diff options
author | Alex W <embezzle.dev@proton.me> | 2024-05-21 23:25:06 +0100 |
---|---|---|
committer | Alex W <embezzle.dev@proton.me> | 2024-05-21 23:25:06 +0100 |
commit | e1450096b4c667a4c33a3fcd8f67ebf6a39d441d (patch) | |
tree | 5c503636e7e8a31176341f560dfdff9a17734b8e /src/conf_mode | |
parent | bc345404b411ac066383e796936de704078787b2 (diff) | |
download | vyos-1x-e1450096b4c667a4c33a3fcd8f67ebf6a39d441d.tar.gz vyos-1x-e1450096b4c667a4c33a3fcd8f67ebf6a39d441d.zip |
reverse-proxy: T6370: Set custom HTTP headers in reverse-proxy responses
Diffstat (limited to 'src/conf_mode')
-rwxr-xr-x | src/conf_mode/load-balancing_reverse-proxy.py | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/src/conf_mode/load-balancing_reverse-proxy.py b/src/conf_mode/load-balancing_reverse-proxy.py index 1569d8d71..a4efb1cd8 100755 --- a/src/conf_mode/load-balancing_reverse-proxy.py +++ b/src/conf_mode/load-balancing_reverse-proxy.py @@ -88,6 +88,12 @@ def verify(lb): if {'send_proxy', 'send_proxy_v2'} <= set(bk_server_conf): raise ConfigError(f'Cannot use both "send-proxy" and "send-proxy-v2" for server "{bk_server}"') + # Check if http-response-headers are configured in any frontend/backend where mode != http + for group in ['service', 'backend']: + for config_name, config in lb[group].items(): + if 'http_response_headers' in config and ('mode' not in config or config['mode'] != 'http'): + raise ConfigError(f'{group} {config_name} must be set to http mode to use http_response_headers!') + if 'ssl' in back_config: if {'no_verify', 'ca_certificate'} <= set(back_config['ssl']): raise ConfigError(f'backend {back} cannot have both ssl options no-verify and ca-certificate set!') |