Harden operator-set target headers (closes #233)
All checks were successful
check / check (push) Successful in 3m5s
All checks were successful
check / check (push) Successful in 3m5s
Three findings from the review of the per-target request headers feature, plus the follow-up they raised about the inbound headers the same delivery path forwards. One rule now governs every header a delivery carries on someone else's behalf: a redirect hop that leaves the origin the target names carries none of them. That covers the operator's configured headers and the inbound event headers forwarded from the sender alike. net/http withholds only Authorization and Cookie across a host change, so an operator's X-Api-Key or a sender's X-Hub-Signature would otherwise follow a 302 to a host nobody configured. Redirects are still followed — refusing them would break every destination that legitimately redirects and would record the 3xx as the delivery's result — but a hop to another host, another port, or down from https to http drops the lot. The shared SSRF-safe transport is kept on that client, so each hop is still dialled through the private-IP guard. The set to strip is not a name list. applyRequestHeaders now returns the canonical names of everything it applied on the sender's or operator's behalf, and the redirect policy strips exactly that, so a header added to the forward set is covered without a second edit. Content-Type and User-Agent are the delivery path's own and always travel; a 307 preserves the body across hosts and it has to stay typed. The origin comparison no longer collapses two IPv6 origins into one. Hostname() unwraps a literal's brackets, so re-appending the port with a bare colon rendered https://[2001:db8::1]:8080 and https://[2001:db8::1:8080] identically — a different address on a different port passing as the same origin. The port is joined with net.JoinHostPort, and both spellings are in TestSameDeliveryOrigin. The ten-hop cap gains a regression test. Installing a CheckRedirect is precisely what discards net/http's own limit, so a self-redirecting destination is driven through the policy and asserted to stop after exactly ten requests with the sentinel surfacing to the caller. Trailer joins the reserved names. net/http strips it from the request it writes, so a configured one was accepted, stored, and provably never sent. The invalid-header-name error no longer quotes the text before the first colon. That text is only a name if it parses as one; when it does not, a pasted value whose own colon split the line put half a token into a 400 body. TestParseTargetHeaders_ErrorsNeverQuoteAValue asserted this invariant while only exercising the after-the-colon case, and now covers the before-the-colon one. README documents the http target's config keys, the 300-second timeout ceiling, the reserved-header list and the redirect behaviour as one rule over both header classes, including that the drop is per hop rather than permanent: net/http re-copies the initial request's headers each hop, so a chain returning to the configured origin carries them again, exactly as it treats Authorization. The edit form's hint gains Trailer and the redirect note. Closes #243
This commit is contained in:
@@ -5,6 +5,7 @@ import (
|
||||
"log/slog"
|
||||
"net"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"time"
|
||||
|
||||
"go.uber.org/fx"
|
||||
@@ -49,13 +50,14 @@ func ExportIsForwardableHeader(name string) bool {
|
||||
}
|
||||
|
||||
// ExportApplyRequestHeaders exposes applyRequestHeaders, so a test
|
||||
// can inspect the header set an outbound delivery actually carries.
|
||||
// can inspect the header set an outbound delivery actually carries
|
||||
// and the origin-scoped names it reports for the redirect policy.
|
||||
func ExportApplyRequestHeaders(
|
||||
req *http.Request,
|
||||
event *database.Event,
|
||||
cfg *HTTPTargetConfig,
|
||||
) {
|
||||
applyRequestHeaders(req, event, cfg)
|
||||
) []string {
|
||||
return applyRequestHeaders(req, event, cfg)
|
||||
}
|
||||
|
||||
// ExportTruncate exposes truncate for testing.
|
||||
@@ -165,12 +167,27 @@ func (e *Engine) ExportDoHTTPRequest(
|
||||
return e.httpTarget.doHTTPRequest(ctx, cfg, event)
|
||||
}
|
||||
|
||||
// ExportClientForConfig exposes the http target's
|
||||
// clientForConfig.
|
||||
func (e *Engine) ExportClientForConfig(
|
||||
// ExportClientForRequest exposes the http target's
|
||||
// clientForRequest.
|
||||
func (e *Engine) ExportClientForRequest(
|
||||
cfg *HTTPTargetConfig,
|
||||
originScoped []string,
|
||||
) *http.Client {
|
||||
return e.httpTarget.clientForConfig(cfg)
|
||||
return e.httpTarget.clientForRequest(cfg, originScoped)
|
||||
}
|
||||
|
||||
// ErrExportTooManyRedirects exposes the sentinel the redirect
|
||||
// policy returns once a chain exceeds the hop cap. It carries the
|
||||
// Err prefix rather than this file's usual Export one because it
|
||||
// is a sentinel error.
|
||||
var ErrExportTooManyRedirects = errTooManyRedirects
|
||||
|
||||
// ExportMaxDeliveryRedirects exposes the redirect hop cap.
|
||||
const ExportMaxDeliveryRedirects = maxDeliveryRedirects
|
||||
|
||||
// ExportSameDeliveryOrigin exposes sameDeliveryOrigin.
|
||||
func ExportSameDeliveryOrigin(origin, dest *url.URL) bool {
|
||||
return sameDeliveryOrigin(origin, dest)
|
||||
}
|
||||
|
||||
// ExportClient returns the http target's shared HTTP client.
|
||||
|
||||
Reference in New Issue
Block a user