Merge branch 'main' into v2
* main: feat(stdiscosrv): configurable desired not-found rate chore(blobs): generalised blob storage chore(stdiscosrv): path style s3 feat(ursv): add os/arch/distribution metric chore(strelaypoolsrv): limit number of returned relays build(infra): run in Docker environment for pushes chore(stupgrades): expose latest release as a metric feat(api, gui): allow authentication bypass for metrics (#10045)
This commit is contained in:
+6
-2
@@ -51,7 +51,7 @@ func forbidden(w http.ResponseWriter) {
|
||||
http.Error(w, "Forbidden", http.StatusForbidden)
|
||||
}
|
||||
|
||||
func isNoAuthPath(path string) bool {
|
||||
func isNoAuthPath(path string, metricsWithoutAuth bool) bool {
|
||||
// Local variable instead of module var to prevent accidental mutation
|
||||
noAuthPaths := []string{
|
||||
"/",
|
||||
@@ -60,6 +60,10 @@ func isNoAuthPath(path string) bool {
|
||||
"/rest/svc/lang", // Required to load language settings on login page
|
||||
}
|
||||
|
||||
if metricsWithoutAuth {
|
||||
noAuthPaths = append(noAuthPaths, "/metrics")
|
||||
}
|
||||
|
||||
// Local variable instead of module var to prevent accidental mutation
|
||||
noAuthPrefixes := []string{
|
||||
// Static assets
|
||||
@@ -115,7 +119,7 @@ func (m *basicAuthAndSessionMiddleware) ServeHTTP(w http.ResponseWriter, r *http
|
||||
}
|
||||
|
||||
// Exception for static assets and REST calls that don't require authentication.
|
||||
if isNoAuthPath(r.URL.Path) {
|
||||
if isNoAuthPath(r.URL.Path, m.guiCfg.MetricsWithoutAuth) {
|
||||
m.next.ServeHTTP(w, r)
|
||||
return
|
||||
}
|
||||
|
||||
+1
-1
@@ -78,7 +78,7 @@ func (m *csrfManager) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
|
||||
if isNoAuthPath(r.URL.Path) {
|
||||
if isNoAuthPath(r.URL.Path, false) {
|
||||
// REST calls that don't require authentication also do not
|
||||
// need a CSRF token.
|
||||
m.next.ServeHTTP(w, r)
|
||||
|
||||
Reference in New Issue
Block a user