pass only the request path in X-Original-URL (#24602)

nginx built X-Original-URL from the client's Host header plus the request path, so a Host containing '#' or '?' pushed the real path into the URL fragment or query. The media and go2rtc auth checks then saw an empty path and allowed restricted-role users to read other cameras' clips, recordings, exports and live streams. The header now carries only $request_uri, which is all the auth checks need.
This commit is contained in:
Josh Hawkins
2026-10-09 07:44:53 -05:00
committed by GitHub
parent 2273cf2d50
commit 33cb8d987d
2 changed files with 2 additions and 2 deletions
@@ -14,7 +14,7 @@ location /auth {
proxy_pass_request_headers off;
# Pass info about the request
proxy_set_header X-Original-Method $request_method;
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
proxy_set_header X-Original-URL $request_uri;
proxy_set_header X-Server-Port $server_port;
proxy_set_header Content-Length "";
# Pass along auth related info
@@ -2,7 +2,7 @@
proxy_set_header Host $host;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "Upgrade";
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
proxy_set_header X-Original-URL $request_uri;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-URI $request_uri;