route-proxy: a policy refusal is also not-my-token
autocert checks the host policy before the token and answers 403 — the internal authority does this for every public name, so mail.novox.be's challenge died on the internal manager's probe one commit after it stopped dying on the public one's 404. Both shapes of refusal now fall through to routing; a fifth test pins the 403 case with a refusing policy.
This commit is contained in:
@@ -458,8 +458,11 @@ func tokenOrRoute(routes http.Handler, managers ...*autocert.Manager) http.Handl
|
||||
for _, probe := range probes {
|
||||
buffered := &probedResponse{header: make(http.Header)}
|
||||
probe.ServeHTTP(buffered, r)
|
||||
if buffered.status == http.StatusNotFound {
|
||||
continue // not this manager's token
|
||||
// Two shapes of "not mine": 404, a token this manager is not holding — and 403, a
|
||||
// name its host policy would never certify at all (autocert checks the policy before
|
||||
// the token, so the internal authority answers 403 for every public name).
|
||||
if buffered.status == http.StatusNotFound || buffered.status == http.StatusForbidden {
|
||||
continue
|
||||
}
|
||||
buffered.replayTo(w)
|
||||
return
|
||||
|
||||
Reference in New Issue
Block a user