1
0
mirror of https://github.com/nginx-proxy/nginx-proxy synced 2025-07-13 23:44:20 +02:00
nginx-proxy/test/stress_tests
Richard Hansen dfd4f54c61 fix: Don't downgrade from https to http if certificate is missing
Before, if a site's certificate was not found, the site was served
over http rather than https.  Failing open like this is problematic
for sites where security is important.  Presumably the user set
`HTTPS_METHOD` to a non-`noredirect` value (or left it unset) for a
good reason; we should honor it even if it means serving error
messages.

WARNING: This change breaks compatibility.  Any vhost where all of the
following are true will fail after this change:

  * `HTTPS_METHOD` is either unset or set to a value other than
    `nohttps`.
  * The vhost does not have its own certificate (`default.crt` doesn't
    count).
  * Clients expect to be able to access the vhost by using plain http
    to nginx-proxy.

To get the previous behavior, set `HTTPS_METHOD` to `nohttps` for the
vhost.
2023-05-14 14:56:43 -04:00
..
test_deleted_cert feat: Unconditionally produce debug comments 2023-01-18 17:27:04 -05:00
test_unreachable_network fix: Don't downgrade from https to http if certificate is missing 2023-05-14 14:56:43 -04:00
README.md TESTS: add directory for tests featuring scenarios trying to make nginx-proxy fail 2017-03-08 21:21:32 +01:00

This directory contains tests that showcase scenarios known to break the expected behavior of nginx-proxy.