-
Notifications
You must be signed in to change notification settings - Fork 1.7k
Unify the WebSocket and HTTP pipelines #2422
Copy link
Copy link
Open
Labels
CoreOcelot Core related or system upgrade (not a public feature)Ocelot Core related or system upgrade (not a public feature)help wantedNot actively being worked on. If you plan to contribute, please drop a note.Not actively being worked on. If you plan to contribute, please drop a note.large effortLikely over a week of development effortLikely over a week of development effortmedium effortLikely a few days of development effortLikely a few days of development effortproposalProposal for a new functionality in OcelotProposal for a new functionality in Ocelot
Description
Activity
Metadata
Metadata
Assignees
Labels
CoreOcelot Core related or system upgrade (not a public feature)Ocelot Core related or system upgrade (not a public feature)help wantedNot actively being worked on. If you plan to contribute, please drop a note.Not actively being worked on. If you plan to contribute, please drop a note.large effortLikely over a week of development effortLikely over a week of development effortmedium effortLikely a few days of development effortLikely a few days of development effortproposalProposal for a new functionality in OcelotProposal for a new functionality in Ocelot
Predecessor
Idea 💡
Proposal — merge the WebSocket and HTTP pipelines
Goal
Remove the forked WebSocket pipeline and route WebSocket upgrade requests through the same Ocelot pipeline as ordinary HTTP requests. This is the larger follow-up discussed on #2406 (the #2403 IP-security fix), where the fork was the root cause of the bypass.
Why
A WebSocket request is an ordinary HTTP request until
AcceptWebSocketAsync. Todayapp.MapWhen(IsWebSocketRequest, ConfigureWebSockets)forks it into a hand-maintained subset of middlewares, which is why WS upgrades miss most Ocelot features (auth, authz, rate limiting, claims, header transforms) and why each gap has to be patched in the forked pipeline separately.Proposed approach
MapWhenWS fork inOcelotPipelineExtensions.BuildOcelotPipeline.WebSocketsProxyMiddlewareself-checkIsWebSocketRequestand pass non-WS requests through, registering it as a normal pipeline stage afterDownstreamUrlCreatorMiddlewareso WS terminates there and HTTP continues to cache/requester.WebSocketsMiddlewareType/WebSocketsMiddleware).ConfigureWebSocketsextension (keep /[Obsolete]).Open questions for maintainers
ConfigureWebSockets'[Obsolete]'?MapWhenOcelotPipelinebranches would begin to see WS upgrade traffic; browser WS clients can't send anAuthorizationheader).