【问题标题】:X-Forwarded-Host header should not be overwritten by the HaProxy when it is already setX-Forwarded-Host 标头在已设置时不应被 HaProxy 覆盖
【发布时间】:2020-01-25 07:05:08
【问题描述】:

有人可以告诉如何在 openshift 3.11 中配置自定义 ha 代理路由器(haproxy-config.template),以避免 X-Forwarded-Host、X-Forwarded-Port 和 X-Forwarded-Proto 标头不应该被覆盖HaProxy 已经设置好了。不设置 header 时,应根据 HTTP 标准进行设置。

我尝试了https://access.redhat.com/solutions/3986281,但它不起作用。

谢谢, 桑托什

【问题讨论】:

    标签: openshift router haproxy


    【解决方案1】:

    以下代码对我有用:

    旧配置:

       http-request set-header X-Forwarded-Host %[req.hdr(host)]
       http-request set-header X-Forwarded-Port %[dst_port]
       http-request set-header X-Forwarded-Proto http if !{ ssl_fc }
       http-request set-header X-Forwarded-Proto https if { ssl_fc }
    

    改成新的:

       acl h_xfh_exists req.hdr(X-Forwarded-Host) -m found
       http-request set-header X-Forwarded-Host %[req.hdr(host)] unless h_xfh_exists
       acl h_xfport_exists req.hdr(X-Forwarded-Port) -m found
       http-request set-header X-Forwarded-Port %[dst_port] unless h_xfport_exists
       acl h_xfproto_exists req.hdr(X-Forwarded-Proto) -m found
       http-request set-header X-Forwarded-Proto http if !{ ssl_fc } !h_xfproto_exists
       http-request set-header X-Forwarded-Proto https if { ssl_fc } !h_xfproto_exists
    

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2013-10-05
      • 1970-01-01
      • 2017-09-27
      • 1970-01-01
      • 2019-11-06
      • 2016-06-03
      • 1970-01-01
      • 2018-03-19
      相关资源
      最近更新 更多