Repository navigation
Fixes #39818 - Configure permitted Smart Proxy hostnames #900
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -36,6 +36,7 @@ | |
| #:foreman_url: http://127.0.0.1:3000 | ||
|
|
||
| :foreman_url: https://{{ ansible_facts['fqdn'] }} | ||
| :permitted_hosts: {{ ([ansible_facts['fqdn']] + (server_aliases | default([]))) | to_json }} | ||
|
Comment on lines
38
to
+39
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🌐 Web query:
💡 Result: 🏁 Script executed: set -u
printf '%s\n' '--- local deployment task ---'
cat -n development/roles/git_repository/defaults/main.yml
cat -n development/roles/git_repository/tasks/main.yml
cat -n development/roles/foreman_development/tasks/smart-proxy/main.yml
printf '%s\n' '--- template ---'
cat -n development/roles/foreman_development/templates/smart-proxy/settings.yml.j2
printf '%s\n' '--- remote metadata ---'
curl -fsSL https://api.github.com/repos/theforeman/smart-proxy | python3 -c 'import json,sys; d=json.load(sys.stdin); print("default_branch=", d.get("default_branch")); print("html_url=", d.get("html_url")); print("pushed_at=", d.get("pushed_at"))'
printf '%s\n' '--- default branch files and references ---'
branch=$(curl -fsSL https://api.github.com/repos/theforeman/smart-proxy | python3 -c 'import json,sys; print(json.load(sys.stdin)["default_branch"])')
printf 'branch=%s\n' "$branch"
for path in config/settings.yaml lib/smart_proxy.rb lib/smart_proxy/defaults.rb lib/smart_proxy/foreman_proxy.rb config.ru Gemfile; do
url="https://raw.githubusercontent.com/theforeman/smart-proxy/$branch/$path"
echo "--- $path ---"
curl -fsSL "$url" | grep -n -E 'permitted_hosts|trusted_hosts|host.*permission|permitted|settings' || true
done
printf '%s\n' '--- default branch tree references ---'
curl -fsSL "https://api.github.com/repos/theforeman/smart-proxy/git/trees/$branch?recursive=1" |
python3 -c 'import json,sys; d=json.load(sys.stdin); [print(x["path"]) for x in d.get("tree",[]) if any(k in x["path"].lower() for k in ("setting","sinatra","rack","config"))]'Repository: theforeman/foremanctl Length of output: 17843 🏁 Script executed: set -u
branch=develop
for path in config/settings.yml.example lib/proxy/settings.rb lib/proxy/settings/global.rb lib/sinatra/authorization.rb test/sinatra/authorization_helpers_test.rb test/sinatra/trusted_hosts_test.rb test/global_settings_test.rb; do
url="https://raw.githubusercontent.com/theforeman/smart-proxy/$branch/$path"
echo "--- $path ---"
if curl -fsSL "$url" | grep -n -E -C 5 'permitted_hosts|trusted_hosts|host.*(author|permission)|settings|Setting'; then
:
else
status=$?
echo "no matching lines or fetch failure status=$status"
fi
done
printf '%s\n' '--- all develop tree paths containing permitted/trusted/authorization ---'
curl -fsSL "https://api.github.com/repos/theforeman/smart-proxy/git/trees/$branch?recursive=1" |
python3 -c 'import json,sys; d=json.load(sys.stdin); [print(x["path"]) for x in d.get("tree",[]) if any(k in x["path"].lower() for k in ("permitted", "trusted", "authoriz"))]'Repository: theforeman/foremanctl Length of output: 10970 🏁 Script executed: set -u
tmp=$(mktemp -d)
trap 'rm -rf "$tmp"' EXIT
curl -fsSL https://github.com/theforeman/smart-proxy/archive/refs/heads/develop.tar.gz -o "$tmp/smart-proxy.tar.gz"
tar -xzf "$tmp/smart-proxy.tar.gz" -C "$tmp"
root=$(find "$tmp" -mindepth 1 -maxdepth 1 -type d -name 'smart-proxy-*' -print -quit)
printf '%s\n' '--- complete develop source references ---'
grep -RInE 'permitted_hosts|host_authorization|allowed_hosts|trusted_hosts|HostAuthorization' "$root" --exclude-dir=.git || true
printf '%s\n' '--- application/configuration files ---'
find "$root" -maxdepth 3 -type f \( -name '*.rb' -o -name '*.ru' -o -name 'Gemfile*' \) -print | sort
for path in config.ru lib/proxy/server.rb lib/sinatra/base.rb lib/sinatra/authorization.rb Gemfile Gemfile.lock; do
file="$root/$path"
if [ -f "$file" ]; then
echo "--- $path ---"
cat -n "$file" | sed -n '1,220p'
fi
doneRepository: theforeman/foremanctl Length of output: 36126 🏁 Script executed: set -u
tmp=$(mktemp -d)
trap 'rm -rf "$tmp"' EXIT
curl -fsSL https://github.com/theforeman/smart-proxy/archive/refs/heads/develop.tar.gz -o "$tmp/smart-proxy.tar.gz"
tar -xzf "$tmp/smart-proxy.tar.gz" -C "$tmp"
root=$(find "$tmp" -mindepth 1 -maxdepth 1 -type d -name 'smart-proxy-*' -print -quit)
for path in lib/smart_proxy_main.rb smart-proxy.gemspec lib/smart_proxy.rb; do
file="$root/$path"
if [ -f "$file" ]; then
echo "--- $path ---"
cat -n "$file" | sed -n '1,180p'
fi
doneRepository: theforeman/foremanctl Length of output: 3397 🏁 Script executed: set -u
git diff --unified=80 1386cb127fcd556ca23e545c15cc0c8300896c9d 3da0e24c934017f51ab35bb724a5e0b957517d91 -- development/roles/foreman_development/templates/smart-proxy/settings.yml.j2
printf '%s\n' '--- server_aliases definitions/usages ---'
rg -n -C 3 'server_aliases|permitted_hosts|trusted_hosts' development srcRepository: theforeman/foremanctl Length of output: 16164 Pin Smart Proxy before rendering The development role clones Smart Proxy with 🤖 Prompt for AI Agents |
||
|
|
||
| # SSL settings for client authentication against Foreman. If undefined, the values | ||
| # from general SSL options are used instead. Mainly useful when Foreman uses | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Don't you think this behavior should be documented here?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done. It's doubtful whether it's a good place since those sections are dedicated to certificates, but I don't have a better suggestion.