GitHub
02/02/2023, 12:29 PMx):
• [ x ] Upgraded to the latest Pact Broker OR
• [ x] Checked the CHANGELOG to see if the issue I am about to raise has been fixed
• [ x] Created an executable example that demonstrates the issue using either a:
• Dockerfile
• Git repository with a Travis or Appveyor (or similar) build
Software versions
• pact-broker docker version: pact-broker-2.105.0.1
Expected behaviour
Able to access the Pact Broker successfully
Actual behaviour
Getting Forbidden while accessing Pact Broker with specified warning
Steps to reproduce
I have used the local docker image of pact-broker and configured it at port 80 and everything is working fine.
But now When I deployed the same image on org hosted staging environment I am getting an IPSpoofing warning and every pact-broker URL is throwing Forbidden even with GET requests.
Even heartbeat URL is sending Forbidden.
ERROR: W [18:puma srv tp 001] PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing
nginx config:
PACT_BROKER_BASE_URL: https://org-env-stage-url/cdc-pactbroker/
PACT_BROKER_PORT: 80
PACT_BROKER_PUBLIC_HEARTBEAT : true
targetPort: 80
port: 80
In logs I can see that Pact broker is successfully deployed and connected to DB. But due to this error I am getting Forbidden for all URLs
Relevant log files
PactBroker::App -- Configuring Rack::Protection -- {:logger=>#<SemanticLogger:Logger0x00007faf1530a220 @filter=nil, @name="PactBroker::App", @level_index=nil, @Level=nil>, except=>[path_traversal, :remote_token, :session_hijacking, :http_origin]}
PactBroker::App -- Mounting HAL browser
PactBroker::App -- Mounting UI
PactBroker::App -- Configuring Rack::Protection -- {:logger=>#<SemanticLogger:Logger0x00007faf1530a220 @filter=nil, @name="PactBroker::App", @level_index=nil, @Level=nil>, except=>[path_traversal, :remote_token, :session_hijacking, :http_origin]}
PactBroker::App -- Mounting HAL browser
PactBroker::App -- Mounting UI
PactBroker::App -- Configuring Rack::Protection -- {:logger=>#<SemanticLogger:Logger0x00007faf1530a220 @filter=nil, @name="PactBroker::App", @level_index=nil, @Level=nil>, except=>[path_traversal, :remote_token, :session_hijacking, :http_origin]}
PactBroker::App -- Mounting HAL browser
PactBroker::App -- Mounting UI
PactBroker::App -- Mounting PactBroker::API
PactBroker::App -- Mounting PactBroker::API
PactBroker::App -- Mounting PactBroker::API
PactBroker::App -- Configuring Rack::Protection -- {:logger=>#<SemanticLogger:Logger0x00007faf1530a220 @filter=nil, @name="PactBroker::App", @level_index=nil, @Level=nil>, except=>[path_traversal, :remote_token, :session_hijacking, :http_origin]}
PactBroker::App -- Mounting HAL browser
PactBroker::App -- Mounting UI
PactBroker::App -- Mounting PactBroker::API
PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing
PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing
PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing
PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing
PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing
Please ensure you set logging to DEBUG and attach any relevant log files here (or link from a gist).
pact-foundation/pact_brokerGitHub
02/08/2023, 4:56 AM