Support allowed hosts for webhook to work with proxy (#27655) #27674
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Backport #27655 by @wolfogre
When
webhook.PROXY_URL
has been set, the old code will check if the proxy host is inALLOWED_HOST_LIST
or reject requests through the proxy. It requires users to add the proxy host toALLOWED_HOST_LIST
. However, it actually allows all requests to any port on the host, when the proxy host is probably an internal address.But things may be even worse.
ALLOWED_HOST_LIST
doesn't really work when requests are sent to the allowed proxy, and the proxy could forward them to any hosts.This PR fixes it by:
ALLOWED_HOST_LIST
before forwarding.