digitaldemocratic/dd-sso
Evilham 8f5de8af6a
[network] Fix handling of forwarded headers
This fixes several issues where services would see the internal IP of
the proxy and not that of the client.

It works by first unsetting any proxy-related headers that arrive from
the internet, then setting those as seen by HAProxy's entrypoint
frontend.
And finally making sure that neither WAF when enabled nor other
HAProxy backends touch these headers, while they are actually used by
the final services.

Services affected:	Netcloud, Keycloak, Moodle
2022-12-02 06:49:56 +01:00
..
admin [dd-admin] Fix issue propagating changes to NC 2022-10-30 20:01:44 +01:00
docker [network] Fix handling of forwarded headers 2022-12-02 06:49:56 +01:00
docker-compose-parts [WAF] Consolidate proxies and documentation 2022-11-24 12:54:46 +01:00
init/keycloak [sso-avatars] Actually use environment variables 2022-08-06 21:47:35 +02:00
.gitignore [sso-admin] Change container not to run as root 2022-08-01 12:47:30 +02:00
.isort.cfg DD education workspace 2022-07-10 12:15:47 +02:00