Skip to content

SSLセットアップが必要なドメインを後ろにする - #63

Merged
haruyan-hopemucci merged 4 commits into
masterfrom
fix/nginx-config-setup-ordered-by-priority
Mar 27, 2026
Merged

haruyan-hopemucci merged 4 commits into
masterfrom
fix/nginx-config-setup-ordered-by-priority

Conversation

@lobin-z0x50

@lobin-z0x50 lobin-z0x50 commented Mar 6, 2026 •

Copy link
Copy Markdown
Member

fix #39

TODO

  • テストコード
  • 実環境で動作検証

@lobin-z0x50 lobin-z0x50 changed the title SSLセットアップ順を優先度ごとに。FORCE_MODEの考慮 [二割共有]SSLセットアップ順を優先度ごとに。FORCE_MODEの考慮 Mar 6, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

このプルリクエストは、NginxのSSL設定プロセス、特にLet's Encryptを使用した証明書生成と更新の堅牢性を向上させることを目的としています。ドメインのSSLセットアップ状況に基づいて処理の優先順位を付けることで、設定の書き出しとNginxのリロードがより安全かつ効率的に行われるようになり、証明書生成中のサービス中断リスクを低減します。また、FORCE_MODE時の挙動も改善され、より柔軟な運用が可能になります。

Highlights

  • SSLセットアップ優先度ロジックの追加: SSLセットアップの優先度を判断するssl_setup_priorityメソッドをconfig.rbに追加しました。これにより、HTTPS非対応、セットアップ済み、要セットアップの3つの状態を識別します。
  • Nginx設定テストとリロードの強化: Nginx設定生成後にnginx -tで設定ファイルの構文チェックを行い、Let's Encryptセットアップ後にnginx -s reloadでNginxをリロードする処理を追加しました。
  • SSLセットアップ処理順序の最適化: reload_config.rbにおいて、SSLセットアップが必要なドメインを最後に処理するように、設定の処理順序をSSLセットアップ優先度に基づいて変更しました。これにより、Nginxのリロード時のアクセスエラーを防ぎます。
  • FORCE_MODE時の挙動改善: FORCE_MODEが有効な場合、既にSSLがセットアップされているドメイン(2:installed)に対してもLet's Encryptの再セットアップを強制実行するロジックを追加しました。
  • Nginxリロードコマンドの変更: Nginxのリロードコマンドをservice nginx reloadからnginx -s reloadに変更しました。

🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Changelog
  • src/app/lib/config.rb
    • SSLセットアップの優先度を返すssl_setup_priorityメソッドを追加しました。
    • HTTPS非対応の場合のNginx設定レンダリング後にnginx -tコマンドを追加しました。
    • Let's Encryptセットアップ後にnginx -s reloadコマンドを追加しました。
  • src/app/reload_config.rb
    • configurationsをssl_setup_priorityに基づいてグループ化し、処理順序をソートするように変更しました。
    • config.generate_nginx_configの呼び出しからENV['FORCE_MODE']引数を削除しました。
    • FORCE_MODEが有効な場合に、2:installed状態のドメインに対してLet's Encryptの再セットアップを強制実行するロジックを追加しました。
    • Nginxのリロードコマンドをservice nginx reloadからnginx -s reloadに変更しました。
Activity
  • このプルリクエストは、Issue #39の修正を目的としています。
  • 現在のところ、テストコードの追加と実環境での動作検証がTODOリストとして挙げられています。
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request intends to prioritize SSL certificate setup and integrate FORCE_MODE. However, it introduces critical security vulnerabilities, including command injection in the SSL setup process due to unsanitized domain names and email addresses, and a path traversal vulnerability when checking for existing certificates. Furthermore, reload_config.rb contains significant logic errors, such as incorrect method calls on Hash objects, variable scoping issues, and improper loop nesting, particularly within the FORCE_MODE implementation, which could lead to crashes and incorrect behavior. Immediate remediation is required to sanitize all external inputs and correct the identified logic flaws.

Comment thread src/app/lib/config.rb
shell_exec 'nginx -t'
shell_exec 'nginx -s reload'

LetsEncrypt.setup self

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-critical critical

The call to LetsEncrypt.setup self triggers a command injection vulnerability. The LetsEncrypt.setup method (in src/app/lib/lets_encrypt.rb) takes the Config object and interpolates its domain and cert_email attributes directly into a shell command string passed to shell_exec. Since these attributes are derived from untrusted sources like environment variables (PROXY_TO, CERT_EMAIL) without sanitization, an attacker can execute arbitrary commands by injecting shell metacharacters (e.g., ;, $(...), `...`) into the domain or email.

