如何基于路径为Envoy配置不同的path_with_escaped_slashes_action?
针对特定路径差异化设置
path_with_escaped_slashes_action 方法一:Lua过滤器动态拦截
利用Envoy的Lua过滤器,在请求阶段根据路径判断是否包含转义斜杠,对特定路径直接返回400,模拟REJECT_REQUEST的效果,其他路径保持默认的KEEP_UNCHANGED:
http_filters: - name: envoy.filters.http.lua typed_config: "@type": type.googleapis.com/envoy.extensions.filters.http.lua.v3.Lua inline_code: | function envoy_on_request(request_handle) local path = request_handle:headers():get(":path") -- 匹配需要严格校验的路径,比如/api/admin前缀 if string.match(path, "^/api/admin") then -- 检查路径中是否存在转义斜杠%2F if string.find(path, "%2F") then request_handle:respond({[":status"] = "400"}, "Request rejected: escaped slashes not allowed in path") end end -- 其余路径不做拦截,保持默认处理 end - name: envoy.filters.http.router typed_config: {}
方法二:路由级直接响应(原生配置)
将全局path_with_escaped_slashes_action设为KEEP_UNCHANGED,然后通过路由规则匹配包含转义斜杠的特定路径,直接返回400响应:
http_connection_manager: stat_prefix: edge_http path_with_escaped_slashes_action: KEEP_UNCHANGED route_config: name: edge_route virtual_hosts: - name: edge_service domains: ["*"] routes: # 拦截/api/admin下包含转义斜杠的请求 - match: safe_regex: regex: "^/api/admin.*%2F.*$" direct_response: status: 400 body: inline_string: "Invalid path: escaped slashes are not permitted" # 正常转发其他所有请求 - match: prefix: "/" route: cluster: your_backend_cluster
方法三:双HTTP连接管理器(内部转发)
通过Listener分流,将特定路径的请求转发到另一个配置了REJECT_REQUEST的HTTP连接管理器:
listeners: # 主Listener,处理大部分请求,默认KEEP_UNCHANGED - name: main_edge_listener address: socket_address: { address: 0.0.0.0, port_value: 80 } filter_chains: - filters: - name: envoy.filters.network.http_connection_manager typed_config: "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager stat_prefix: main_edge_http path_with_escaped_slashes_action: KEEP_UNCHANGED route_config: name: main_route virtual_hosts: - name: main_service domains: ["*"] routes: - match: prefix: "/api/admin" route: cluster: reject_handler_cluster - match: prefix: "/" route: cluster: your_backend_cluster # 专门处理严格校验的Listener,设置REJECT_REQUEST - name: reject_handler_listener address: socket_address: { address: 127.0.0.1, port_value: 8081 } filter_chains: - filters: - name: envoy.filters.network.http_connection_manager typed_config: "@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager stat_prefix: reject_http path_with_escaped_slashes_action: REJECT_REQUEST route_config: name: reject_route virtual_hosts: - name: reject_service domains: ["*"] routes: - match: prefix: "/" route: cluster: your_backend_cluster clusters: - name: reject_handler_cluster connect_timeout: 0.25s type: STATIC lb_policy: ROUND_ROBIN load_assignment: cluster_name: reject_handler_cluster endpoints: - lb_endpoints: - endpoint: address: socket_address: { address: 127.0.0.1, port_value: 8081 } - name: your_backend_cluster # 你的后端集群配置 connect_timeout: 0.25s type: STATIC lb_policy: ROUND_ROBIN load_assignment: cluster_name: your_backend_cluster endpoints: - lb_endpoints: - endpoint: address: socket_address: { address: 10.0.0.1, port_value: 8080 }
内容的提问来源于stack exchange,提问作者Johnny000
相关产品推荐
相关产品推荐

