mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-10 00:15:39 +02:00
@@ -16,6 +16,7 @@ func validateAllowlists(o *options.Options) []string {
|
||||
|
||||
msgs = append(msgs, validateAuthRoutes(o)...)
|
||||
msgs = append(msgs, validateAuthRegexes(o)...)
|
||||
msgs = append(msgs, validateTrustedProxyIPs(o)...)
|
||||
msgs = append(msgs, validateTrustedIPs(o)...)
|
||||
|
||||
if len(o.TrustedIPs) > 0 && o.ReverseProxy {
|
||||
@@ -28,6 +29,17 @@ func validateAllowlists(o *options.Options) []string {
|
||||
return msgs
|
||||
}
|
||||
|
||||
// validateTrustedProxyIPs validates IP/CIDRs for trusted reverse proxies.
|
||||
func validateTrustedProxyIPs(o *options.Options) []string {
|
||||
msgs := []string{}
|
||||
for i, ipStr := range o.TrustedProxyIPs {
|
||||
if ip.ParseIPNet(ipStr) == nil {
|
||||
msgs = append(msgs, fmt.Sprintf("trusted_proxy_ips[%d] (%s) could not be recognized", i, ipStr))
|
||||
}
|
||||
}
|
||||
return msgs
|
||||
}
|
||||
|
||||
// validateAuthRoutes validates method=path routes passed with options.SkipAuthRoutes
|
||||
func validateAuthRoutes(o *options.Options) []string {
|
||||
msgs := []string{}
|
||||
|
||||
Reference in New Issue
Block a user