Comment thread src/app/reload_config.rb Outdated
grouped['2:installed'].each do |config|
configs.each do |config|
log "----- start setup of Let's Encrypt for #{config.domain} -----"
config.generate_nginx_config force: true

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-critical critical

The call to config.generate_nginx_config force: true leads to a command injection vulnerability. The domain attribute of the config object is eventually used in a shell command (via LetsEncrypt.setup) without proper sanitization. An attacker controlling the PROXY_TO environment variable can inject arbitrary shell commands.

Comment thread src/app/reload_config.rb Outdated
Comment on lines 77 to 85
if ENV['FORCE_MODE']
log "========== #{type} FORCE re-install =========="
grouped['2:installed'].each do |config|
configs.each do |config|
log "----- start setup of Let's Encrypt for #{config.domain} -----"
config.generate_nginx_config force: true
end
end
end

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-medium medium

This block contains a critical logic error and potential crash in the FORCE_MODE handling, which could lead to incorrect processing and potential Denial of Service through repeated certificate requests. Specifically, variables like type and configs are out of scope from previous blocks (lines 65-71), causing a NameError. The inner loop (line 80) incorrectly iterates over configs instead of config, shadowing the loop variable. Additionally, grouped['2:installed'] (line 79) might return nil if grouped becomes an array, leading to an error on .each, and the variable type at line 78 is out of scope, potentially causing unintended log output. The overall nesting of loops for FORCE_MODE processing (lines 79-84) is also incorrect.

    if ENV['FORCE_MODE']
      log "========== 2:installed FORCE re-install =========="
      grouped['2:installed']&.each do |config|
        log "----- start setup of Let's Encrypt for #{config.domain} -----"
        config.generate_nginx_config force: true
      end
    end

Comment thread src/app/lib/config.rb
# HTTPS 対応版
unless cert_file
# 証明書ファイルが指定されていなければ、Let's Encrypt を使って生成する
if !File.exist?("/etc/letsencrypt/live/#{domain}")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-medium medium

The domain attribute is used directly to construct a file path in File.exist?("/etc/letsencrypt/live/#{domain}"). If an attacker can control the domain value (e.g., via the PROXY_TO environment variable), they can use path traversal sequences like ../ to check for the existence of arbitrary files on the system, leading to information disclosure.

@lobin-z0x50
lobin-z0x50 force-pushed the fix/nginx-config-setup-ordered-by-priority branch from aec79af to 451995d Compare March 6, 2026 15:27
@lobin-z0x50 lobin-z0x50 changed the title [二割共有]SSLセットアップ順を優先度ごとに。FORCE_MODEの考慮 [6割共有]SSLセットアップが必要なドメインを後ろにする Mar 6, 2026
@lobin-z0x50
lobin-z0x50 force-pushed the fix/nginx-config-setup-ordered-by-priority branch from 451995d to 34a9842 Compare March 25, 2026 06:20
@lobin-z0x50

Copy link
Copy Markdown
Member Author

@lobin-z0x50 lobin-z0x50 changed the title [6割共有]SSLセットアップが必要なドメインを後ろにする SSLセットアップが必要なドメインを後ろにする Mar 25, 2026

@haruyan-hopemucci haruyan-hopemucci left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

レビューOKです! ありがとうございました!

Comment thread src/app/lib/config.rb
Comment on lines +111 to +112
def ssl_setup_priority
return "1:no_installation" if @no_ssl

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

require_relative './config'
require_relative './socat_manager'

class ReloadController

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍
Reload処理のクラス化ナイスです!

require_relative 'test_helper'
require 'lib/reload_controller'

class ReloadControllerTest < Minitest::Test

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍
テスト作成ありがとうございます!

config_no_ssl = MockConfig.new("no-ssl.example.com", "1:no_installation")
config_installed = MockConfig.new("installed.example.com", "2:installed")

# 意図的に優先度の逆順で渡す

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@haruyan-hopemucci
haruyan-hopemucci merged commit 87acf14 into master Mar 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

reload中にアクセスすると、証明書エラーになる

2 participants