Docker-Images bauen und veröffentlichen / build (, omsorgCore/Dockerfile, omsorgcore) (push) Successful in 3s
Docker-Images bauen und veröffentlichen / build (, omsorgWeb/Dockerfile, omsorgweb) (push) Successful in 4s
Docker-Images bauen und veröffentlichen / build (, omsorgapp/Dockerfile, omsorgapp) (push) Successful in 3s
The root .htaccess forces HTTPS via `RewriteCond %{HTTPS} !=on`. Behind a
reverse proxy that terminates TLS and forwards to Apache over plain HTTP,
%{HTTPS} is always "off" - verified via mod_rewrite trace logging that
this is NOT spoofable via SetEnvIf or a RewriteRule E-flag, despite that
being commonly recommended; %{HTTPS} reflects only the actual TLS
connection to Apache. Every request was therefore redirected to https://,
which the proxy forwarded back over HTTP, looping forever (browser: "the
page isn't redirecting properly").
Fix: .htaccess's redirect condition also accepts a trusted
X-Forwarded-Proto: https header as evidence the request is already
HTTPS. omsorgWeb/docker/000-default.conf additionally sets HTTPS=on in
the request environment when that header is present, so mod_headers'
`env=HTTPS` condition (HSTS header) still fires correctly - this part
doesn't affect mod_rewrite's %{HTTPS} but is unrelated to the redirect fix.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
23 lines
1.1 KiB
Plaintext
23 lines
1.1 KiB
Plaintext
<VirtualHost *:80>
|
|
ServerName omsorgweb
|
|
ServerAdmin webmaster@localhost
|
|
DocumentRoot /var/www/html
|
|
|
|
# Der Host-nginx terminiert TLS und proxied per HTTP an diesen Container (siehe
|
|
# docker-compose.yml) - ohne diese Regel weiß die root-.htaccess
|
|
# (`RewriteCond %{HTTPS} !=on` -> Redirect auf https://) nie, dass die ursprüngliche Anfrage
|
|
# HTTPS war, und redirected endlos (führt zu "Firefox kann nicht verbinden - Seite leitet
|
|
# falsch weiter" bzw. ERR_TOO_MANY_REDIRECTS). Per mod_rewrite-Trace verifiziert: das MUSS
|
|
# innerhalb dieses <VirtualHost>-Blocks stehen - weder eine Regel in conf-enabled/*.conf
|
|
# außerhalb jedes VirtualHost, noch eine in einem <Directory>-Block wird mit dem
|
|
# per-Directory-Regelsatz der .htaccess desselben Pfads zusammengeführt (beides per Trace
|
|
# ausprobiert, keins hat gewirkt - Apache vererbt Rewrite-Regeln standardmäßig nicht über
|
|
# Kontextgrenzen hinweg, siehe RewriteOptions Inherit in der mod_rewrite-Doku).
|
|
RewriteEngine On
|
|
RewriteCond "%{HTTP:X-Forwarded-Proto}" "=https"
|
|
RewriteRule ^ - [E=HTTPS:on]
|
|
|
|
ErrorLog ${APACHE_LOG_DIR}/error.log
|
|
CustomLog ${APACHE_LOG_DIR}/access.log combined
|
|
</VirtualHost>
|