feat(11-03): re-authorize every Centrifugo subscribe through a namespace registry
- lighthouse: Registry of namespace authorizers (Result, Allowed, Denied), ParseChannel, ChannelID with PHP (int)-cast semantics (PHPInt, pinned by a php -r table test), FormatChannels, WithClientID/ClientID - centrifugo: ProxyHandler (constant-time X-Centrifugo-Secret, HTTP 200 generic deny, info [] on allow, presence allow/override merge, 64 KiB body cap) mounted as the ServerToServer subscribe route - README: proxy contract, registry and channel rules
This commit is contained in:
@@ -5,11 +5,13 @@
|
||||
package centrifugo
|
||||
|
||||
import (
|
||||
"net/netip"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"git.golem15.com/golem15/summercms/modules/compass"
|
||||
"git.golem15.com/golem15/summercms/modules/lighthouse"
|
||||
"git.golem15.com/golem15/summercms/modules/surf"
|
||||
)
|
||||
|
||||
// Default values of the realtime.centrifugo.* keys.
|
||||
@@ -40,6 +42,9 @@ type Config struct {
|
||||
// TokenPath and SubscribePath are the mounted route paths.
|
||||
TokenPath string
|
||||
SubscribePath string
|
||||
// TrustedProxies are the http.trusted_proxies used to log the client IP
|
||||
// of a denied subscribe.
|
||||
TrustedProxies []netip.Prefix
|
||||
}
|
||||
|
||||
// LoadConfig reads realtime.centrifugo.* from c, filling the defaults.
|
||||
@@ -74,5 +79,6 @@ func LoadConfig(c *compass.Config) Config {
|
||||
if v := str("subscribe_path"); v != "" {
|
||||
cfg.SubscribePath = v
|
||||
}
|
||||
cfg.TrustedProxies = surf.TrustedProxies(c)
|
||||
return cfg
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user