Skip to content

Commit 4ef38ae

Browse files
authored
Don't send request headers & body to jwks uri (#8119)
1 parent f4f9441 commit 4ef38ae

File tree

2 files changed

+10
-0
lines changed

2 files changed

+10
-0
lines changed

internal/configs/version2/__snapshots__/templates_test.snap

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1117,6 +1117,8 @@ server {
11171117
proxy_cache_valid 200 12h;
11181118
proxy_ssl_server_name on;
11191119
proxy_ssl_name sni.idp.spec.example.com;
1120+
proxy_pass_request_headers off;
1121+
proxy_pass_request_body off;
11201122
proxy_set_header Host idp.spec.example.com;
11211123
set $idp_backend idp.spec.example.com;
11221124
proxy_pass https://$idp_backend:443/spec-keys;
@@ -1129,6 +1131,8 @@ server {
11291131
proxy_cache_valid 200 12h;
11301132
proxy_ssl_server_name on;
11311133
proxy_ssl_name sni.idp.spec.example.com;
1134+
proxy_pass_request_headers off;
1135+
proxy_pass_request_body off;
11321136
proxy_set_header Host idp.route.example.com;
11331137
set $idp_backend idp.route.example.com;
11341138
proxy_pass http://$idp_backend:80/route-keys;
@@ -1239,6 +1243,8 @@ server {
12391243
proxy_set_header Content-Length "";
12401244
proxy_cache jwks_uri_cafe;
12411245
proxy_cache_valid 200 12h;
1246+
proxy_pass_request_headers off;
1247+
proxy_pass_request_body off;
12421248
proxy_set_header Host idp.spec.example.com;
12431249
set $idp_backend idp.spec.example.com;
12441250
proxy_pass https://$idp_backend:443/spec-keys;
@@ -1249,6 +1255,8 @@ server {
12491255
proxy_set_header Content-Length "";
12501256
proxy_cache jwks_uri_cafe;
12511257
proxy_cache_valid 200 12h;
1258+
proxy_pass_request_headers off;
1259+
proxy_pass_request_body off;
12521260
proxy_set_header Host idp.route.example.com;
12531261
set $idp_backend idp.route.example.com;
12541262
proxy_pass http://$idp_backend:80/route-keys;

internal/configs/version2/nginx-plus.virtualserver.tmpl

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -243,6 +243,8 @@ server {
243243
proxy_ssl_name {{ .JwksSNIName }};
244244
{{- end }}
245245
{{- end }}
246+
proxy_pass_request_headers off;
247+
proxy_pass_request_body off;
246248
proxy_set_header Host {{ .JwksHost }};
247249
set $idp_backend {{ .JwksHost }};
248250
proxy_pass {{ .JwksScheme}}://$idp_backend{{ if .JwksPort }}:{{ .JwksPort }}{{ end }}{{ .JwksPath }};

0 commit comments

Comments
 (0)