mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-04 07:33:44 +09:00
fix(git)!: use internal proxy for all git operations (#39426)
Introduces gitproxy module which spawns a small forward proxy as scanner for git calls Replaces hostmatcher with matchlist which supports port rules Deprecates ALLOWED_DOMAINS/BLOCKED_DOMAINS and ALLOW_LOCALNETWORKS settings in migration in favor of full names we have in security configs. Removes `external` preset in favor of lax/strict modes, strict mode requiring explicit ports if they aren't standard http/s ones. Breaking changes: - `external` preset no longer works as deny rule. To enforce that, use `strict` mode and allow ranges to connect to - Wildcards are no longer accepted in IP addresses - `*` is no longer allowed as entry in lists - domain rules now use curl like syntax `*.example.com` matching subdomains but not `example.com`, `example.com` matching itself and all subdomains. `example.*` is not a valid rule - In the default `lax` mode, `[security] ALLOWED_HOST_LIST` no longer restricts public hosts, set `EGRESS_MODE = strict` to keep an exclusive list. A startup warning flags this - Invalid list entries are logged at startup, invalid `BLOCKED_HOST_LIST`/`BLOCKED_DOMAINS` entries stop it Docs: https://gitea.com/gitea/docs/pulls/557 Signed-off-by: wxiaoguang <wxiaoguang@gmail.com> Co-authored-by: silverwind <me@silverwind.io> Co-authored-by: bircni <bircni@icloud.com> Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
+38
-20
@@ -534,13 +534,29 @@ INTERNAL_TOKEN =
|
||||
;; The value of the general Content-Security-Policy for most web pages.
|
||||
;; Leave it empty to apply the default policy, or set it to "unset" to disable Content-Security-Policy.
|
||||
;CONTENT_SECURITY_POLICY_GENERAL =
|
||||
|
||||
;; Webhook and oauth2 clients can only call allowed hosts for security reasons. Comma separated list, eg: external, 192.168.1.0/24, *.mydomain.com
|
||||
;; Built-in: loopback (for localhost), private (for LAN/intranet), external (for public hosts on internet), * (for all hosts)
|
||||
;; CIDR list: 1.2.3.0/8, 2001:db8::/32
|
||||
;; Wildcard hosts: *.mydomain.com, 192.168.100.*
|
||||
;;
|
||||
;; Egress mode toggles between strictness of outgoing requests:
|
||||
;; Lax requires addresses to be allowed only if they are in private ranges, it allows all public ones
|
||||
;; Strict requires an explicit allow of all addresses
|
||||
; EGRESS_MODE = lax
|
||||
;;
|
||||
;; Webhook and oauth2 clients can only call allowed hosts for security reasons. Comma separated list, eg: 192.168.1.0/24:3000, [2001:db8::/32]:9090, *.mydomain.com:[80|443]
|
||||
;; Built-in: loopback (for localhost), private (for LAN/intranet and CGNAT)
|
||||
;; CIDR list: 1.2.3.0/8, 2001:db8::/32, and with a port [2001:db8::/32]:9090 (IPv6 addresses and CIDRs need brackets when a port is given)
|
||||
;; Host matching: "example.com" matches the host and any subdomain, dot-anchored so "notexample.com" never matches;
|
||||
;; "*.example.com" and ".example.com" match only subdomains, the apex itself is excluded. IDN names must be given as punycode.
|
||||
;; All addresses can have ports specified. Accepted port specs:
|
||||
;; a single port: 192.168.1.0/24:3000
|
||||
;; a range, both bounds inclusive: *.mydomain.com:3000-3010
|
||||
;; a bracketed set of ports and ranges, | separated: *.mydomain.com:[80|443|3000-3010]
|
||||
;; all ports: *.mydomain.com:*
|
||||
;; A portless entry covers all ports in Lax mode, only 80 and 443 in Strict mode
|
||||
;; Port specs apply only where the list is consulted: in Lax mode that is private, loopback and CGNAT
|
||||
;; targets alone, public targets are allowed on every port whatever the list says. In Strict mode every
|
||||
;; target is checked, so ports restrict public hosts too.
|
||||
;; Reserved addresses like link-local and cloud metadata are denied
|
||||
;; This list is enforced on direct connections only. When an HTTP proxy is configured, restricting the proxied target is the proxy server's responsibility.
