mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-09-30 11:41:19 +02:00
@@ -16,6 +16,7 @@ func validateAllowlists(o *options.Options) []string {
|
||||
|
||||
msgs = append(msgs, validateAuthRoutes(o)...)
|
||||
msgs = append(msgs, validateAuthRegexes(o)...)
|
||||
msgs = append(msgs, validateTrustedProxyIPs(o)...)
|
||||
msgs = append(msgs, validateTrustedIPs(o)...)
|
||||
|
||||
if len(o.TrustedIPs) > 0 && o.ReverseProxy {
|
||||
@@ -28,6 +29,17 @@ func validateAllowlists(o *options.Options) []string {
|
||||
return msgs
|
||||
}
|
||||
|
||||
// validateTrustedProxyIPs validates IP/CIDRs for trusted reverse proxies.
|
||||
func validateTrustedProxyIPs(o *options.Options) []string {
|
||||
msgs := []string{}
|
||||
for i, ipStr := range o.TrustedProxyIPs {
|
||||
if ip.ParseIPNet(ipStr) == nil {
|
||||
msgs = append(msgs, fmt.Sprintf("trusted_proxy_ips[%d] (%s) could not be recognized", i, ipStr))
|
||||
}
|
||||
}
|
||||
return msgs
|
||||
}
|
||||
|
||||
// validateAuthRoutes validates method=path routes passed with options.SkipAuthRoutes
|
||||
func validateAuthRoutes(o *options.Options) []string {
|
||||
msgs := []string{}
|
||||
|
||||
@@ -23,6 +23,11 @@ var _ = Describe("Allowlist", func() {
|
||||
errStrings []string
|
||||
}
|
||||
|
||||
type validateTrustedProxyIPsTableInput struct {
|
||||
trustedProxyIPs []string
|
||||
errStrings []string
|
||||
}
|
||||
|
||||
DescribeTable("validateRoutes",
|
||||
func(r *validateRoutesTableInput) {
|
||||
opts := &options.Options{
|
||||
@@ -121,4 +126,29 @@ var _ = Describe("Allowlist", func() {
|
||||
},
|
||||
}),
|
||||
)
|
||||
|
||||
DescribeTable("validateTrustedProxyIPs",
|
||||
func(t *validateTrustedProxyIPsTableInput) {
|
||||
opts := &options.Options{
|
||||
TrustedProxyIPs: t.trustedProxyIPs,
|
||||
}
|
||||
Expect(validateTrustedProxyIPs(opts)).To(ConsistOf(t.errStrings))
|
||||
},
|
||||
Entry("Valid trusted proxy IPs", &validateTrustedProxyIPsTableInput{
|
||||
trustedProxyIPs: []string{
|
||||
"127.0.0.1",
|
||||
"10.32.0.1/32",
|
||||
"::1",
|
||||
"2a12:105:ee7:9234:0:0:0:0/64",
|
||||
},
|
||||
errStrings: []string{},
|
||||
}),
|
||||
Entry("Invalid trusted proxy IPs", &validateTrustedProxyIPsTableInput{
|
||||
trustedProxyIPs: []string{"[::1]", "alkwlkbn/32"},
|
||||
errStrings: []string{
|
||||
"trusted_proxy_ips[0] ([::1]) could not be recognized",
|
||||
"trusted_proxy_ips[1] (alkwlkbn/32) could not be recognized",
|
||||
},
|
||||
}),
|
||||
)
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user