no-mistakes(review): harden dsh token capture: loopback bind, atomic nginx config
This commit is contained in:
@@ -292,9 +292,14 @@ The script:
|
||||
ssh root@192.168.68.15 "pct exec 112 -- curl -s -o /dev/null -w '%{http_code}' http://127.0.0.1:8081/dsh-web-login"
|
||||
# Expected: 303
|
||||
|
||||
# Check if the cookie works:
|
||||
ssh root@192.168.68.15 "pct exec 112 -- curl -s -o /dev/null -w '%{http_code}' -b 'dsh-auth-*' http://127.0.0.1:3080/"
|
||||
# Expected: 200 (after the cookie has been set)
|
||||
# Mint the 30-day cookie from the login endpoint:
|
||||
ssh root@192.168.68.15 "pct exec 112 -- rm -f /tmp/dsh.jar"
|
||||
ssh root@192.168.68.15 "pct exec 112 -- curl -s -c /tmp/dsh.jar -o /dev/null -w '%{http_code}' http://127.0.0.1:8081/dsh-web-login"
|
||||
# Expected: 303
|
||||
|
||||
# Check if the stored cookie authenticates against dsh-web:
|
||||
ssh root@192.168.68.15 "pct exec 112 -- curl -s -b /tmp/dsh.jar -o /dev/null -w '%{http_code}' http://127.0.0.1:3080/"
|
||||
# Expected: 200
|
||||
```
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user