From 45e9501a2f70de0a712d4b477e2044d350d7dc23 Mon Sep 17 00:00:00 2001 From: zino Date: Tue, 5 Dec 2023 23:22:41 +0100 Subject: [PATCH] m --- volumes/conf.d/code.zinomedia.de.conf | 22 +++++++++---------- .../validate.vouch.armos.zinomedia.de.conf | 2 +- 2 files changed, 12 insertions(+), 12 deletions(-) diff --git a/volumes/conf.d/code.zinomedia.de.conf b/volumes/conf.d/code.zinomedia.de.conf index a93430e..5c2b335 100644 --- a/volumes/conf.d/code.zinomedia.de.conf +++ b/volumes/conf.d/code.zinomedia.de.conf @@ -30,18 +30,18 @@ server { internal; proxy_pass https://validate.vouch.armos.zinomedia.de; - #be sure to pass the original host header - proxy_set_header Host $http_host; + # # be sure to pass the original host header + # proxy_set_header Host $http_host; - # Vouch Proxy only acts on the request headers - proxy_pass_request_body off; - proxy_set_header Content-Length ""; - # optionally add X-Vouch-User as returned by Vouch Proxy along with the request - auth_request_set $auth_resp_x_vouch_user $upstream_http_x_vouch_user; - # these return values are used by the @error401 call - auth_request_set $auth_resp_jwt $upstream_http_x_vouch_jwt; - auth_request_set $auth_resp_err $upstream_http_x_vouch_err; - auth_request_set $auth_resp_failcount $upstream_http_x_vouch_failcount; + # # Vouch Proxy only acts on the request headers + # proxy_pass_request_body off; + # proxy_set_header Content-Length ""; + # # optionally add X-Vouch-User as returned by Vouch Proxy along with the request + # auth_request_set $auth_resp_x_vouch_user $upstream_http_x_vouch_user; + # # these return values are used by the @error401 call + # auth_request_set $auth_resp_jwt $upstream_http_x_vouch_jwt; + # auth_request_set $auth_resp_err $upstream_http_x_vouch_err; + # auth_request_set $auth_resp_failcount $upstream_http_x_vouch_failcount; } # if validate returns `401 not authorized` then forward the request to the error401block diff --git a/volumes/conf.d/validate.vouch.armos.zinomedia.de.conf b/volumes/conf.d/validate.vouch.armos.zinomedia.de.conf index b458023..0df1147 100644 --- a/volumes/conf.d/validate.vouch.armos.zinomedia.de.conf +++ b/volumes/conf.d/validate.vouch.armos.zinomedia.de.conf @@ -1,4 +1,4 @@ -log_format custom '[$time_iso8601] VALIDATE | request_uri: $request_uri | status: $status | http_host: $http_host | auth_resp_x_vouch_user: $auth_resp_x_vouch_user | upstream_http_x_vouch_user: $upstream_http_x_vouch_user | auth_resp_jwt: $auth_resp_jwt | upstream_http_x_vouch_jwt: $upstream_http_x_vouch_jwt | auth_resp_err: $auth_resp_err | upstream_http_x_vouch_err: $upstream_http_x_vouch_err | auth_resp_failcount: $auth_resp_failcount | upstream_http_x_vouch_failcount: $upstream_http_x_vouch_failcount'; +log_format custom '[$time_iso8601] VALIDATE | proxy_add_x_forwarded_for: $proxy_add_x_forwarded_host | request_uri: $request_uri | status: $status | http_host: $http_host | auth_resp_x_vouch_user: $auth_resp_x_vouch_user | upstream_http_x_vouch_user: $upstream_http_x_vouch_user | auth_resp_jwt: $auth_resp_jwt | upstream_http_x_vouch_jwt: $upstream_http_x_vouch_jwt | auth_resp_err: $auth_resp_err | upstream_http_x_vouch_err: $upstream_http_x_vouch_err | auth_resp_failcount: $auth_resp_failcount | upstream_http_x_vouch_failcount: $upstream_http_x_vouch_failcount'; server { listen 443 ssl;