route-proxy serves a route's internal-name alias, never certifies it
A route now consumed with two hosts when the mesh composed both — the same host under internal-name reaches the same rule as its public name, restoring the convenience a predecessor proxy gave for reaching a service over the VPN without a public TLS round trip (the field composeName now writes, feat/route-carries-internal-alias — this branch depends on that one landing for internal-name to ever be populated; builds and tests clean without it, just serves nothing extra). Never certified: onlyWhatTheMeshSaid used routed(), which answered yes for any host in the table regardless of how it got there. A new eligibleForACME() checks a parallel 'public' set instead — every host reached through a route's own name, never one reached only through its internal-name — so an internal alias is proxied but never given its own failing ACME order. routed() is unchanged and still used for the 404 message, which legitimately wants 'is this host served at all.'
This commit is contained in:
@@ -61,12 +61,12 @@ func proxyFor(t *testing.T, routesJSON string) string {
|
||||
if err := os.WriteFile(path, []byte(routesJSON), 0o644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
routes, err := routesFrom(path)
|
||||
routes, public, err := routesFrom(path)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
held := newTable()
|
||||
held.set(routes)
|
||||
held.set(routes, public)
|
||||
server := httptest.NewServer(handler(held))
|
||||
t.Cleanup(server.Close)
|
||||
return server.URL
|
||||
@@ -157,7 +157,7 @@ func TestACredentialInTheDeclarationIsRefusedRatherThanServed(t *testing.T) {
|
||||
if err := os.WriteFile(path, []byte(body), 0o644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
routes, err := routesFrom(path)
|
||||
routes, _, err := routesFrom(path)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user