pax-web-undertow support for proxy-address-forwarding and checkForwardedHeaders

22 views
Skip to first unread message

Hannes Holtzhausen

unread,
Aug 22, 2019, 2:19:47 AM8/22/19
to OPS4J
Good day

Pax-web-undertow 7.3.3 ignores the proxy-address-forwarding attribute and org.osgi.service.http.checkForwardedHeaders property.

As a result non of the X-Forwarded headers are applied to the http request in scenarios where SSL is offloaded using a load balancer.
This in turn causes the java keycloak adapter to formulate incorrect redirect_uri's and breaks the standard OIDC flow.

We are running pax-web-undertow as part of the Redhat JBoss Fuse 7.4.0 distribution.

I applied a fix to the web-7.3.3 tag and have tested it successfully in our environment. Find attached my changes for possible inclusion in
an upcoming 7.3.x release.

Hannes


Server.diff
ServerControllerImpl.diff

Grzegorz Grzybek

unread,
Aug 22, 2019, 6:21:44 AM8/22/19
to op...@googlegroups.com
Hello

Great and thanks for the patch - I'll take care of it (and of fixing it also in RedHat Fuse 7.5) soon.

regards
Grzegorz Grzybek

--
--
------------------
OPS4J - http://www.ops4j.org - op...@googlegroups.com

---
You received this message because you are subscribed to the Google Groups "OPS4J" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ops4j+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ops4j/f380a9e8-e944-4c4c-b959-a1c43c77f5d1%40googlegroups.com.

Grzegorz Grzybek

unread,
Sep 10, 2019, 4:09:47 AM9/10/19
to op...@googlegroups.com
Hello

I created https://ops4j1.jira.com/browse/PAXWEB-1233 to track this. Should be fixed with pax-web 7.3.4.

regards
Grzegorz Grzybek

czw., 22 sie 2019 o 08:19 Hannes Holtzhausen <hannes.ho...@gmail.com> napisał(a):

Grzegorz Grzybek

unread,
Sep 10, 2019, 4:28:32 AM9/10/19
to op...@googlegroups.com
Thanks Hannes for the patch!


regards
Grzegorz Grzybek

Hannes Holtzhausen

unread,
Sep 10, 2019, 4:43:59 AM9/10/19
to op...@googlegroups.com
Great!  Looking forward to the Redhat Fuse 7.5 updates.


Reply all
Reply to author
Forward
0 new messages