【问题标题】:Sonarqube behind https proxy with X_FORWARDED_PROTO带有 X_FORWARDED_PROTO 的 https 代理后面的 Sonarqube
【发布时间】:2016-01-20 13:44:31
【问题描述】:

我想要达到的目标:

浏览器 -> Apache (https) -> Sonarqube (http)

问题:

Sonar 的位置标头是 http://..,所以访问 https://trm.tine.no/sonar 重定向到 http://trm.tine.no/sonar

我已按照此处所述的标准反向代理基础架构的说明进行操作: http://docs.sonarqube.org/display/SONAR/Running+SonarQube+Over+HTTPS

ProxyPreserveHost On
ProxyRequests Off
..
.. SSL config goes here
..
RequestHeader set X-Forwarded-Proto "https"

#SONAR related configurations
AllowEncodedSlashes NoDecode
ProxyPass /sonar http://<my.ip>:9000/sonar disablereuse=On nocanon
ProxyPassReverse /sonar http://<my.ip>:9000/sonar

我已经通过代理 Nexus(也依赖于 X-Forwarded-Proto)验证了 X-Forwarded-Proto 标头,并且按预期工作。

curl 将 Location 标头确认为 http,而不是 https curl -I https://trm.tine.no/sonar

HTTP/1.1 302 Found
Date: Wed, 21 Oct 2015 13:49:39 GMT
Server: Apache-Coyote/1.1
Location: http://trm.tine.no/sonar/
Transfer-Encoding: chunked

想知道我可能遗漏了什么,或者这是否是一个实际的错误?

运行 Sonarqube 5.1.1

解决方案

@kraal 提出的解决方案对我们没有任何影响,但如果您将 / 附加到 URI,它就可以工作。

例如

curl -I https://trm.tine.no/sonar
HTTP/1.1 302 Found
Date: Thu, 22 Oct 2015 10:53:23 GMT
Server: Apache-Coyote/1.1
Location: http://trm.tine.no/sonar/
Transfer-Encoding: chunked

正如我们所见,Location 仍然设置为 http,但以下工作(注意末尾的 /)

curl -I https://trm.tine.no/sonar/
HTTP/1.1 302 Found  
Date: Thu, 22 Oct 2015 10:53:25 GMT
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Location: https://trm.tine.no/sonar/sessions/new
X-Frame-Options: SAMEORIGIN
Content-Type: text/html;charset=utf-8
Content-Length: 104
Set-Cookie: JSESSIONID=A8B19F73D93B35BCA24F019EEB848666; Path=/sonar/; HttpOnly

所以当 Sonar 重​​定向到 /sonar/sessions/new(登录页面)时似乎发生了一些事情,它的行为与 /sonar/ 到 /sonar 不同

将 / 附加到 URI 是一种适用于我们的解决方法。

【问题讨论】:

    标签: sonarqube mod-proxy sonarqube5.1


    【解决方案1】:

    在我使用 Apache 2.4 和 Sonarqube 8.0 的情况下,我解决了:

    <Location /sonarqube>
            RewriteEngine  On
            RewriteCond %{HTTP:X-Forwarded-Proto} !https
            RewriteCond %{HTTPS} off
            RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301,NE]
    
            ProxyPreserveHost On
            ProxyPass http://192.168.10.15:9000/sonarqube
            ProxyPassReverse http://192.168.10.15:9000/sonarqube
    </Location>
    

    【讨论】:

      【解决方案2】:

      (对于偶然发现这篇文章的任何人,我在 google 组中发布了类似的问题:https://groups.google.com/forum/#!topic/sonarqube/mztZGAvG_I0 并被回复者通知关闭此帖子,我无意造成重复)

      关于通过更改尾部斜杠对您有用的修复,遗憾的是这对我不起作用(我已经附加了它们)删除它们也不起作用。

      【讨论】:

      • 感谢您告诉我,我也会监控 google 群组线程
      【解决方案3】:

      问题可能是由于您的ProxyPassReverse。以下是我们配置的摘录(使用 apache

      <VirtualHost *:443>
          # https and port are specified in order to make sure that the server generates the correct
          # self-referential URLs.
          ServerName https://visiblehost:443
      
          # ... SSL and other configuration here
      
          # ProxyRequests must be set to "off" as we use Apache as a reverse proxy.
          ProxyRequests           Off
      
          # ProxyPreserveHost must be set to "on" in order to pass the Host: line from the incoming request to the
          # proxied host, instead of the hostname specified in the ProxyPass line.
          ProxyPreserveHost       On
      
          # AllowEncodedSlashes must be set to "on" in order to preserve urls built by SonarQube which include
          # encoded slashes. Once we upgrade to Apache 2.2.18, the property will need to be set to "NoDecode".
          AllowEncodedSlashes     On
      
          # Some RequestHeaders must be set in order for the headers to have the right value required for https
          # communications.
          RequestHeader set X-Forwarded-Proto "https"
          RequestHeader set X-Forwarded-Port "443"
      
          # ProxyPass defines that Apache communicates with SonarQube using ajp protocol
          # and that no canonalization has to be done.
          # ReverseProxyPass defines that https communications are only done between client
          # and Apache.
      
          ProxyPass               /sonar    ajp://hiddenhost:port/sonar nocanon
          ProxyPassReverse        /sonar    https://visiblehost/sonar
      
      </VirtualHost>
      

      如您所见,一方面,ProxyPassReverse 定义必须在用户和 /sonar 上下文根上的反向代理之间进行 https 通信。指定的 URL 是对用户“可见”的 Apache URL。

      另一方面,ProxyPass 定义 Apache 将 /sonar 上的所有流量发送到“隐藏”URL。在我们的例子中,我们使用AJP 协议以确保无法直接访问此 URL,但如果您使用的是http,则配置应该类似(将ajp 替换为http)。

      希望对你有帮助,

      米歇尔

      【讨论】:

      • 感谢您的输入,我已更新原始帖子以包含我们的解决方案。
      • 您的解决方案不是真正的解决方法,curl -I 不遵循 HTTP 302 重定向响应。尝试输入curl -I -L https://trm.tine.no/sonar。注意你还需要确保sonar.core.serverBaseURL设置正确,即如果你想使用https协议,你在SQ设置中设置的Server base URL必须使用https协议,并且ReverseProxyPass指令也应该用https定义协议。
      • 旁注:为什么将 https 重定向到同一主机上的 http?这意味着任何人都可以通过http URL访问SQ,也就是说你的url是完全不安全的。
      • 也许 curl 应该遵循重定向,然而,这并没有太大变化,我在 firefox/chrome 中观察到完全相同的行为,即trm.tine.no/sonar 被重定向到 http。我已经以完全相同的方式配置了 4 个其他应用程序,它们都在工作,并且没有重定向到 http,所以 Sonar 肯定有一些不同的东西。注册旁注:确认 https 正常工作后,Http 将立即关闭!
      • 您在设置中正确设置了 Sonar Base URL 吗?
      猜你喜欢
      • 1970-01-01
      • 2019-08-14
      • 2016-06-13
      • 2015-07-16
      • 2017-12-31
      • 1970-01-01
      • 1970-01-01
      • 2020-02-20
      • 1970-01-01
      相关资源
      最近更新 更多