https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=12620

--- Comment #22 from Adolfo Rodríguez Taboada <[email protected]> ---
Hi David,

Thanks for catching this in comment #18 — koha-conf.xml is clearly a stronger
boundary than a system preference, so I've gone ahead and made the change.
Attached three patches (the first obsoletes 201633, which is the same base fix
just rebased):

* Bug 12620: Proxy Add-on for Koha z39.50/SRU servers — the base patch, rebased
onto current main.
* Bug 12620: (follow-up) Move HttpForwardProxy from a system preference to
koha-conf.xml — removes the syspref entirely (sysprefs.sql, web_services.pref,
the atomicupdate), adds a documented http_forward_proxy entry to koha-conf.xml,
and updates C4::Breeding::_create_connection / admin/z3950servers.pl /
z3950servers.tt to read it from C4::Context->config instead of Koha.Preference.
The per-server do_not_use_proxy checkbox/column is unchanged.
* Bug 12620: (QA follow-up) Add test coverage for http_forward_proxy —
_create_connection had no test coverage at all for the proxy branch, for either
the syspref or the config version. Added 4 assertions mocking
ZOOM::Connection::connect and C4::Context->config.
Tested manually too: without http_forward_proxy set, the checkbox doesn't show
and there's no proxy attempt; with it pointed at a local Squid allowing CONNECT
to port 210, a real Z39.50 search tunnels through it (confirmed in Squid's
access log); with "Do not use proxy" checked, the connection goes direct.

One thing for the record, not to argue against making the change —
koha-conf.xml is the right call either way: HttpForwardProxy as a syspref was
already gated behind the parameters permission, not editable by just any
logged-in user. The real difference is "staff with syspref admin rights via the
web UI" vs "someone with actual server/filesystem access", which is a
meaningful drop in blast radius, but it wasn't wide open before either. Worth
keeping in mind since staff with syspref access already have plenty of other
preferences that could do comparable damage if misused (arbitrary URLs, LDAP
config, etc.) — this closes one more of those doors, it's not the only one
standing open.

Let me know if this addresses your concern or if you'd like anything else
changed before a signoff.

Thanks,
Adolfo

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to