A route may have its own listener: every request there is that route, paths unprefixed
Implemented-By: OpenCode session (model recorded in docs/implementer-log.md)
This commit is contained in:
@@ -45,6 +45,21 @@ func Middleware(c *Checker, peersFor func(route string) ([]string, bool), next h
|
||||
})
|
||||
}
|
||||
|
||||
// RouteMiddleware gates every request on a fixed set of peers, whatever path or X-Crossbar-Route
|
||||
// header it carries: on a route's dedicated listener the route is fixed, so the gate is that route's
|
||||
// peers for every request. There is no admin-path exemption — there is no admin on a route listener.
|
||||
// Empty peers lets everyone through, as for Middleware.
|
||||
func RouteMiddleware(c *Checker, peers []string, next http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
ctx := WithHeaderPeer(r.Context(), r.Header.Get(peerHeader))
|
||||
if err := c.Allow(ctx, peers, r.RemoteAddr); err != nil {
|
||||
writeForbidden(w)
|
||||
return
|
||||
}
|
||||
next.ServeHTTP(w, r)
|
||||
})
|
||||
}
|
||||
|
||||
// writeForbidden answers the JSON 403 the tests and callers expect.
|
||||
func writeForbidden(w http.ResponseWriter) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
|
||||
Reference in New Issue
Block a user