|
| 1 | +// Copyright 2024 The Gitea Authors. All rights reserved. |
| 2 | +// SPDX-License-Identifier: MIT |
| 3 | + |
| 4 | +package setting |
| 5 | + |
| 6 | +var ReverseProxyAuth = struct { |
| 7 | + Enabled bool |
| 8 | + EnableReverseProxyAuthAPI bool |
| 9 | + EnableReverseProxyAutoRegister bool |
| 10 | + EnableReverseProxyEmail bool |
| 11 | + EnableReverseProxyFullName bool |
| 12 | + ReverseProxyAuthUser string |
| 13 | + ReverseProxyAuthEmail string |
| 14 | + ReverseProxyAuthFullName string |
| 15 | + ReverseProxyLimit int |
| 16 | + ReverseProxyTrustedProxies []string |
| 17 | +}{} |
| 18 | + |
| 19 | +func loadReverseProxyAuthFrom(rootCfg ConfigProvider) error { |
| 20 | + serviceSec := rootCfg.Section("service") |
| 21 | + |
| 22 | + ReverseProxyAuth.Enabled = serviceSec.Key("ENABLE_REVERSE_PROXY_AUTHENTICATION").MustBool() |
| 23 | + ReverseProxyAuth.EnableReverseProxyAuthAPI = serviceSec.Key("ENABLE_REVERSE_PROXY_AUTHENTICATION_API").MustBool() |
| 24 | + ReverseProxyAuth.EnableReverseProxyAutoRegister = serviceSec.Key("ENABLE_REVERSE_PROXY_AUTO_REGISTRATION").MustBool() |
| 25 | + ReverseProxyAuth.EnableReverseProxyEmail = serviceSec.Key("ENABLE_REVERSE_PROXY_EMAIL").MustBool() |
| 26 | + ReverseProxyAuth.EnableReverseProxyFullName = serviceSec.Key("ENABLE_REVERSE_PROXY_FULL_NAME").MustBool() |
| 27 | + |
| 28 | + securitySec := rootCfg.Section("security") |
| 29 | + ReverseProxyAuth.ReverseProxyAuthUser = securitySec.Key("REVERSE_PROXY_AUTHENTICATION_USER").MustString("X-WEBAUTH-USER") |
| 30 | + ReverseProxyAuth.ReverseProxyAuthEmail = securitySec.Key("REVERSE_PROXY_AUTHENTICATION_EMAIL").MustString("X-WEBAUTH-EMAIL") |
| 31 | + ReverseProxyAuth.ReverseProxyAuthFullName = securitySec.Key("REVERSE_PROXY_AUTHENTICATION_FULL_NAME").MustString("X-WEBAUTH-FULLNAME") |
| 32 | + |
| 33 | + ReverseProxyAuth.ReverseProxyLimit = securitySec.Key("REVERSE_PROXY_LIMIT").MustInt(1) |
| 34 | + ReverseProxyAuth.ReverseProxyTrustedProxies = securitySec.Key("REVERSE_PROXY_TRUSTED_PROXIES").Strings(",") |
| 35 | + if len(ReverseProxyAuth.ReverseProxyTrustedProxies) == 0 { |
| 36 | + ReverseProxyAuth.ReverseProxyTrustedProxies = []string{"127.0.0.0/8", "::1/128"} |
| 37 | + } |
| 38 | + |
| 39 | + return nil |
| 40 | +} |
0 commit comments