Skip to content

[proxy] Add per-target HTTP access controls - #823

Open
mlsmaycon wants to merge 9 commits into
mainfrom
feature/reverse-proxy-target-access-control
Open

mlsmaycon wants to merge 9 commits into
mainfrom
feature/reverse-proxy-target-access-control

Conversation

@mlsmaycon

@mlsmaycon mlsmaycon commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Describe your changes

Adds optional target access controls and icon-only badges with hover/focus labels. Browser E2E creates, edits, and deletes targets while checking real HTTPS proxy traffic and upstream arrivals.

Validation: 778 unit tests, TypeScript, and production build passed locally. GitHub Actions unit tests, build, and focused browser E2E (4/4, retries disabled) passed. Full cloud E2E uses the pinned backend PR image below.

Issue ticket number and link

Maintainer-approved; no separate issue.

Backend stack: netbirdio/netbird#8114 → netbirdio/netbird#8115 → netbirdio/netbird#8116 → netbirdio/netbird#8117

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

netbirdio/docs#1014

E2E tests

Optional: override the image tags used by the Playwright e2e workflow.
Defaults to main when omitted.

management-cloud-tag: sha-ab54bf6
reverse-proxy-tag: pr-7954

Summary by CodeRabbit

  • New Features
    • Configure HTTP target paths to inherit service authentication, bypass authentication, or block access. Authentication bypass is unavailable for private services.
    • Target lists show badges for paths that bypass authentication or block access; inherited settings remain unmarked.
  • Improvements
    • Reverse-proxy event details now identify authentication-bypassed and path-blocked requests.
    • Requests to blocked paths are denied, while bypassed paths can be reached without authentication.

Let operators choose service authentication, authentication bypass, or blocked access from each HTTP target's optional settings. Surface the effective override in target lists, preserve explicit choices during edits, and disable unsupported options based on proxy capabilities and private-service mode.

Cover selection, serialization, capability resolution, and access-log labels with unit tests, and extend the HTTPS service browser tests with target access assertions.
Keep target rows compact with resource-style badges and expose access labels through hover and keyboard-focus tooltips. Preserve accessible labels and cover bypass, block, and unknown actions without changing path rewriting.
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 76c73e48-c36d-427b-939d-48d97f7ac0c4
📥 Commits

Reviewing files that changed from the base of the PR and between f52dab5 and d8083cd.

📒 Files selected for processing (20)
  • .github/workflows/e2e-test.yml
  • .github/workflows/reverse-proxy-target-access-e2e.yml
  • e2e/environment/README.md
  • e2e/environment/create-test-env.sh
  • e2e/helpers/reverse-proxy-traffic.ts
  • e2e/tests/reverse-proxy-services-https.spec.ts
  • e2e/tests/reverse-proxy-target-access-traffic.spec.ts
  • src/contexts/ReverseProxiesProvider.test.ts
  • src/contexts/ReverseProxiesProvider.tsx
  • src/interfaces/ReverseProxy.ts
  • src/modules/reverse-proxy/ReverseProxyHTTPTargets.tsx
  • src/modules/reverse-proxy/ReverseProxyModal.tsx
  • src/modules/reverse-proxy/events/ReverseProxyEventsAuthMethodCell.test.tsx
  • src/modules/reverse-proxy/events/ReverseProxyEventsAuthMethodCell.tsx
  • src/modules/reverse-proxy/targets/ReverseProxyTargetAccessActionBadge.tsx
  • src/modules/reverse-proxy/targets/ReverseProxyTargetAccessControl.test.tsx
  • src/modules/reverse-proxy/targets/ReverseProxyTargetAccessControl.tsx
  • src/modules/reverse-proxy/targets/ReverseProxyTargetModal.test.tsx
  • src/modules/reverse-proxy/targets/ReverseProxyTargetModal.tsx
  • src/modules/reverse-proxy/targets/ReverseProxyTargetPath.tsx

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

Adds per-target inherit, bypass, and block access actions to reverse-proxy target editing and display. Adds focused E2E infrastructure and tests that check proxy traffic behavior for those actions.

Changes

Reverse Proxy Target Access

Layer / File(s) Summary
Access action editing and display
src/interfaces/ReverseProxy.ts, src/modules/reverse-proxy/targets/*, src/modules/reverse-proxy/ReverseProxy*.tsx, src/modules/reverse-proxy/events/*, src/contexts/ReverseProxiesProvider*
Adds typed access actions, an HTTP target access editor, action badges, and event labels. Tests cover action selection, unknown values, private-service behavior, rendering, and target sanitization.
Provision proxy traffic tests
e2e/environment/create-test-env.sh, e2e/helpers/reverse-proxy-traffic.ts, e2e/environment/README.md
Adds configurable images and proxy test settings, an echo upstream and HTTPS proxy request helper, and setup instructions.
Verify target access behavior
e2e/tests/reverse-proxy-target-access-traffic.spec.ts, e2e/tests/reverse-proxy-services-https.spec.ts
Adds real-traffic checks for authentication, bypass and block actions, path matching, header handling, updates, and service deletion. The HTTPS service test checks access-action values in create and update requests.
Run focused E2E checks
.github/workflows/reverse-proxy-target-access-e2e.yml, .github/workflows/e2e-test.yml
Adds a focused workflow with backend tag validation, test execution, and failure diagnostics. The existing workflow also includes Signal logs in the reverse-proxy logs artifact.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Playwright
  participant requestThroughReverseProxy
  participant ReverseProxy
  participant EchoUpstream
  Playwright->>requestThroughReverseProxy: Send HTTPS request with service domain
  requestThroughReverseProxy->>ReverseProxy: Send request using configured CA
  ReverseProxy->>EchoUpstream: Forward permitted request
  EchoUpstream-->>ReverseProxy: Return captured request as JSON
  ReverseProxy-->>requestThroughReverseProxy: Return proxy response
  requestThroughReverseProxy-->>Playwright: Return status, headers, and body
Loading

Suggested reviewers: heisbrot

Merge Risk: ⚪ Minimal · up to d8083

No concrete issue in the supplied evidence currently blocks merging. Confirm that the selected backend images support target access actions as part of the normal E2E checks.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 19.23% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 26 functions across 17 files. (3 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: adding per-target HTTP access controls.
Description check ✅ Passed The description includes the required issue, documentation, documentation PR URL, and E2E image tag sections. It also provides implementation details and validation results.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 19.23% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 26 functions across 17 files. (3 skipped: 3 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the paths at night
Inherit, bypass, and block take flight
The proxy sends a careful call
The echo catches headers, all
The test logs glow beneath the moon

Comment @coderabbitai help to get the list of available commands.

Allow HTTP target access actions without a cluster capability check. Keep private-service bypass restrictions and preserve target actions when editing.
Embedded proxy clients could not finish connecting because the test environment routed Signal requests to a missing service. Their startup timeouts delayed later proxy mappings during the full browser suite. Start Signal on the existing internal route and include its logs in failure diagnostics.
Cloud management loads relay signing credentials when a connected peer requests its traffic flow configuration. The test environment enabled flow support without these credentials, causing management to exit during Sync. Generate a fixture secret with a credential lifetime while keeping relay addresses empty.
@mlsmaycon
mlsmaycon marked this pull request as ready for review October 8, 2026 09:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant