Skip to content

修复 UserService v1/v2 本机来源头认证绕过 - #49

Open
atopos31 wants to merge 1 commit into
mainfrom
fix/local-jwt-origin
Open

atopos31 wants to merge 1 commit into
mainfrom
fix/local-jwt-origin

Conversation

@atopos31

Copy link
Copy Markdown
Collaborator

修改

将 UserService v1/v2 路由的 JWT 本机豁免从 c.RealIP() 改为同时核对 TCP 对端和代理转发来源。仅在对端与已记录的原始来源均为本机时保留现有本机服务调用;来源冲突或不明确时继续验证 JWT。增加直连、Gateway 转发、IPv6 与伪造来源头的回归测试。

此改动与初始化注册密钥 PR #48 分属不同分支,不包含其注册逻辑修改。

对应问题

阻止无令牌请求仅凭自填的本机来源请求头跳过 UserService 的 JWT 中间件。

验证

  • Linux/arm64 后端构建及路由单元测试通过。
  • 独立 Docker 容器中,v2 受保护只读接口对非本机直连伪造来源头返回 401;本机直连返回 200;Gateway 无令牌请求返回 401;有效令牌请求返回 200。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant