
|
// in this package can do.
|
||||||
|
func TestCORSOnlyOnImageRoutes(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
const appOrigin = "https://app.example.com"
|
||||||
|
|
||||||
|
s := newTestServer(t)
|
||||||
|
s.config.AccessControlAllowOrigin = appOrigin
|
||||||
|
s.SetupRoutes()
|
||||||
|
|
||||||
|
requests := []struct {
|
||||||
|
method string
|
||||||
|
path string
|
||||||
|
want string
|
||||||
|
}{
|
||||||
|
{http.MethodGet, unsignedImagePath, appOrigin},
|
||||||
|
{http.MethodHead, unsignedImagePath, appOrigin},
|
||||||
|
{http.MethodOptions, unsignedImagePath, appOrigin},
|
||||||
|
{http.MethodGet, encryptedImagePath, appOrigin},
|
||||||
|
{http.MethodGet, "/", ""},
|
||||||
|
{http.MethodOptions, "/", ""},
|
||||||
|
{http.MethodPost, "/generate", ""},
|
||||||
|
{http.MethodGet, "/logout", ""},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range requests {
|
||||||
|
t.Run(tc.method+" "+tc.path, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
req := httptest.NewRequestWithContext(
|
||||||
|
t.Context(), tc.method, tc.path, nil)
|
||||||
|
req.Header.Set("Origin", appOrigin)
|
||||||
|
|
||||||
|
// An OPTIONS request naming the method it asks about is the
|
||||||
|
// preflight a browser sends before some cross-origin requests.
|
||||||
|
if tc.method == http.MethodOptions {
|
||||||
|
req.Header.Set("Access-Control-Request-Method", http.MethodGet)
|
||||||
|
}
|
||||||
|
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
s.ServeHTTP(rec, req)
|
||||||
|
t.Logf("status %d", rec.Code)
|
||||||
|
|
||||||
|
got := rec.Header().Get("Access-Control-Allow-Origin")
|
||||||
|
if got != tc.want {
|
||||||
|
t.Errorf("Access-Control-Allow-Origin = %q, want %q",
|
||||||
|
got, tc.want)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -13,6 +13,10 @@ import (
|
|||||||
// unsignedImagePath is an image URL that carries no signature.
|
// unsignedImagePath is an image URL that carries no signature.
|
||||||
const unsignedImagePath = "/v1/image/cdn.example.com/cat.jpg/100x100.jpeg"
|
const unsignedImagePath = "/v1/image/cdn.example.com/cat.jpg/100x100.jpeg"
|
||||||
|
|
||||||
|
// encryptedImagePath is an encrypted image URL whose token cannot be
|
||||||
|
// decrypted.
|
||||||
|
const encryptedImagePath = "/v1/e/token/cat.jpg"
|
||||||
|
|
||||||
// TestMaintenanceModeRefusesImageRequests verifies that while maintenance
|
// TestMaintenanceModeRefusesImageRequests verifies that while maintenance
|
||||||
// mode is on, both image routes answer 503 Service Unavailable with a
|
// mode is on, both image routes answer 503 Service Unavailable with a
|
||||||
// Retry-After header and the JSON error body the image handlers send.
|
// Retry-After header and the JSON error body the image handlers send.