|
||||
;ALLOWED_HOST_LIST = external
|
||||
;ALLOWED_HOST_LIST =
|
||||
|
||||
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
|
||||
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
|
||||
@@ -1808,11 +1824,13 @@ LEVEL = Info
|
||||
;; Number of history information in each page
|
||||
;PAGING_NUM = 10
|
||||
;;
|
||||
;; Proxy server URL, support http://, https//, socks://, blank will follow environment http_proxy/https_proxy
|
||||
;; Proxy server URL, support http://, https://, socks5://, blank will follow environment http_proxy/https_proxy
|
||||
;PROXY_URL =
|
||||
;;
|
||||
;; Comma separated list of host names requiring proxy. Glob patterns (*) are accepted; use ** to match all hosts.
|
||||
;PROXY_HOSTS =
|
||||
;; When a proxy is configured, Gitea does not enforce [security] ALLOWED_HOST_LIST on the proxied
|
||||
;; target, the proxy server is expected to restrict it
|
||||
|
||||
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
|
||||
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
|
||||
@@ -2795,20 +2813,17 @@ LEVEL = Info
|
||||
;; Backoff time per http/https request retry (seconds)
|
||||
;RETRY_BACKOFF = 3
|
||||
;;
|
||||
;; Allowed domains for migrating, default is blank. Blank means everything will be allowed.
|
||||
;; Multiple domains could be separated by commas.
|
||||
;; Wildcard is supported: "github.com, *.github.com"
|
||||
;ALLOWED_DOMAINS =
|
||||
;; Mode toggles between strictness of scanning outgoing requests, same format as [security] EGRESS_MODE
|
||||
; EGRESS_MODE = lax
|
||||
;;
|
||||
;; Blocklist for migrating, default is blank. Multiple domains could be separated by commas.
|
||||
;; When ALLOWED_DOMAINS is not blank, this option has a higher priority to deny domains.
|
||||
;; Wildcard is supported.
|
||||
;BLOCKED_DOMAINS =
|
||||
;; Hosts migrations and mirrors may call, same format as [security] ALLOWED_HOST_LIST. Private and loopback addresses need a builtin or CIDR entry.
|
||||
;ALLOWED_HOST_LIST =
|
||||
;;
|
||||
;; Allow private addresses defined by RFC 1918, RFC 1122, RFC 4632 and RFC 4291 (false by default)
|
||||
;; When false, migration URLs are rejected if any resolved address is private or loopback,
|
||||
;; even when the host matches ALLOWED_DOMAINS: the block list is applied before the allow list.
|
||||
;ALLOW_LOCALNETWORKS = false
|
||||
;; Hosts migrations and mirrors may never call, portless entries defaults to all ports blocked
|
||||
;BLOCKED_HOST_LIST =
|
||||
;;
|
||||
;; These lists are enforced on direct connections only. When a proxy is configured
|
||||
;; ([proxy], [git.config] http.proxy or the environment), restricting the proxied target is the proxy server's responsibility.
|
||||
|
||||
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
|
||||
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
|
||||
@@ -3041,10 +3056,13 @@ LEVEL = Info
|
||||
;[proxy]
|
||||
;; Enable the proxy, all requests to external via HTTP will be affected
|
||||
;PROXY_ENABLED = false
|
||||
;; Proxy server URL, support http://, https//, socks://, blank will follow environment http_proxy/https_proxy/no_proxy
|
||||
;; Proxy server URL, support http://, https://, socks5://, blank will follow environment http_proxy/https_proxy/no_proxy
|
||||
;PROXY_URL =
|
||||
;; Comma separated list of host names requiring proxy. Glob patterns (*) are accepted; use ** to match all hosts.
|
||||
;PROXY_HOSTS =
|
||||
;; Git remotes prefer [git.config] http.proxy and use the environment's proxy even when PROXY_ENABLED is false
|
||||
;; When a proxy is configured, Gitea does not enforce the egress lists ([security], [migrations]) on the proxied
|
||||
;; target, the proxy server is expected to restrict it
|
||||
|
||||
; [actions]
|
||||
;; Enable/Disable actions capabilities
|
||||
|
||||
Reference in New Issue
Block a user