fix(git)!: use internal proxy for all git operations (#39426)

Introduces gitproxy module which spawns a small forward proxy as scanner
for git calls
Replaces hostmatcher with matchlist which supports port rules
Deprecates ALLOWED_DOMAINS/BLOCKED_DOMAINS and ALLOW_LOCALNETWORKS
settings in migration in favor of full names we have in security
configs.
Removes `external` preset in favor of lax/strict modes, strict mode
requiring explicit ports if they aren't standard http/s ones.

Breaking changes:
- `external` preset no longer works as deny rule. To enforce that, use
`strict` mode and allow ranges to connect to
- Wildcards are no longer accepted in IP addresses
- `*` is no longer allowed as entry in lists
- domain rules now use curl like syntax `*.example.com` matching
subdomains but not `example.com`, `example.com` matching itself and all
subdomains. `example.*` is not a valid rule
- In the default `lax` mode, `[security] ALLOWED_HOST_LIST` no longer
restricts public hosts, set `EGRESS_MODE = strict` to keep an exclusive
list. A startup warning flags this
- Invalid list entries are logged at startup, invalid
`BLOCKED_HOST_LIST`/`BLOCKED_DOMAINS` entries stop it

Docs: https://gitea.com/gitea/docs/pulls/557
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: bircni <bircni@icloud.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
TheFox0x7
2026-09-29 14:43:36 +02:00
committed by GitHub
parent ebcb0150d1
commit 1b1274486c
57 changed files with 2356 additions and 1106 deletions
+38 -20
View File
@@ -534,13 +534,29 @@ INTERNAL_TOKEN =
;; The value of the general Content-Security-Policy for most web pages.
;; Leave it empty to apply the default policy, or set it to "unset" to disable Content-Security-Policy.
;CONTENT_SECURITY_POLICY_GENERAL =
;; Webhook and oauth2 clients can only call allowed hosts for security reasons. Comma separated list, eg: external, 192.168.1.0/24, *.mydomain.com
;; Built-in: loopback (for localhost), private (for LAN/intranet), external (for public hosts on internet), * (for all hosts)
;; CIDR list: 1.2.3.0/8, 2001:db8::/32
;; Wildcard hosts: *.mydomain.com, 192.168.100.*
;;
;; Egress mode toggles between strictness of outgoing requests:
;; Lax requires addresses to be allowed only if they are in private ranges, it allows all public ones
;; Strict requires an explicit allow of all addresses
; EGRESS_MODE = lax
;;
;; Webhook and oauth2 clients can only call allowed hosts for security reasons. Comma separated list, eg: 192.168.1.0/24:3000, [2001:db8::/32]:9090, *.mydomain.com:[80|443]
;; Built-in: loopback (for localhost), private (for LAN/intranet and CGNAT)
;; CIDR list: 1.2.3.0/8, 2001:db8::/32, and with a port [2001:db8::/32]:9090 (IPv6 addresses and CIDRs need brackets when a port is given)
;; Host matching: "example.com" matches the host and any subdomain, dot-anchored so "notexample.com" never matches;
;; "*.example.com" and ".example.com" match only subdomains, the apex itself is excluded. IDN names must be given as punycode.
;; All addresses can have ports specified. Accepted port specs:
;; a single port: 192.168.1.0/24:3000
;; a range, both bounds inclusive: *.mydomain.com:3000-3010
;; a bracketed set of ports and ranges, | separated: *.mydomain.com:[80|443|3000-3010]
;; all ports: *.mydomain.com:*
;; A portless entry covers all ports in Lax mode, only 80 and 443 in Strict mode
;; Port specs apply only where the list is consulted: in Lax mode that is private, loopback and CGNAT
;; targets alone, public targets are allowed on every port whatever the list says. In Strict mode every
;; target is checked, so ports restrict public hosts too.
;; Reserved addresses like link-local and cloud metadata are denied
;; This list is enforced on direct connections only. When an HTTP proxy is configured, restricting the proxied target is the proxy server's responsibility.
;ALLOWED_HOST_LIST = external
;ALLOWED_HOST_LIST =
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
@@ -1808,11 +1824,13 @@ LEVEL = Info
;; Number of history information in each page
;PAGING_NUM = 10
;;
;; Proxy server URL, support http://, https//, socks://, blank will follow environment http_proxy/https_proxy
;; Proxy server URL, support http://, https://, socks5://, blank will follow environment http_proxy/https_proxy
;PROXY_URL =
;;
;; Comma separated list of host names requiring proxy. Glob patterns (*) are accepted; use ** to match all hosts.
;PROXY_HOSTS =
;; When a proxy is configured, Gitea does not enforce [security] ALLOWED_HOST_LIST on the proxied
;; target, the proxy server is expected to restrict it
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
@@ -2795,20 +2813,17 @@ LEVEL = Info
;; Backoff time per http/https request retry (seconds)
;RETRY_BACKOFF = 3
;;
;; Allowed domains for migrating, default is blank. Blank means everything will be allowed.
;; Multiple domains could be separated by commas.
;; Wildcard is supported: "github.com, *.github.com"
;ALLOWED_DOMAINS =
;; Mode toggles between strictness of scanning outgoing requests, same format as [security] EGRESS_MODE
; EGRESS_MODE = lax
;;
;; Blocklist for migrating, default is blank. Multiple domains could be separated by commas.
;; When ALLOWED_DOMAINS is not blank, this option has a higher priority to deny domains.
;; Wildcard is supported.
;BLOCKED_DOMAINS =
;; Hosts migrations and mirrors may call, same format as [security] ALLOWED_HOST_LIST. Private and loopback addresses need a builtin or CIDR entry.
;ALLOWED_HOST_LIST =
;;
;; Allow private addresses defined by RFC 1918, RFC 1122, RFC 4632 and RFC 4291 (false by default)
;; When false, migration URLs are rejected if any resolved address is private or loopback,
;; even when the host matches ALLOWED_DOMAINS: the block list is applied before the allow list.
;ALLOW_LOCALNETWORKS = false
;; Hosts migrations and mirrors may never call, portless entries defaults to all ports blocked
;BLOCKED_HOST_LIST =
;;
;; These lists are enforced on direct connections only. When a proxy is configured
;; ([proxy], [git.config] http.proxy or the environment), restricting the proxied target is the proxy server's responsibility.
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
@@ -3041,10 +3056,13 @@ LEVEL = Info
;[proxy]
;; Enable the proxy, all requests to external via HTTP will be affected
;PROXY_ENABLED = false
;; Proxy server URL, support http://, https//, socks://, blank will follow environment http_proxy/https_proxy/no_proxy
;; Proxy server URL, support http://, https://, socks5://, blank will follow environment http_proxy/https_proxy/no_proxy
;PROXY_URL =
;; Comma separated list of host names requiring proxy. Glob patterns (*) are accepted; use ** to match all hosts.
;PROXY_HOSTS =
;; Git remotes prefer [git.config] http.proxy and use the environment's proxy even when PROXY_ENABLED is false
;; When a proxy is configured, Gitea does not enforce the egress lists ([security], [migrations]) on the proxied
;; target, the proxy server is expected to restrict it
; [actions]
;; Enable/Disable actions capabilities