Repository navigation
Route to services by host or path prefix - #169
Conversation
A service can declare Hosts and a PathPrefix (optionally stripped and announced in X-Forwarded-Prefix) so several applications can sit behind one AuthProxy without a Service-ID header or ?service= query parameter. The precedence is stated once in ServiceRoutes and shared by the route table, the per-service authorization gate and client-credentials token resolution, and ambiguous declarations fail at startup.
|
Notes for reviewers (not part of the release note): Design decisions (all conservative; flag any you want changed)
Local gate (mirrors CI): Coverage: end-to-end security specs on a running proxy with three origins cover prefix strip + This is security-sensitive and needs a cross-provider review before merge. |
|
Addressed all confirmed review findings, combining the duplicate authorization/header-parsing and anonymous-prefix reports. Authorization and bearer-service resolution now use the selected YARP route. Added regression coverage for quoted/comma-separated service headers, host-selected client-credentials services sharing Local checks passed: solution Debug and Release builds (zero warnings), full Debug specs (74 Aspire, 2223 unit, 270 security), Release security specs (270), frontend high/critical dependency audit, NuGet vulnerability audit, Release publish, and the Docker image build. Checks ran through pi-phase. Linux/x64 execution remains for GitHub CI; local execution used macOS/arm64 and the Docker build used Linux/arm64. The additional The rejected host-scoping finding was intentionally ignored. No product decisions are outstanding. No merge or label changes were made. |
|
Merged origin/main in 2264e8e. The only conflicted file was Requested local checks: solution Release build, AuthProxy.Specs (Debug), and AuthProxy.Security.Specs (Debug) each skipped after pi-phase’s 120-second queue limit; none started (exit 75). PR CI remains the full gate; no CI watch or PR merge performed. Rechecked the release-note body against |
Added
Hostsand/orPathPrefixalongsidex-cratis-microservice(or legacyService-ID) and?service=selection. A path prefix takes precedence over explicit service selection, which takes precedence over a host-only route. Prefix API routes target the backend and other prefix routes target the frontend, falling back to the backend when no frontend is configured.StripPathPrefixremoves the prefix and announces it inX-Forwarded-Prefix, including on anonymous paths. SetClientCredentials.RoutePrefixto the external API prefix, such as/reporting/api, for bearer requests under/reporting. Host declarations accept Unicode and punycode names; ambiguous host and prefix declarations are refused at startup. See Routing by host or path prefix. (Route multiple services by host or path prefix, not only by Service-ID header or ?service= query #150)Security