Skip to content

fix: Use relaxed firewall only for routed request#4643

Open
pavel-jares-bcm wants to merge 3 commits into
v3.x.xfrom
reboot/relaxed-firewall-only-for-gw
Open

fix: Use relaxed firewall only for routed request#4643
pavel-jares-bcm wants to merge 3 commits into
v3.x.xfrom
reboot/relaxed-firewall-only-for-gw

Conversation

@pavel-jares-bcm
Copy link
Copy Markdown
Contributor

Description

Currently the whole services uses a relaxed firewalls. It is based on an original issue #23. Some services requires to provide these type of URLs. Anyway, it is valid only for gateway - the routing part. For the rest of the endpoints there could be use a strict firewall. This PR allows to define relaxed one only for proxying.

Linked to # (issue)
Part of the # (epic)

Type of change

Please delete options that are not relevant.

  • fix: Bug fix (non-breaking change which fixes an issue)
  • feat: New feature (non-breaking change which adds functionality)
  • docs: Change in a documentation
  • refactor: Refactor the code
  • chore: Chore, repository cleanup, updates the dependencies.
  • BREAKING CHANGE or !: Breaking change (fix or feature that would cause existing functionality to not work as expected)

Checklist:

  • My code follows the style guidelines of this project
  • PR title conforms to commit message guideline ## Commit Message Structure Guideline
  • I have commented my code, particularly in hard-to-understand areas. In JS I did provide JSDoc
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • The java tests in the area I was working on leverage @nested annotations
  • Any dependent changes have been merged and published in downstream modules

For more details about how should the code look like read the Contributing guideline

Signed-off-by: Pavel Jareš <Pavel.Jares@broadcom.com>
private static final String[] BASE_PATHS_MODULITH = ArrayUtils.addAll(BASE_PATH_MICROSERVICES, new String[] {
"/discovery",
"/apicatalog",
"/cachingservice"
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

what about zaas and eureka?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

zaas is not routable (there is no endpoint). It is valid also for discovery (removed) and eureka is on another port. If these basePath would be used it will be processed as routable (service could have such a serviceId even it is strage)

Signed-off-by: Pavel Jareš <Pavel.Jares@broadcom.com>
@pull-request-size pull-request-size Bot added size/L and removed size/M labels May 27, 2026
@sonarqubecloud
Copy link
Copy Markdown

@pavel-jares-bcm pavel-jares-bcm marked this pull request as ready for review May 27, 2026 12:03
@EvaJavornicka EvaJavornicka moved this from New to In Progress in API Mediation Layer Backlog Management May 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

3 participants