BBlack has uploaded a new change for review.

  https://gerrit.wikimedia.org/r/237701

Change subject: Beta secure POST exception: ?i and $-anchoring
......................................................................

Beta secure POST exception: ?i and $-anchoring

Improves on cff09645 a bit

Change-Id: I93fe8eb342d01405518de4da88de1e3070ce231f
---
M modules/varnish/templates/vcl/wikimedia.vcl.erb
1 file changed, 1 insertion(+), 1 deletion(-)


  git pull ssh://gerrit.wikimedia.org:29418/operations/puppet 
refs/changes/01/237701/1

diff --git a/modules/varnish/templates/vcl/wikimedia.vcl.erb 
b/modules/varnish/templates/vcl/wikimedia.vcl.erb
index c6df9bf..776c585 100644
--- a/modules/varnish/templates/vcl/wikimedia.vcl.erb
+++ b/modules/varnish/templates/vcl/wikimedia.vcl.erb
@@ -212,7 +212,7 @@
                        }
                }
 <% if @vcl_config.fetch("secure_post", true) -%>
-               if (req.request == "POST" && !(req.http.Host ~ 
"\.beta\.wmflabs\.org")) {
+               if (req.request == "POST" && !(req.http.Host ~ 
"(?i)\.beta\.wmflabs\.org$")) {
                        error 403 "Insecure POST Forbidden - use HTTPS";
                }
 <% end %>

-- 
To view, visit https://gerrit.wikimedia.org/r/237701
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings

Gerrit-MessageType: newchange
Gerrit-Change-Id: I93fe8eb342d01405518de4da88de1e3070ce231f
Gerrit-PatchSet: 1
Gerrit-Project: operations/puppet
Gerrit-Branch: production
Gerrit-Owner: BBlack <bbl...@wikimedia.org>

_______________________________________________
MediaWiki-commits mailing list
MediaWiki-commits@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits

Reply via email to