Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions internal/controller/proxy_controller.go
Original file line number Diff line number Diff line change
Expand Up @@ -465,8 +465,8 @@ func (controller *ProxyController) getExtAuthzContext(c *gin.Context) (ProxyCont
return ProxyContext{}, errors.New("host not found")
}

// We get the path from the query string
path := c.Query("path")
// The path is attached to the end of the /api/auth/envoy?path= string so we just strip it out
path := strings.TrimPrefix(c.Request.RequestURI, "/api/auth/envoy?path=")

if strings.TrimSpace(path) == "" {
return ProxyContext{}, errors.New("path not found")
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Expand Down
23 changes: 11 additions & 12 deletions internal/controller/proxy_controller_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -169,7 +169,7 @@ func TestProxyController(t *testing.T) {
router.ServeHTTP(recorder, req)
assert.Equal(t, http.StatusFound, recorder.Code)
location := recorder.Header().Get("Location")
assert.Contains(t, location, url.QueryEscape("https://test.example.com/hello?foo=bar"))
assert.Contains(t, location, url.QueryEscape("https://test.example.com%2Fhello%3Ffoo%3Dbar"))
assert.Contains(t, location, "login_for=app")
assert.Contains(t, location, "https://tinyauth.example.com/login")
},
Expand Down Expand Up @@ -464,17 +464,6 @@ func TestProxyController(t *testing.T) {
assert.Equal(t, http.StatusBadRequest, recorder.Code)
},
},
{
description: "Ensure path block ACL cannot be bypassed with query params on envoy ext authz",
middlewares: []gin.HandlerFunc{},
run: func(t *testing.T, router *gin.Engine, recorder *httptest.ResponseRecorder) {
req := httptest.NewRequest("HEAD", "/api/auth/envoy?path=/admin%3Ffoo=bar", nil)
req.Host = "path-block.example.com"
req.Header.Set("x-forwarded-proto", "https")
router.ServeHTTP(recorder, req)
assert.Equal(t, http.StatusUnauthorized, recorder.Code)
},
},
{
description: "Ensure path block ACL cannot be bypassed with dot segments on nginx auth request",
middlewares: []gin.HandlerFunc{},
Expand Down Expand Up @@ -903,6 +892,16 @@ func TestProxyController(t *testing.T) {
assert.Equal(t, http.StatusBadRequest, recorder.Code)
},
},
{
description: "Ext authz path should not be treated as a query parameter",
run: func(t *testing.T, router *gin.Engine, recorder *httptest.ResponseRecorder) {
req := httptest.NewRequest("HEAD", "/api/auth/envoy?path=/admin?;&path=/allowed", nil)
req.Host = "path-allow.example.com"
req.Header.Set("x-forwarded-proto", "https")
router.ServeHTTP(recorder, req)
assert.Equal(t, http.StatusUnauthorized, recorder.Code)
},
},
}

store := memory.New()
Expand Down
Loading