gitea: the internal-API refusal is part of the route, not a file beside the proxy
The 2026-09-12 incident response blocked /api/internal by hand in the predecessor's dynamic directory, with a note that its durable home is the mesh's routing. A route carries the policy applied to a request (ADR 0108), so the refusal now travels with the grant: route-proxy enforces it on both the public name and the internal alias the moment it serves this route, and the adapter skips it aloud (no port, nothing to write) while the predecessor's own file still stands. The hand-authored file retires with the proxy it configures.
This commit is contained in:
@@ -11,8 +11,16 @@
|
||||
"name": "gitea"
|
||||
},
|
||||
"route": {
|
||||
"web": {
|
||||
"label": "git",
|
||||
"port": 3000
|
||||
},
|
||||
"internal-api-refused": {
|
||||
"label": "git",
|
||||
"path": "/api/internal",
|
||||
"deny": true,
|
||||
"priority": 100000
|
||||
}
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
|
||||
Reference in New Issue
Block a user