0
0
Fork 0
mirror of https://github.com/go-gitea/gitea synced 2024-12-23 10:44:44 +01:00
gitea/services/webhook
Jason Song 4e98224a45
Support allowed hosts for webhook to work with proxy (#27655)
When `webhook.PROXY_URL` has been set, the old code will check if the
proxy host is in `ALLOWED_HOST_LIST` or reject requests through the
proxy. It requires users to add the proxy host to `ALLOWED_HOST_LIST`.
However, it actually allows all requests to any port on the host, when
the proxy host is probably an internal address.

But things may be even worse. `ALLOWED_HOST_LIST` doesn't really work
when requests are sent to the allowed proxy, and the proxy could forward
them to any hosts.

This PR fixes it by:

- If the proxy has been set, always allow connectioins to the host and
port.
- Check `ALLOWED_HOST_LIST` before forwarding.
2023-10-18 09:44:36 +00:00
..
deliver.go Support allowed hosts for webhook to work with proxy (#27655) 2023-10-18 09:44:36 +00:00
deliver_test.go Support allowed hosts for webhook to work with proxy (#27655) 2023-10-18 09:44:36 +00:00
dingtalk.go Fix release URL in webhooks (#27182) 2023-09-21 17:55:09 -05:00
dingtalk_test.go Fix release URL in webhooks (#27182) 2023-09-21 17:55:09 -05:00
discord.go Fix release URL in webhooks (#27182) 2023-09-21 17:55:09 -05:00
discord_test.go Fix release URL in webhooks (#27182) 2023-09-21 17:55:09 -05:00
feishu.go Modify the content format of the Feishu webhook (#25106) 2023-08-24 09:00:11 +08:00
feishu_test.go Modify the content format of the Feishu webhook (#25106) 2023-08-24 09:00:11 +08:00
general.go Modify the content format of the Feishu webhook (#25106) 2023-08-24 09:00:11 +08:00
general_test.go Fix release URL in webhooks (#27182) 2023-09-21 17:55:09 -05:00
main_test.go make writing main test easier (#27270) 2023-09-28 01:38:53 +00:00
matrix.go Fix release URL in webhooks (#27182) 2023-09-21 17:55:09 -05:00
matrix_test.go
msteams.go Fix release URL in webhooks (#27182) 2023-09-21 17:55:09 -05:00
msteams_test.go Fix release URL in webhooks (#27182) 2023-09-21 17:55:09 -05:00
notifier.go Move notification interface to services layer (#26915) 2023-09-05 18:37:47 +00:00
packagist.go
packagist_test.go
payloader.go
slack.go Fix release URL in webhooks (#27182) 2023-09-21 17:55:09 -05:00
slack_test.go
telegram.go Add ThreadID parameter for Telegram webhooks (#25996) 2023-08-13 14:00:06 +00:00
telegram_test.go
webhook.go Warn instead of reporting an error when a webhook cannot be found (#26039) 2023-07-28 17:46:48 +00:00
webhook_test.go
wechatwork.go Use the type RefName for all the needed places and fix pull mirror sync bugs (#24634) 2023-05-26 01:04:48 +00:00