|
||||||
@@ -28,7 +32,7 @@ func TestMaintenanceModeRefusesImageRequests(t *testing.T) {
|
|||||||
}{
|
}{
|
||||||
{http.MethodGet, unsignedImagePath},
|
{http.MethodGet, unsignedImagePath},
|
||||||
{http.MethodHead, unsignedImagePath},
|
{http.MethodHead, unsignedImagePath},
|
||||||
{http.MethodGet, "/v1/e/token/cat.jpg"},
|
{http.MethodGet, encryptedImagePath},
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tc := range requests {
|
for _, tc := range requests {
|
||||||
@@ -95,7 +99,7 @@ func TestImageRequestsServedWithoutMaintenanceMode(t *testing.T) {
|
|||||||
}{
|
}{
|
||||||
{http.MethodGet, unsignedImagePath, http.StatusUnauthorized},
|
{http.MethodGet, unsignedImagePath, http.StatusUnauthorized},
|
||||||
{http.MethodHead, unsignedImagePath, http.StatusUnauthorized},
|
{http.MethodHead, unsignedImagePath, http.StatusUnauthorized},
|
||||||
{http.MethodGet, "/v1/e/token/cat.jpg", http.StatusBadRequest},
|
{http.MethodGet, encryptedImagePath, http.StatusBadRequest},
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tc := range requests {
|
for _, tc := range requests {
|
||||||
|
|||||||
+23
-15
@@ -38,7 +38,6 @@ func (s *Server) SetupRoutes() {
|
|||||||
s.router.Use(s.mw.Metrics())
|
s.router.Use(s.mw.Metrics())
|
||||||
}
|
}
|
||||||
|
|
||||||
s.router.Use(s.mw.CORS())
|
|
||||||
s.router.Use(middleware.Timeout(s.config.DownstreamTimeout))
|
s.router.Use(middleware.Timeout(s.config.DownstreamTimeout))
|
||||||
|
|
||||||
if s.sentryEnabled {
|
if s.sentryEnabled {
|
||||||
@@ -74,22 +73,31 @@ func (s *Server) SetupRoutes() {
|
|||||||
|
|
||||||
s.router.Get("/logout", s.h.HandleLogout())
|
s.router.Get("/logout", s.h.HandleLogout())
|
||||||
|
|
||||||
// Image routes, refused while maintenance mode is on. Only these: the
|
// Image routes, the only ones that send CORS headers, as pages on other
|
||||||
// image's Docker HEALTHCHECK requests the health check, a 503 there
|
// sites read them. They are a subrouter rather than a group: a group's
|
||||||
// would make the container unhealthy, and upaas marks a deploy failed
|
// middleware runs only for a request that matches one of its routes,
|
||||||
// when its container is unhealthy.
|
// and a browser's preflight OPTIONS request matches none, so the CORS
|
||||||
s.router.Group(func(r chi.Router) {
|
// middleware could not answer it.
|
||||||
r.Use(s.refuseDuringMaintenance)
|
s.router.Route("/v1", func(r chi.Router) {
|
||||||
|
r.Use(s.mw.CORS())
|
||||||
|
|
||||||
// Main image proxy route
|
// Refused while maintenance mode is on. Only these: the image's
|
||||||
// /v1/image/<host>/<path>/<width>x<height>.<format>
|
// Docker HEALTHCHECK requests the health check, a 503 there would
|
||||||
r.Get("/v1/image/*", s.h.HandleImage())
|
// make the container unhealthy, and upaas marks a deploy failed
|
||||||
r.Head("/v1/image/*", s.h.HandleImage())
|
// when its container is unhealthy.
|
||||||
|
r.Group(func(r chi.Router) {
|
||||||
|
r.Use(s.refuseDuringMaintenance)
|
||||||
|
|
||||||
// Encrypted image URL route
|
// Main image proxy route
|
||||||
// The trailing filename (e.g., /img.jpg) is ignored but helps
|
// /v1/image/<host>/<path>/<width>x<height>.<format>
|
||||||
// browsers with content type
|
r.Get("/image/*", s.h.HandleImage())
|
||||||
r.Get("/v1/e/{token}/*", s.h.HandleImageEnc())
|
r.Head("/image/*", s.h.HandleImage())
|
||||||
|
|
||||||
|
// Encrypted image URL route
|
||||||
|
// The trailing filename (e.g., /img.jpg) is ignored but helps
|
||||||
|
// browsers with content type
|
||||||
|
r.Get("/e/{token}/*", s.h.HandleImageEnc())
|
||||||
|
})
|
||||||
})
|
})
|
||||||
|
|
||||||
// Metrics endpoint with auth
|
// Metrics endpoint with auth
|
||||||
|
|||||||
Reference in New Issue
Block a user