mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: stop redirecting DERP and replicasync http requests (#10752)
Fixes an issue where setting CODER_REDIRECT_TO_ACCESS_URL breaks use of multiple Coder server replicas for DERP traffic.
This commit is contained in:
@@ -1922,6 +1922,18 @@ func redirectToAccessURL(handler http.Handler, accessURL *url.URL, tunnel bool,
|
||||
http.Redirect(w, r, accessURL.String(), http.StatusTemporaryRedirect)
|
||||
}
|
||||
|
||||
// Exception: DERP
|
||||
// We use this endpoint when creating a DERP-mesh in the enterprise version to directly
|
||||
// dial other Coderd derpers. Redirecting to the access URL breaks direct dial since the
|
||||
// access URL will be load-balanced in a multi-replica deployment.
|
||||
//
|
||||
// It's totally fine to access DERP over TLS, but we also don't need to redirect HTTP to
|
||||
// HTTPS as DERP is itself an encrypted protocol.
|
||||
if isDERPPath(r.URL.Path) {
|
||||
handler.ServeHTTP(w, r)
|
||||
return
|
||||
}
|
||||
|
||||
// Only do this if we aren't tunneling.
|
||||
// If we are tunneling, we want to allow the request to go through
|
||||
// because the tunnel doesn't proxy with TLS.
|
||||
@@ -1949,6 +1961,14 @@ func redirectToAccessURL(handler http.Handler, accessURL *url.URL, tunnel bool,
|
||||
})
|
||||
}
|
||||
|
||||
func isDERPPath(p string) bool {
|
||||
segments := strings.SplitN(p, "/", 3)
|
||||
if len(segments) < 2 {
|
||||
return false
|
||||
}
|
||||
return segments[1] == "derp"
|
||||
}
|
||||
|
||||
// IsLocalhost returns true if the host points to the local machine. Intended to
|
||||
// be called with `u.Hostname()`.
|
||||
func IsLocalhost(host string) bool {
|
||||
|
||||
Reference in New Issue
Block a user