route-proxy: a policy refusal is also not-my-token
autocert checks the host policy before the token and answers 403 — the internal authority does this for every public name, so mail.novox.be's challenge died on the internal manager's probe one commit after it stopped dying on the public one's 404. Both shapes of refusal now fall through to routing; a fifth test pins the 403 case with a refusing policy.
This commit is contained in:
@@ -7,6 +7,8 @@ package main
|
||||
// three behaviours tokenOrRoute exists for.
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
@@ -73,6 +75,27 @@ func TestASecondAuthorityIsProbedBeforeRouting(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnAuthorityWhosePolicyRefusesTheNameIsProbedPast(t *testing.T) {
|
||||
// autocert checks the host policy before the token and answers 403 — the internal authority
|
||||
// does this for every public name. A policy refusal is as much "not mine" as a missing token:
|
||||
// the request must still reach plain routing, where the workload's own ACME client answers.
|
||||
refusing := &autocert.Manager{
|
||||
Prompt: autocert.AcceptTOS,
|
||||
Cache: autocert.DirCache(t.TempDir()),
|
||||
HostPolicy: func(ctx context.Context, host string) error {
|
||||
return fmt.Errorf("no internal-only route for %q in this mesh", host)
|
||||
},
|
||||
}
|
||||
h := tokenOrRoute(routedTo(t, "the workload answered"), refusing)
|
||||
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, httptest.NewRequest("GET", "http://mail.example/.well-known/acme-challenge/mailus-token", nil))
|
||||
|
||||
if rec.Code != http.StatusOK || rec.Body.String() != "the workload answered" {
|
||||
t.Fatalf("a policy refusal must fall through to routing; got %d %q", rec.Code, rec.Body.String())
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnOrdinaryPathNeverTouchesTheChallengeMachinery(t *testing.T) {
|
||||
m := &autocert.Manager{Prompt: autocert.AcceptTOS, Cache: autocert.DirCache(t.TempDir())}
|
||||
h := tokenOrRoute(routedTo(t, "routed"), m)
|
||||
|
||||
Reference in New Issue
Block a user