클라이언트 공급 identity headers upstream를 전달하십시오
forward(), forwardWebhook() 및 forwardCallback()는 모든 inbound를 복사했습니다. 호스트를 제외한 헤더 (및, sessionless two, credential headers) 업스트림 요청에. BillingService는 모두 허용되며 Call...
앞으로 캐리어 SMS webhooks, 모든 것에 아무것도 도달
Traefik은 api.kamocrm.com에서 경로 분할없이이 게이트웨이에 모든 경로를 보냅니다. 그리고 이 클래스는 /api/voip/** 그리고 아무것도 다른. · /api/bulktext/inbound/{carrier} — 서면, 테스트 및 VOIPService에 배포 — 인터넷...
앞으로 캐리어 SMS webhooks, 모든 것에 아무것도 도달
Traefik은 api.kamocrm.com에서 경로 분할없이이 게이트웨이에 모든 경로를 보냅니다. 그리고 이 클래스는 /api/voip/** 그리고 아무것도 다른. · /api/bulktext/inbound/{carrier} — 서면, 테스트 및 VOIPService에 배포 — 인터넷...
에 의해 배포 digest, 태그에 의해
Preceding commit stops `set image` 침묵의 no-op. 이 주장 outcome : 롤아웃 후, 태그는 레지스트리에서 소화로 해결됩니다. 실행된 파드는 그것에 대하여 검사됩니다. 팟이 실행되지 않은 경우 생성, 빌드는 성공보고 대신 실패. 태그는 그 질문에 대...
동일한 커밋의 재건은 아무것도 배포하고 성공을보고
이미지는 커밋 SHA로 태그되어 있으므로 동일한 커밋 생성을 재구성합니다. 동일한 이미지 참조. `kubectl set image` 그런 다음 아무것도 변경, 배포는 결코 터치되지 않습니다, `rollout status`는 즉시 성공 OLD pods, 그리고이 파이프라인은 아무것도 배포...
/api/settings forward를 떨어뜨리십시오
EmailService는 sync-integration 컨트롤러를 제공합니다. **************** not /api/settings/integrations — 그래서 앞으로는 서비스 경로에 도달하지 않고 404을 반환합니다. /api/email 와일드 카드는 이미 그것을 운반합...
Route /api/contacts, /api/calendar 및 /api/settings to EmailService
KamoMobile의 접촉 및 달력 스크린 404는 각 요구에 했습니다. 이름 * 경로는 api 호스트에서 경로로, 그래서 아무것도에 도달 EmailService 및 서비스는 모든 것에 아무것도 기록 — 실패는 멀리에서 보이지 않습니다. kamo-internal 결코 이것을 필요로 하...
지금 비용 15s minReadySeconds에 대한 롤아웃 룸 제공
progressDeadlineSeconds는 60이었다. 롤아웃이 진행되기 전에 쿠버네티스는 실패하고, 이전 커밋은 minReadySeconds의 15를 추가했습니다. 이미지 잡아당기기의 정상에 각 롤아웃 및 앱의 자신의 시동. 혼자 추운 잡아 이제 여행 할 수 그리고 작업이 실패. 6...
APIService는 전혀 흠뻑 빠지지 않습니다
Deploys는 요청을 잡기 위해 아무것도와 함께 각 서비스의 유일한 파드를 대체 비행. 함대에 적용된 3개의 조정: - 프로세스가 SIGTERM을 참조하기 전에 10s를 잠그십시오. 쿠버네티스는 팟을 제거한다. EndpointSlice와 같은 순간에 신호, 그리고 Traefik는 제...
한 번에 한 번에 디코딩 토큰을 인코딩
21670e5는 UpstreamUri의 FULLY-PRE-ENCODED 항목을 통해 SocialWebhookController를 routed 점, 그러나 그것의 URL은 잡종입니다: `token`는 @PathVariable입니다, 그래서 봄 손은 getQueryString()이 원합니다...
Public-facing 프록시에서 콜러의 쿼리 바이트를 전달
게이트웨이는 3c24d32의 전달된 쿼리 문자열을 중지하지만 4 이 서비스에 다른 프록시는 여전히 이미 인코딩된 바이트를 concatenated String으로, restTemplate의 String overload로 옮긴다. URI 템플릿으로, 두 번째로 인코딩: %2C는 %252C로...
Caller의 쿼리 바이트 대신 인코딩 두 번
모든 URL이 게이트웨이 빌드는 getRequestURI()에서 조립됩니다. getQueryString() — 이미 퍼센트 인코딩된 모두 — 그리고 그 때에 문자열로 restTemplate. restTemplate의 문자열 과부하는 URL을 가지고 있지 않습니다; 그들은 URI TEMP...
