ci: 加 -race、staticcheck、govulncheck、shellcheck 与真 PostgreSQL 集成测试门禁,release 复用 ci 门禁
This commit is contained in:
8 files changed
+130
-58
No files matched your search
@@ -505,7 +505,7 @@ func (o OffsiteConfig) validate() error {
|
||||
return fmt.Errorf("config: [offsite] bucket %q must be a bare bucket name; put a key prefix in prefix", o.Bucket)
|
||||
}
|
||||
if strings.Contains(o.Prefix, "..") {
|
||||
return fmt.Errorf("config: [offsite] prefix %q must not contain ..", o.Prefix)
|
||||
return fmt.Errorf("config: [offsite] prefix %q must not contain \"..\"", o.Prefix)
|
||||
}
|
||||
if o.DBKeep < 1 {
|
||||
return fmt.Errorf("config: [offsite] db_keep %d must be at least 1", o.DBKeep)
|
||||
|
||||
@@ -81,13 +81,15 @@ type Gate struct {
|
||||
// New builds a Gate for upstream.
|
||||
func New(upstream *url.URL, tokens map[string]string, log *slog.Logger) *Gate {
|
||||
g := &Gate{Tokens: tokens, Upstream: upstream, Log: log}
|
||||
rp := httputil.NewSingleHostReverseProxy(upstream)
|
||||
base := rp.Director
|
||||
rp.Director = func(r *http.Request) {
|
||||
base(r)
|
||||
rp := &httputil.ReverseProxy{Rewrite: func(pr *httputil.ProxyRequest) {
|
||||
pr.SetURL(upstream)
|
||||
// The registry builds upload Location URLs from Host: keep the one the client
|
||||
// dialled, not the loopback upstream.
|
||||
pr.Out.Host = pr.In.Host
|
||||
pr.SetXForwarded()
|
||||
// The registry has no auth of its own; the credential stops here.
|
||||
r.Header.Del("Authorization")
|
||||
}
|
||||
pr.Out.Header.Del("Authorization")
|
||||
}}
|
||||
// Blob uploads and pulls are streamed; flush as bytes arrive so a large layer
|
||||
// pull is not buffered in the gate.
|
||||
rp.FlushInterval = -1
|
||||
|
||||
Reference in new issue
Block a user