Files
document-haness/docs/clean-architecture-backend-template/final/evidence/raw/a11-f007-dns.txt
T
DongHyeonkaandClaude Opus 5 b2963105a8 docs(keycloak-session-store): import the session-storage lab as a new project
The keycloak project ended with four open questions that design could not
settle. A two-VM lab was built to answer them by measurement, and this is
that material: 26 experiments, 125 raw command outputs, 22 browser captures.

Follows the import procedure in README.md.

  source/     the originating repository verbatim — 78 documents, 28 SVGs,
              8 manifests, plus .source-revision recording the commit
  final/      the SSOT
    document.md   729 lines written from the 29 experiment documents, not
                  concatenated: what was predicted, what was measured, and
                  where the measurement itself was wrong
    evidence/raw    125 outputs, flattened to <experiment>__<file> because
                    the originals collided (01-baseline.txt appeared three
                    times) and the audit only globs the top level
    evidence/meta   one per raw file; command and exitCode are null and the
                    README says why rather than inventing them
    evidence/browser  22 captures
    assets/       three diagrams through techviz
    .techviz/     their VizSpecs

A separate project rather than an addition to keycloak: the B-layer answers
that project's four questions, but the A, C and D layers are about cluster
failure, SSO and operations, and one document.md should hold one subject.
The four question records there can point here through 관계.

Recorded rather than papered over: only three of the 28 diagrams were
remade. The repository forbids hand-drawn SVG and forbids titles inside the
canvas; all 28 originals carry both, so converting them is redrawing, not
reformatting. They stay in source/ and the gap is written into the document.

verify-pipeline.py passes. audit-records.py reports no issues.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-04 22:51:59 +09:00

69 lines
3.7 KiB
Plaintext

# 블로킹 오버로드의 마지막 두 검사
35: if (profile.mode() == ClientMode.DYNAMIC && !capabilities.dynamicTargetStable()) {
36: missing.add("validated DNS pinning for dynamic targets");
37: }
38: if (profile.mode() == ClientMode.DYNAMIC && !capabilities.validatedDnsPinning()) {
39: // `validatedDnsPinning` was declared on every capability record and read by nothing. It is
40: // the capability that decides whether the SSRF address validation survives to the socket, so
41: // a transport that does not have it cannot serve a dynamic target no matter what its
42: // `dynamicTargetStable` flag says — the two were being conflated.
43: missing.add("call-scoped validated DNS pinning");
44: }
45: reject(profile, missing);
46: }
# 반응형 오버로드의 마지막 검사
64: if (profile.mode() == ClientMode.DYNAMIC && !capabilities.dynamicTargetStable()) {
65: missing.add("validated DNS pinning for dynamic targets");
66: }
67: reject(profile, missing);
68: }
# 이 두 검사에 걸린 유일한 test
39: void rejectsDynamicModeWithoutValidatedPinning() {
40- ClientProfile dynamic = ClientProfiles.builder("webhook").mode(ClientMode.DYNAMIC).build();
41- assertThatThrownBy(
42- () ->
43- validator.validate(
44- dynamic, BlockingTransportCapabilities.lightweightHttp11AndHttp2()))
45- .isInstanceOf(HttpConfigurationException.class)
46- .hasMessageContaining("validated DNS pinning");
47- }
48-
# 세 플래그를 읽는 곳 전부
TransportCapabilityValidator.java:38: if (profile.mode() == ClientMode.DYNAMIC && !capabilities.validatedDnsPinning()) {
TransportCapabilityValidator.java:39: // `validatedDnsPinning` was declared on every capability record and read by nothing. It is
ReactiveTransportCapabilities.java:14: boolean validatedDnsPinning,
ReactiveTransportCapabilities.java:16: boolean serverSentEvents,
ReactiveTransportCapabilities.java:17: boolean cancellationReleasesConnection) {
BlockingTransportCapabilities.java:19: boolean validatedDnsPinning,
# 출하된 능력 다섯이 그 두 플래그에 넣는 값
apacheClassic validatedDnsPinning=true dynamicTargetStable=true
http11AndHttp2 validatedDnsPinning=true dynamicTargetStable=true
lightweightHttp11AndHttp2 validatedDnsPinning=false dynamicTargetStable=false
reactorNetty validatedDnsPinning=true dynamicTargetStable=true
jettyHttp3Experimental validatedDnsPinning=false dynamicTargetStable=false
# 반응형 오버로드에 닿는 능력을 정하는 곳
@Bean
@ConditionalOnMissingBean(name = "httpClientReactiveTransportProviders")
Map<TransportType, ReactiveTransportProvider> httpClientReactiveTransportProviders(
ObjectProvider<MeterRegistry> meterRegistry, TlsMaterialProvider tlsMaterialProvider) {
Map<TransportType, ReactiveTransportProvider> providers = new EnumMap<>(TransportType.class);
providers.put(
TransportType.REACTOR_NETTY,
new ReactorNettyTransportProvider(
Optional.ofNullable(meterRegistry.getIfAvailable()),
profile -> materialize(profile, tlsMaterialProvider),
HttpClientTransportAutoConfiguration::dynamicTargetPinning));
return Map.copyOf(providers);
}
# 프로파일 검증기가 동적 모드에 대해 이름으로 막는 전송
173- if (profile.mode() == ClientMode.DYNAMIC
174- && (profile.transport() == TransportType.JDK
175- || profile.transport() == TransportType.JETTY)) {
176: out.add(violation("DYNAMIC_TARGET_TRANSPORT_UNSUPPORTED", profile, "transport"));