The keycloak project ended with four open questions that design could not
settle. A two-VM lab was built to answer them by measurement, and this is
that material: 26 experiments, 125 raw command outputs, 22 browser captures.
Follows the import procedure in README.md.
source/ the originating repository verbatim — 78 documents, 28 SVGs,
8 manifests, plus .source-revision recording the commit
final/ the SSOT
document.md 729 lines written from the 29 experiment documents, not
concatenated: what was predicted, what was measured, and
where the measurement itself was wrong
evidence/raw 125 outputs, flattened to <experiment>__<file> because
the originals collided (01-baseline.txt appeared three
times) and the audit only globs the top level
evidence/meta one per raw file; command and exitCode are null and the
README says why rather than inventing them
evidence/browser 22 captures
assets/ three diagrams through techviz
.techviz/ their VizSpecs
A separate project rather than an addition to keycloak: the B-layer answers
that project's four questions, but the A, C and D layers are about cluster
failure, SSO and operations, and one document.md should hold one subject.
The four question records there can point here through 관계.
Recorded rather than papered over: only three of the 28 diagrams were
remade. The repository forbids hand-drawn SVG and forbids titles inside the
canvas; all 28 originals carry both, so converting them is redrawing, not
reformatting. They stay in source/ and the gap is written into the document.
verify-pipeline.py passes. audit-records.py reports no issues.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
69 lines
3.7 KiB
Plaintext
69 lines
3.7 KiB
Plaintext
# 블로킹 오버로드의 마지막 두 검사
|
|
35: if (profile.mode() == ClientMode.DYNAMIC && !capabilities.dynamicTargetStable()) {
|
|
36: missing.add("validated DNS pinning for dynamic targets");
|
|
37: }
|
|
38: if (profile.mode() == ClientMode.DYNAMIC && !capabilities.validatedDnsPinning()) {
|
|
39: // `validatedDnsPinning` was declared on every capability record and read by nothing. It is
|
|
40: // the capability that decides whether the SSRF address validation survives to the socket, so
|
|
41: // a transport that does not have it cannot serve a dynamic target no matter what its
|
|
42: // `dynamicTargetStable` flag says — the two were being conflated.
|
|
43: missing.add("call-scoped validated DNS pinning");
|
|
44: }
|
|
45: reject(profile, missing);
|
|
46: }
|
|
|
|
# 반응형 오버로드의 마지막 검사
|
|
64: if (profile.mode() == ClientMode.DYNAMIC && !capabilities.dynamicTargetStable()) {
|
|
65: missing.add("validated DNS pinning for dynamic targets");
|
|
66: }
|
|
67: reject(profile, missing);
|
|
68: }
|
|
|
|
# 이 두 검사에 걸린 유일한 test
|
|
39: void rejectsDynamicModeWithoutValidatedPinning() {
|
|
40- ClientProfile dynamic = ClientProfiles.builder("webhook").mode(ClientMode.DYNAMIC).build();
|
|
41- assertThatThrownBy(
|
|
42- () ->
|
|
43- validator.validate(
|
|
44- dynamic, BlockingTransportCapabilities.lightweightHttp11AndHttp2()))
|
|
45- .isInstanceOf(HttpConfigurationException.class)
|
|
46- .hasMessageContaining("validated DNS pinning");
|
|
47- }
|
|
48-
|
|
|
|
# 세 플래그를 읽는 곳 전부
|
|
TransportCapabilityValidator.java:38: if (profile.mode() == ClientMode.DYNAMIC && !capabilities.validatedDnsPinning()) {
|
|
TransportCapabilityValidator.java:39: // `validatedDnsPinning` was declared on every capability record and read by nothing. It is
|
|
ReactiveTransportCapabilities.java:14: boolean validatedDnsPinning,
|
|
ReactiveTransportCapabilities.java:16: boolean serverSentEvents,
|
|
ReactiveTransportCapabilities.java:17: boolean cancellationReleasesConnection) {
|
|
BlockingTransportCapabilities.java:19: boolean validatedDnsPinning,
|
|
|
|
# 출하된 능력 다섯이 그 두 플래그에 넣는 값
|
|
apacheClassic validatedDnsPinning=true dynamicTargetStable=true
|
|
http11AndHttp2 validatedDnsPinning=true dynamicTargetStable=true
|
|
lightweightHttp11AndHttp2 validatedDnsPinning=false dynamicTargetStable=false
|
|
reactorNetty validatedDnsPinning=true dynamicTargetStable=true
|
|
jettyHttp3Experimental validatedDnsPinning=false dynamicTargetStable=false
|
|
|
|
# 반응형 오버로드에 닿는 능력을 정하는 곳
|
|
@Bean
|
|
@ConditionalOnMissingBean(name = "httpClientReactiveTransportProviders")
|
|
Map<TransportType, ReactiveTransportProvider> httpClientReactiveTransportProviders(
|
|
ObjectProvider<MeterRegistry> meterRegistry, TlsMaterialProvider tlsMaterialProvider) {
|
|
Map<TransportType, ReactiveTransportProvider> providers = new EnumMap<>(TransportType.class);
|
|
providers.put(
|
|
TransportType.REACTOR_NETTY,
|
|
new ReactorNettyTransportProvider(
|
|
Optional.ofNullable(meterRegistry.getIfAvailable()),
|
|
profile -> materialize(profile, tlsMaterialProvider),
|
|
HttpClientTransportAutoConfiguration::dynamicTargetPinning));
|
|
return Map.copyOf(providers);
|
|
}
|
|
|
|
# 프로파일 검증기가 동적 모드에 대해 이름으로 막는 전송
|
|
173- if (profile.mode() == ClientMode.DYNAMIC
|
|
174- && (profile.transport() == TransportType.JDK
|
|
175- || profile.transport() == TransportType.JETTY)) {
|
|
176: out.add(violation("DYNAMIC_TARGET_TRANSPORT_UNSUPPORTED", profile, "transport"));
|