Stage 10: admin console & dictionary ops (complaint review, hot-reload, broadcasts) (#11)
This commit was merged in pull request #11.
This commit is contained in:
@@ -1,8 +1,11 @@
|
||||
// Package admin is the gateway's admin surface: HTTP Basic-Auth in front of a
|
||||
// reverse proxy to the backend admin API (docs/ARCHITECTURE.md §12). The gateway
|
||||
// validates the operator credential and forwards authenticated requests to
|
||||
// backend /api/v1/admin/*; the backend trusts the gateway on this segment. The
|
||||
// admin API itself is filled in Stage 10.
|
||||
// Package admin is the gateway's admin edge: HTTP Basic-Auth in front of a reverse
|
||||
// proxy that forwards the operator's browser to the backend's server-rendered admin
|
||||
// console under /_gm. The proxy is mounted at /_gm/ on the gateway's public listener
|
||||
// (below the h2c wrap, see internal/connectsrv) and forwards verbatim — an inbound
|
||||
// /_gm/<rest> reaches <backendURL>/_gm/<rest>, preserving the inbound Host so the
|
||||
// backend's same-origin check sees the public origin. The backend trusts the gateway
|
||||
// on this segment and adds the console's same-origin CSRF guard
|
||||
// (docs/ARCHITECTURE.md §12).
|
||||
package admin
|
||||
|
||||
import (
|
||||
@@ -11,17 +14,14 @@ import (
|
||||
"net/http"
|
||||
"net/http/httputil"
|
||||
"net/url"
|
||||
"strings"
|
||||
|
||||
"go.uber.org/zap"
|
||||
)
|
||||
|
||||
// backendAdminPrefix is where the backend mounts its admin API.
|
||||
const backendAdminPrefix = "/api/v1/admin"
|
||||
|
||||
// NewProxy returns a handler that checks Basic-Auth against user/password and
|
||||
// reverse-proxies the request to the backend admin API, mapping an inbound
|
||||
// /admin/<rest> path to <backendURL>/api/v1/admin/<rest>.
|
||||
// reverse-proxies the request verbatim to the backend: the inbound path is
|
||||
// preserved, so /_gm/<rest> reaches <backendURL>/_gm/<rest>. It is mounted at /_gm/
|
||||
// on the gateway's public listener.
|
||||
func NewProxy(backendURL, user, password string, log *zap.Logger) (http.Handler, error) {
|
||||
target, err := url.Parse(backendURL)
|
||||
if err != nil {
|
||||
@@ -32,10 +32,8 @@ func NewProxy(backendURL, user, password string, log *zap.Logger) (http.Handler,
|
||||
}
|
||||
proxy := &httputil.ReverseProxy{
|
||||
Rewrite: func(pr *httputil.ProxyRequest) {
|
||||
pr.SetURL(target)
|
||||
rel := strings.TrimPrefix(pr.In.URL.Path, "/admin")
|
||||
pr.Out.URL.Path = backendAdminPrefix + rel
|
||||
pr.Out.Host = pr.In.Host
|
||||
pr.SetURL(target) // backend scheme+host; the inbound /_gm path is preserved
|
||||
pr.Out.Host = pr.In.Host // keep the public Host for the backend same-origin check
|
||||
},
|
||||
ErrorHandler: func(w http.ResponseWriter, r *http.Request, err error) {
|
||||
log.Warn("admin proxy upstream error", zap.String("path", r.URL.Path), zap.Error(err))
|
||||
|
||||
Reference in New Issue
Block a user