<#596 PactBroker::App -- attack prevented by Rack:...
# pact-broker
g
#596 PactBroker::App -- attack prevented by Rack::Protection::IPSpoofing Issue created by yhimg Pre issue-raising checklist I have already (please mark the applicable with an
x
): • [ x ] Upgraded to the latest Pact Broker OR • [ x] Checked the CHANGELOG to see if the issue I am about to raise has been fixed • [ x] Created an executable example that demonstrates the issue using either a: • Dockerfile • Git repository with a Travis or Appveyor (or similar) build Software versions • pact-broker docker version: pact-broker-2.105.0.1 Expected behaviour Able to access the Pact Broker successfully Actual behaviour Getting Forbidden while accessing Pact Broker with specified warning Steps to reproduce I have used the local docker image of pact-broker and configured it at port 80 and everything is working fine. But now When I deployed the same image on org hosted staging environment I am getting an IPSpoofing warning and every pact-broker URL is throwing Forbidden even with GET requests. Even heartbeat URL is sending Forbidden. ERROR: W [18:puma srv tp 001] PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing nginx config: PACT_BROKER_BASE_URL: https://org-env-stage-url/cdc-pactbroker/ PACT_BROKER_PORT: 80 PACT_BROKER_PUBLIC_HEARTBEAT : true targetPort: 80 port: 80 In logs I can see that Pact broker is successfully deployed and connected to DB. But due to this error I am getting Forbidden for all URLs Relevant log files PactBroker::App -- Configuring Rack::Protection -- {:logger=>#<SemanticLogger:Logger0x00007faf1530a220 @filter=nil, @name="PactBroker::App", @level_index=nil, @Level=nil>, except=&gt;[path_traversal, :remote_token, :session_hijacking, :http_origin]} PactBroker::App -- Mounting HAL browser PactBroker::App -- Mounting UI PactBroker::App -- Configuring Rack::Protection -- {:logger=>#<SemanticLogger:Logger0x00007faf1530a220 @filter=nil, @name="PactBroker::App", @level_index=nil, @Level=nil>, except=&gt;[path_traversal, :remote_token, :session_hijacking, :http_origin]} PactBroker::App -- Mounting HAL browser PactBroker::App -- Mounting UI PactBroker::App -- Configuring Rack::Protection -- {:logger=>#<SemanticLogger:Logger0x00007faf1530a220 @filter=nil, @name="PactBroker::App", @level_index=nil, @Level=nil>, except=&gt;[path_traversal, :remote_token, :session_hijacking, :http_origin]} PactBroker::App -- Mounting HAL browser PactBroker::App -- Mounting UI PactBroker::App -- Mounting PactBroker::API PactBroker::App -- Mounting PactBroker::API PactBroker::App -- Mounting PactBroker::API PactBroker::App -- Configuring Rack::Protection -- {:logger=>#<SemanticLogger:Logger0x00007faf1530a220 @filter=nil, @name="PactBroker::App", @level_index=nil, @Level=nil>, except=&gt;[path_traversal, :remote_token, :session_hijacking, :http_origin]} PactBroker::App -- Mounting HAL browser PactBroker::App -- Mounting UI PactBroker::App -- Mounting PactBroker::API PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing PactBroker::App -- attack prevented by Rack:Protection:IPSpoofing Please ensure you set logging to
DEBUG
and attach any relevant log files here (or link from a gist). pact-foundation/pact_broker