Repository navigation
Conversation
Let operators choose service authentication, authentication bypass, or blocked access from each HTTP target's optional settings. Surface the effective override in target lists, preserve explicit choices during edits, and disable unsupported options based on proxy capabilities and private-service mode. Cover selection, serialization, capability resolution, and access-log labels with unit tests, and extend the HTTPS service browser tests with target access assertions.
Keep target rows compact with resource-style badges and expose access labels through hover and keyboard-focus tooltips. Preserve accessible labels and cover bypass, block, and unknown actions without changing path rewriting.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (20)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughAdds per-target inherit, bypass, and block access actions to reverse-proxy target editing and display. Adds focused E2E infrastructure and tests that check proxy traffic behavior for those actions. ChangesReverse Proxy Target Access
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Playwright
participant requestThroughReverseProxy
participant ReverseProxy
participant EchoUpstream
Playwright->>requestThroughReverseProxy: Send HTTPS request with service domain
requestThroughReverseProxy->>ReverseProxy: Send request using configured CA
ReverseProxy->>EchoUpstream: Forward permitted request
EchoUpstream-->>ReverseProxy: Return captured request as JSON
ReverseProxy-->>requestThroughReverseProxy: Return proxy response
requestThroughReverseProxy-->>Playwright: Return status, headers, and body
Suggested reviewers: Merge Risk: ⚪ Minimal · up to No concrete issue in the supplied evidence currently blocks merging. Confirm that the selected backend images support target access actions as part of the normal E2E checks. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 19.23% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 26 functions across 17 files. (3 skipped: 3 unsupported.)
✨ Finishing Touches 💡 2📝 Generate docstrings 💡
🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the paths at night Comment |
Allow HTTP target access actions without a cluster capability check. Keep private-service bypass restrictions and preserve target actions when editing.
Embedded proxy clients could not finish connecting because the test environment routed Signal requests to a missing service. Their startup timeouts delayed later proxy mappings during the full browser suite. Start Signal on the existing internal route and include its logs in failure diagnostics.
Cloud management loads relay signing credentials when a connected peer requests its traffic flow configuration. The test environment enabled flow support without these credentials, causing management to exit during Sync. Generate a fixture secret with a credential lifetime while keeping relay addresses empty.
Describe your changes
Adds optional target access controls and icon-only badges with hover/focus labels. Browser E2E creates, edits, and deletes targets while checking real HTTPS proxy traffic and upstream arrivals.
Validation: 778 unit tests, TypeScript, and production build passed locally. GitHub Actions unit tests, build, and focused browser E2E (4/4, retries disabled) passed. Full cloud E2E uses the pinned backend PR image below.
Issue ticket number and link
Maintainer-approved; no separate issue.
Backend stack: netbirdio/netbird#8114 → netbirdio/netbird#8115 → netbirdio/netbird#8116 → netbirdio/netbird#8117
Documentation
Select exactly one:
Docs PR URL (required if "docs added" is checked)
Paste the PR link from https://github.com/netbirdio/docs here:
netbirdio/docs#1014
E2E tests
Optional: override the image tags used by the Playwright e2e workflow.
Defaults to
mainwhen omitted.management-cloud-tag: sha-ab54bf6
reverse-proxy-tag: pr-7954
Summary by CodeRabbit