Resolve "NGINX must be reviewed"

Proposers

  • Jorge Moratinos Salcines (Telefónica)

Description

Nginx configuration must be reviewed, due to some issues on validating certificate user and operation in some operations

Main issue rise with helper new APIs, if we use superadmin to reach PATCH or PUT it pass the check, but it should be blocked if configuration is not updated.

Acknowledgements

This work is funded by the European Commission through the HORIZON-JU-SNS-2022 IMAGINE-B5G project with Grant Agreement number 101096452.`

Merge request reports

Loading
+1 −1
Changes for services/helper/helper_service/app.py: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -120,7 +120,7 @@ for name, pkg in package_paths.items():
        openapi_file,             # relative to specification_dir (SERVICES_DIR)
        arguments={"title": title},
        pythonic_params=True,
        base_path=base_path
        base_path="/helper/" + base_path
    )


+40 −0
Changes for services/nginx/endpoints/endpoints.conf: 40 added lines, 0 removed lines.
Original line number Diff line number Diff line
map $uri $endpoint {
    default "NO MATCH";

    # Exact matches for endpoints that require specific handling (Must be on top of the regex matches)
    /api-invoker-management/v1/onboardedInvokers invoker_onboarding_exact;
    /api-provider-management/v1/registrations provider_registrations_exact;
    /service-apis/v1/allServiceAPIs discover_service_exact;

    # Regex matches for endpoints that can be grouped by common patterns
    # Helper related endpoints
    ~^/helper/ helper_base_tree;

    # Invoker management related endpoints
    ~^/api-invoker-management/v1/onboardedInvokers/ invoker_onboarding_tree;

    # Provider management related endpoints
    ~^/api-provider-management/v1/registrations/ provider_registrations_tree;
    
    # Published APIs related endpoints
    ~^/published-apis/v1/ published_apis_tree;

    # Logging related endpoints
    ~^/api-invocation-logs/v1/ logging_tree;
    
    # Auditing related endpoints
    ~^/logs/v1/ auditing_tree;

    # Security related endpoints
    ~^/capif-security/v1/trustedInvokers/.+/update  security_update;
    ~^/capif-security/v1/trustedInvokers/.+/delete  security_delete;
    ~^/capif-security/v1/trustedInvokers/.+  security_trusted_invokers_exact;
    ~^/capif-security/v1/securities/.+/token  security_token;
    ~^/capif-security/v1/  security_tree;

    # Events related endpoints
    ~^/capif-events/v1/  events_tree;

    # Access control policy related endpoints
    ~^/access-control-policy/v1/  acl_tree;
}
+13 −0
Changes for services/nginx/maps/00-services.conf: 13 added lines, 0 removed lines.
Original line number Diff line number Diff line
map $uri $service {
    default "";
    ~^/helper(/|$)  helper;
    ~^/api-invoker-management(/|$)  invoker-management;
    ~^/api-provider-management(/|$)  provider-management;
    ~^/service-apis(/|$)  discover-service;
    ~^/published-apis(/|$)  publish-service;
    ~^/api-invocation-logs(/|$)  logging-service;
    ~^/logs(/|$)  auditing-service;
    ~^/capif-security(/|$)  security-service;
    ~^/capif-events(/|$)  events-service;
    ~^/access-control-policy(/|$)  access-control-policy;
}
+8 −0
Changes for services/nginx/maps/20-methods.conf: 8 added lines, 0 removed lines.
Original line number Diff line number Diff line
map $request_method $method {
    default OTHER;
    GET     GET;
    POST    POST;
    PUT     PUT;
    DELETE  DELETE;
    PATCH   PATCH;
}
+9 −0
Changes for services/nginx/maps/30-auth-type.conf: 9 added lines, 0 removed lines.
Original line number Diff line number Diff line
map $ssl_client_verify $has_cert {
    default 0;
    SUCCESS 1;
}

map $http_authorization $has_token {
    default 0;
    ~^Bearer\s+.+ 1;
}
Loading
Loading