nginx: add tests & fix failures for SSL_TYPE=upstream#1589
Merged
alxndrsn merged 14 commits intogetodk:nextfrom Dec 30, 2025
Merged
nginx: add tests & fix failures for SSL_TYPE=upstream#1589alxndrsn merged 14 commits intogetodk:nextfrom
alxndrsn merged 14 commits intogetodk:nextfrom
Conversation
alxndrsn
commented
Dec 29, 2025
alxndrsn
commented
Dec 29, 2025
alxndrsn
commented
Dec 29, 2025
| }); | ||
| socket.on('end', resolve); | ||
| socket.on('error', reject); | ||
| })); |
Contributor
Author
There was a problem hiding this comment.
These tests are specific to SSL_TYPE=selfsign, and have been moved above.
alxndrsn
commented
Dec 29, 2025
| res.on('error', reject); | ||
|
|
||
| const body = new Readable({ _read: () => {} }); | ||
| const body = new Readable({ read:() => {} }); |
Contributor
Author
There was a problem hiding this comment.
This was a bug, but only shows when the Readable is used with http.request, not with https.request.
alxndrsn
commented
Dec 29, 2025
| }); | ||
| socket.on('end', resolve); | ||
| socket.on('error', reject); | ||
| })); |
Contributor
Author
There was a problem hiding this comment.
These tests are specific to SSL_TYPE=selfsign, and have been moved up from below.
2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1588
What has been done to verify that this works as intended?
Adapted existing nginx tests to run with both:
SSL_TYPE=selfsign(as happened previously), andSSL_TYPE=upstream(previously untested, as exposed in Update X-Forwarded-Proto directive in backend.conf #1586)Why is this the best possible solution? Were any other approaches considered?
This PR adapts existing tests and runs them for
SSL_TYPE=upstream. This is in addition toSSL_TYPE=selfsign, which was already being tested.This approach has shown its worth by exposing another bug with
SSL_TYPE=upstream, where/csp-report-related nginx config was being stripped by an overly-broadperlregex.How does this change affect users? Describe intentional changes to behavior and behavior that could have accidentally been affected by code changes. In other words, what are the regression risks?
Should reduce risk from nginx config changes for users using
SSL_TYPE=upstream.Does this change require updates to documentation? If so, please file an issue here and include the link below.
No.
Before submitting this PR, please make sure you have:
nextbranch OR only changed documentation/infrastructure (masteris stable and used in production)