no-mistakes(review): harden dsh token capture: loopback bind, atomic nginx config

This commit is contained in:
2026-09-11 15:22:41 +00:00
parent b2a259fa23
commit 85ea1f4f3d
2 changed files with 54 additions and 14 deletions
+8 -3
View File
@@ -292,9 +292,14 @@ The script:
ssh root@192.168.68.15 "pct exec 112 -- curl -s -o /dev/null -w '%{http_code}' http://127.0.0.1:8081/dsh-web-login"
# Expected: 303
# Check if the cookie works:
ssh root@192.168.68.15 "pct exec 112 -- curl -s -o /dev/null -w '%{http_code}' -b 'dsh-auth-*' http://127.0.0.1:3080/"
# Expected: 200 (after the cookie has been set)
# Mint the 30-day cookie from the login endpoint:
ssh root@192.168.68.15 "pct exec 112 -- rm -f /tmp/dsh.jar"
ssh root@192.168.68.15 "pct exec 112 -- curl -s -c /tmp/dsh.jar -o /dev/null -w '%{http_code}' http://127.0.0.1:8081/dsh-web-login"
# Expected: 303
# Check if the stored cookie authenticates against dsh-web:
ssh root@192.168.68.15 "pct exec 112 -- curl -s -b /tmp/dsh.jar -o /dev/null -w '%{http_code}' http://127.0.0.1:3080/"
# Expected: 200
```