Flaky egress에 대한 kubectl 다운로드를 Harden [skip ci]
dl.k8s.io 런너의 egress 간에 실수로 중간 전송을 삭제: 컬: (56) OpenSSL SSL read: 해독 실패 또는 나쁜 기록 맥 그렇지 않으면 녹색 빌드에 배포되지 않습니다. 반복적으로 관찰 kamo-signer-monorepo 및 카모 번역 사전. 추가 --retr...
1단계 – OriginMatcher opt-in(empty allow-list / 누락된 Origin 허용)
Phase-0 위젯은 서버 측 프록시를 통해 여전히 호출됩니다, 그래서 원래 잠금이 없습니다 아직 혜택과 모든 라이브 공개 채팅 키는 빈 허용 목록이 있습니다. 사이트맵 집행 (empty=deny, missing-Origin=deny) 마케팅 + sign.pink VOIP-recordi...
진정한 잘못된 키 만 캐시가 유효하지 않습니다
추운 Redis 캐시에서 잘못된 /absent Origin의 유효 공개 채팅 키가되었습니다. 60s에 대한 INVALID로 캐시, 그에 대한 올바른 기원의 요청을 거부 창. HTTP 및 WebSocket Cold-cache fallbacks 모두 구별 *********** null 반환...
Bind WS 릴레이 handhake 원산지 + 콜드 캐시 키 검증을 추가
PublicChatController의 프라이빗 validateViaDownstream()을 공유합니다. PublicChatKeyResolver bean 그래서 PublicChatWebSocketHandler 같은 재사용 할 수 있습니다 downstream DB 유효성 검사 + 필수 O...
Carve /api/voip/recordings/** out of the wildcard VOIP forwarder
The /api/voip/** catch-all in APIGatewayController was shadowing the dedicated VoipRecordingUploadController POST /api/voip/recordings/upload mapping when Sprin...
파일 업로드 크기 제한 500MB
봄 부트는 1MB에 모자 multipart 부속, 배경 이미지를 일으키는 원인이 되었습니다 으로 실패 500 요청에.getParts(). SecurityService의 일치 기존의 500MB의 한계 그래서 APIService는 큰 파일 업로드 할 수 있습니다.
Move CORS to Traefik via kamo-middlewares, remove in-app CorsFilter
The CorsFilter @Bean in the Spring app was silently not applying headers after WebConfig.java was removed. CORS is now handled entirely at the Traefik layer by ...
게이트웨이에서 중복 필터 및 스트립 업스트림 CORS 헤더 제거
WebConfig.java는 CorsConfig과 비교하여 두 번째 CorsFilter bean을 정의했습니다. java의 bean, 위험 중복 헤더 쓰기. 하나의 CorsFilter가 존재합니다. 앞으로 () 방법은 또한 상류에서 Access-Control-Allow-Origin을 ...
SecurityService에 전달된 JSON body용 application/json 설정
업스트림에 restTemplate는 봄과 호환이 되는 Content-Type을 남길 수 있었습니다 @RequestBody, 원인 415. 익지않는 몸을 읽는 후에, 강제 APPLICATION JSON 페이로드가 JSON처럼 보입니다.
Validate Forgejo HMAC-SHA256 signature instead of plain secret header
Forgejo sends webhook secret as X-Gitea-Signature / X-Forgejo-Signature HMAC-SHA256 hash, not as a plain header value. Read body, verify HMAC, then forward to S...
Include SUBSCRIPTION_CATALOG in default scopes fallback
When MediaService doesn't return scopes in the validation response, default to including both PUBLIC_CHAT and SUBSCRIPTION_CATALOG scopes. This ensures public c...
Use getServerName() instead of getHeader(Host) for original host resolution
ForwardedHeaderFilter consumes X-Forwarded-Host and adapts getServerName() accordingly, while getHeader(Host) returns the raw HTTP Host which may be a K8s inter...
Use HTTP on port 80 for meet service URL to match other services
The HTTPS endpoint on 8443 causes SSL cert mismatch when routing through K8s internal DNS. All other services use HTTP on port 80.
Preserve upstream X-Forwarded-Host instead of overwriting with own Host
When an upstream proxy (Next.js) sets X-Forwarded-Host to the browser's original host, APIService now preserves it instead of overwriting with its own Host head...
Explicitly forward visitor IP to downstream services
ForwardedHeaderFilter consumes X-Forwarded-For from the incoming request, so when APIService forwards to SecurityService via RestTemplate the header is missing....
Move AccessEnforcementFilter to scanned package, revert ComponentScan
The widened @ComponentScan caused a corsFilter bean conflict between CorsConfig and WebConfig. Moved the filter into com.kamo.api.app.config (already scanned by...
Add Redis connection config to K8s configmap
APIService pod was failing to start because spring-boot-starter-data-redis auto-configuration couldn't connect to Redis at localhost:6379. Points to redis.kamo....
Use JdkClientHttpRequestFactory to support PATCH method forwarding
The default RestTemplate uses SimpleClientHttpRequestFactory (HttpURLConnection) which doesn't support the PATCH HTTP method, causing branch-titles save to fail...