@cryptotaxi247 / netdata-1 / commits / 68e5ce8f9

Bug fix for netdata behind authenticated proxies (#5216)

* Was incorrectly updating the headers when the Authorization header was being sent * Use X-Auth-Token instead of Authorization header, to allow the management API to work authenticated behind proxies as well

Chris Akritidis committed Jan 18, 2019 at 23:06 UTC 68e5ce8f9a70ceaee9dbe2527ff59bef06786f10
3 files changed +9 -16
tests/health_mgmtapi/health-cmdapi-test.sh.in
+1 -1
@@ -41,7 +41,7 @@ check () {
41
42 cmd () {
43 echo -e "${WHITE}Cmd '${1}', expecting '${2}'"
44 - RESPONSE=$(curl -s "http://$URL/api/v1/manage/health?${1}" -H "Authorization: Bearer $TOKEN" 2>&1)
44 + RESPONSE=$(curl -s "http://$URL/api/v1/manage/health?${1}" -H "X-Auth-Token: $TOKEN" 2>&1)
45 if [ "${RESPONSE}" != "${2}" ] ; then
46 echo -e "${RED}ERROR: Response '${RESPONSE}' != '${2}'"
47 err=$((err+1))
web/api/health/README.md
+5 -5
@@ -61,7 +61,7 @@ The API is available by default, but it is protected by an `api authorization to
61 You can access the API via GET requests, by adding the bearer token to an `Authorization` http header, like this:
62
63 ```
64 -curl "http://myserver/api/v1/manage/health?cmd=RESET" -H "Authorization: Bearer Mytoken"
64 +curl "http://myserver/api/v1/manage/health?cmd=RESET" -H "X-Auth-Token: Mytoken"
65 ```
66
67 The command `RESET` just returns netdata to the default operation, with all health checks and notifications enabled.
@@ -71,13 +71,13 @@ If you've configured and entered your token correclty, you should see the plain
71
72 If all you need is temporarily disable all health checks, then you issue the following before your maintenance period starts:
73 ```
74 -curl "http://myserver/api/v1/manage/health?cmd=DISABLE ALL" -H "Authorization: Bearer Mytoken"
74 +curl "http://myserver/api/v1/manage/health?cmd=DISABLE ALL" -H "X-Auth-Token: Mytoken"
75 ```
76 The effect of disabling health checks is that the alarm criteria are not evaluated at all and nothing is written in the alarm log.
77 If you want the health checks to be running but to not receive any notifications during your maintenance period, you can instead use this:
78
79 ```
80 -curl "http://myserver/api/v1/manage/health?cmd=SILENCE ALL" -H "Authorization: Bearer Mytoken"
80 +curl "http://myserver/api/v1/manage/health?cmd=SILENCE ALL" -H "X-Auth-Token: Mytoken"
81 ```
82
83 Alarms may then still be raised and logged in netdata, so you'll be able to see them via the UI.
@@ -85,7 +85,7 @@ Alarms may then still be raised and logged in netdata, so you'll be able to see
85 Regardless of the option you choose, at the end of your maintenance period you revert to the normal state via the RESET command.
86
87 ```
88 - curl "http://myserver/api/v1/manage/health?cmd=RESET" -H "Authorization: Bearer Mytoken"
88 + curl "http://myserver/api/v1/manage/health?cmd=RESET" -H "X-Auth-Token: Mytoken"
89 ```
90
91 ### Disable or silence specific alarms
@@ -108,7 +108,7 @@ To clear all selectors and reset the mode to default, use the `RESET` command.
108 The following example silences notifications for all the alarms with context=load:
109
110 ```
111 -curl "http://myserver/api/v1/manage/health?cmd=SILENCE&context=load" -H "Authorization: Bearer Mytoken"
111 +curl "http://myserver/api/v1/manage/health?cmd=SILENCE&context=load" -H "X-Auth-Token: Mytoken"
112 ```
113
114 #### Selection criteria
web/server/web_client.c
+3 -10
@@ -732,7 +732,7 @@ static inline char *http_header_parse(struct web_client *w, char *s, int parse_u
732 hash_accept_encoding = simple_uhash("Accept-Encoding");
733 hash_donottrack = simple_uhash("DNT");
734 hash_useragent = simple_uhash("User-Agent");
735 - hash_authorization = simple_uhash("Authorization");
735 + hash_authorization = simple_uhash("X-Auth-Token");
736 }
737
738 char *e = s;
@@ -777,15 +777,8 @@ static inline char *http_header_parse(struct web_client *w, char *s, int parse_u
777 }
778 else if(parse_useragent && hash == hash_useragent && !strcasecmp(s, "User-Agent")) {
779 w->user_agent = strdupz(v);
780 - } else if(hash == hash_authorization&& !strcasecmp(s, "Authorization")) {
781 - if (strlen(v) > 8) { // Must contain at least "Bearer "
782 - char *auth_key=v+6;
783 - *auth_key='\0';
784 - if (!strcasecmp(v,"Bearer")) {
785 - auth_key++;
786 - w->auth_bearer_token=strdupz(auth_key);
787 - }
788 - }
780 + } else if(hash == hash_authorization&& !strcasecmp(s, "X-Auth-Token")) {
781 + w->auth_bearer_token = strdupz(v);
782 }
783 #ifdef NETDATA_WITH_ZLIB
784 else if(hash == hash_accept_encoding && !strcasecmp(s, "Accept-Encoding")) {