mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-08 18:37:46 +08:00
fix(auth): reject unsigned admin identity headers
This commit is contained in:
@@ -177,6 +177,19 @@ fn extract_trusted_auth_headers(headers: &http::HeaderMap) -> Option<GatewayTrus
|
||||
})
|
||||
}
|
||||
|
||||
#[cfg(not(test))]
|
||||
pub(super) fn extract_trusted_admin_headers(
|
||||
_headers: &http::HeaderMap,
|
||||
) -> Option<GatewayTrustedAdminHeaders> {
|
||||
// The public gateway has no authenticated upstream that is allowed to
|
||||
// assert an administrator principal. `x-aether-gateway` is also emitted
|
||||
// on public responses, so it cannot serve as proof that these headers were
|
||||
// produced by a trusted hop. Production requests must authenticate with a
|
||||
// real admin session or management bearer token instead.
|
||||
None
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
pub(super) fn extract_trusted_admin_headers(
|
||||
headers: &http::HeaderMap,
|
||||
) -> Option<GatewayTrustedAdminHeaders> {
|
||||
|
||||
Reference in New Issue
Block a user