plugins

BareProxy Request Signing Plugin: Signed Requests to Backends and Expiring Signed URLs

Status: planned, number 6 of 21 in BareProxy’s build order. The plugins are built easiest first, and this one is about a day of coding: signatures with a key from the config, no outside calls. It comes after the Geo rules plugin. This post describes what it will do, and it will be updated as it is built.

Signing solves two different problems at the edge, and the plugin will handle both.

Proof That a Request Came Through the Proxy

An app behind a proxy trusts headers the proxy adds: the client’s address, the logged-in user from an auth gate, the country from geo rules. If anyone can reach the app directly, anyone can send those headers too. The usual answer is a private network, which isn’t always there.

The plugin signs each request it forwards: a timestamp and a hash of the method, path and chosen headers, keyed with a secret the app shares. The app checks the signature, and a request that didn’t come through BareProxy, or was changed on the way, fails the check. It’s the same idea as the signed requests many APIs require from their own clients.

The other direction: a private file, a download for a paying customer, a preview link for a client. A signed URL carries an expiry time and a signature in its query string, and only works until then. The plugin checks the signature before the request goes anywhere, and answers 403 to a link that was changed or has run out. The app, or a script, makes the links with the same key.

A config will look something like this:

plugin sign /etc/bareproxy/plugins/request-signing.wasm
  config /etc/bareproxy/plugins/sign.json
  on-error closed

site files.example.com
  use sign
  route /private/* -> files /var/www/private

Keys live in the plugin’s config file. Changing one is a config change, which plan lists and rollback can undo. Every refused request carries a note in its record saying why: a bad signature, an expired link, or a missing one.

The whole program is on the plugins page.