You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何基于路径为Envoy配置不同的path_with_escaped_slashes_action?

针对特定路径差异化设置path_with_escaped_slashes_action

方法一:Lua过滤器动态拦截

利用Envoy的Lua过滤器,在请求阶段根据路径判断是否包含转义斜杠,对特定路径直接返回400,模拟REJECT_REQUEST的效果,其他路径保持默认的KEEP_UNCHANGED:

http_filters:
  - name: envoy.filters.http.lua
    typed_config:
      "@type": type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua
      inline_code: |
        function envoy_on_request(request_handle)
          local path = request_handle:headers():get(":path")
          -- 匹配需要严格校验的路径,比如/api/admin前缀
          if string.match(path, "^/api/admin") then
            -- 检查路径中是否存在转义斜杠%2F
            if string.find(path, "%2F") then
              request_handle:respond({[":status"] = "400"}, "Request rejected: escaped slashes not allowed in path")
            end
          end
          -- 其余路径不做拦截,保持默认处理
        end
  - name: envoy.filters.http.router
    typed_config: {}

方法二:路由级直接响应(原生配置)

将全局path_with_escaped_slashes_action设为KEEP_UNCHANGED,然后通过路由规则匹配包含转义斜杠的特定路径,直接返回400响应:

http_connection_manager:
  stat_prefix: edge_http
  path_with_escaped_slashes_action: KEEP_UNCHANGED
  route_config:
    name: edge_route
    virtual_hosts:
      - name: edge_service
        domains: ["*"]
        routes:
          # 拦截/api/admin下包含转义斜杠的请求
          - match:
              safe_regex:
                regex: "^/api/admin.*%2F.*$"
            direct_response:
              status: 400
              body:
                inline_string: "Invalid path: escaped slashes are not permitted"
          # 正常转发其他所有请求
          - match:
              prefix: "/"
            route:
              cluster: your_backend_cluster

方法三:双HTTP连接管理器(内部转发)

通过Listener分流,将特定路径的请求转发到另一个配置了REJECT_REQUEST的HTTP连接管理器:

listeners:
  # 主Listener,处理大部分请求,默认KEEP_UNCHANGED
  - name: main_edge_listener
    address:
      socket_address: { address: 0.0.0.0, port_value: 80 }
    filter_chains:
      - filters:
          - name: envoy.filters.network.http_connection_manager
            typed_config:
              "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager
              stat_prefix: main_edge_http
              path_with_escaped_slashes_action: KEEP_UNCHANGED
              route_config:
                name: main_route
                virtual_hosts:
                  - name: main_service
                    domains: ["*"]
                    routes:
                      - match:
                          prefix: "/api/admin"
                        route:
                          cluster: reject_handler_cluster
                      - match:
                          prefix: "/"
                        route:
                          cluster: your_backend_cluster
  # 专门处理严格校验的Listener,设置REJECT_REQUEST
  - name: reject_handler_listener
    address:
      socket_address: { address: 127.0.0.1, port_value: 8081 }
    filter_chains:
      - filters:
          - name: envoy.filters.network.http_connection_manager
            typed_config:
              "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager
              stat_prefix: reject_http
              path_with_escaped_slashes_action: REJECT_REQUEST
              route_config:
                name: reject_route
                virtual_hosts:
                  - name: reject_service
                    domains: ["*"]
                    routes:
                      - match:
                          prefix: "/"
                        route:
                          cluster: your_backend_cluster

clusters:
  - name: reject_handler_cluster
    connect_timeout: 0.25s
    type: STATIC
    lb_policy: ROUND_ROBIN
    load_assignment:
      cluster_name: reject_handler_cluster
      endpoints:
        - lb_endpoints:
            - endpoint:
                address:
                  socket_address: { address: 127.0.0.1, port_value: 8081 }
  - name: your_backend_cluster
    # 你的后端集群配置
    connect_timeout: 0.25s
    type: STATIC
    lb_policy: ROUND_ROBIN
    load_assignment:
      cluster_name: your_backend_cluster
      endpoints:
        - lb_endpoints:
            - endpoint:
                address:
                  socket_address: { address: 10.0.0.1, port_value: 8080 }

内容的提问来源于stack exchange,提问作者Johnny000

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 03:45:35