Commit 93d0d36
committed
change(core): keep the original X-Forwarded-* on the ctx, not on ctx.var
`api_ctx.var` proxies NGINX variables: `__index` resolves a name against
`ngx.var`, `__newindex` writes through to the real variable for the whitelisted
names. `original_x_forwarded_*` is none of those -- it is a plain Lua value that
#12551 parked in that namespace.
Three consequences, none of them intended:
- It looks like a variable it is not. `$original_x_forwarded_proto` is empty in
`log_format` and in `proxy_set_header`, which is where recording what a client
claimed would actually be useful, yet `ctx.var.original_x_forwarded_proto`
reads back fine from Lua.
- It shares a namespace with real variable names, so a future NGINX variable of
the same name would be silently shadowed by the cached entry.
- Reading one that was never written walks the whole `__index` chain -- the
`uri_param_` / `http_` / `graphql_` / `post_arg.` prefix tests, the dotted-path
branch, the `apisix_var_names` lookup -- and ends in an `ngx.var` lookup for a
name NGINX has never heard of. Measured at 53 ns against 0 for a plain table
read.
So they become `api_ctx.original_x_forwarded_*`. Nothing in this repo reads them
under either name -- they have been write-only since they were added -- so this
changes no behaviour that anything observes. A plugin outside the tree reading
the old name now gets nil rather than a value, which is the same thing it
already got on every trusted request.
TEST 22 gives the field its first coverage: a forged `X-Forwarded-Proto: https`
is rewritten to `http` while the plugin can still see the original.1 parent 9a22aae commit 93d0d36
2 files changed
Lines changed: 46 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
740 | 740 | | |
741 | 741 | | |
742 | 742 | | |
743 | | - | |
744 | | - | |
745 | | - | |
746 | | - | |
747 | | - | |
748 | | - | |
| 743 | + | |
| 744 | + | |
| 745 | + | |
| 746 | + | |
| 747 | + | |
| 748 | + | |
| 749 | + | |
| 750 | + | |
| 751 | + | |
| 752 | + | |
| 753 | + | |
| 754 | + | |
749 | 755 | | |
750 | 756 | | |
751 | 757 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
802 | 802 | | |
803 | 803 | | |
804 | 804 | | |
| 805 | + | |
| 806 | + | |
| 807 | + | |
| 808 | + | |
| 809 | + | |
| 810 | + | |
| 811 | + | |
| 812 | + | |
| 813 | + | |
| 814 | + | |
| 815 | + | |
| 816 | + | |
| 817 | + | |
| 818 | + | |
| 819 | + | |
| 820 | + | |
| 821 | + | |
| 822 | + | |
| 823 | + | |
| 824 | + | |
| 825 | + | |
| 826 | + | |
| 827 | + | |
| 828 | + | |
| 829 | + | |
| 830 | + | |
| 831 | + | |
| 832 | + | |
| 833 | + | |
| 834 | + | |
| 835 | + | |
| 836 | + | |
| 837 | + | |
| 838 | + | |
0 commit comments