Skip to content

Commit

Permalink
httpcaddyfile: Support explicitly turning off strict_sni_host (#4592)
Browse files Browse the repository at this point in the history
  • Loading branch information
francislavoie committed Mar 2, 2022
1 parent ac14b64 commit 5bd96a6
Show file tree
Hide file tree
Showing 2 changed files with 17 additions and 6 deletions.
11 changes: 7 additions & 4 deletions caddyconfig/httpcaddyfile/serveroptions.go
Expand Up @@ -157,11 +157,14 @@ func unmarshalCaddyfileServerOptions(d *caddyfile.Dispenser) (interface{}, error
serverOpts.ExperimentalHTTP3 = true

case "strict_sni_host":
if d.NextArg() {
return nil, d.ArgErr()
if d.NextArg() && d.Val() != "insecure_off" && d.Val() != "on" {
return nil, d.Errf("strict_sni_host only supports 'on' or 'insecure_off', got '%s'", d.Val())
}
boolVal := true
if d.Val() == "insecure_off" {
boolVal = false
}
trueBool := true
serverOpts.StrictSNIHost = &trueBool
serverOpts.StrictSNIHost = &boolVal

default:
return nil, d.Errf("unrecognized protocol option '%s'", d.Val())
Expand Down
Expand Up @@ -3,6 +3,9 @@
timeouts {
idle 90s
}
protocol {
strict_sni_host insecure_off
}
}
servers :80 {
timeouts {
Expand All @@ -13,6 +16,9 @@
timeouts {
idle 30s
}
protocol {
strict_sni_host
}
}
}

Expand Down Expand Up @@ -46,7 +52,8 @@ http://bar.com {
],
"terminal": true
}
]
],
"strict_sni_host": true
},
"srv1": {
"listen": [
Expand All @@ -70,7 +77,8 @@ http://bar.com {
"listen": [
":8080"
],
"idle_timeout": 90000000000
"idle_timeout": 90000000000,
"strict_sni_host": false
}
}
}
Expand Down

0 comments on commit 5bd96a6

Please sign in to comment.