2017-02-23 18:10:32 +00:00
/ *
Copyright 2016 The Kubernetes Authors .
Licensed under the Apache License , Version 2.0 ( the "License" ) ;
you may not use this file except in compliance with the License .
You may obtain a copy of the License at
http : //www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing , software
distributed under the License is distributed on an "AS IS" BASIS ,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND , either express or implied .
See the License for the specific language governing permissions and
limitations under the License .
* /
package snippet
import (
2021-08-21 20:42:00 +00:00
networking "k8s.io/api/networking/v1"
2017-02-23 18:10:32 +00:00
2017-11-07 22:02:12 +00:00
"k8s.io/ingress-nginx/internal/ingress/annotations/parser"
2017-11-08 20:58:57 +00:00
"k8s.io/ingress-nginx/internal/ingress/resolver"
2017-02-23 18:10:32 +00:00
)
2023-07-22 03:32:07 +00:00
const (
configurationSnippetAnnotation = "configuration-snippet"
)
var configurationSnippetAnnotations = parser . Annotation {
Group : "snippets" ,
Annotations : parser . AnnotationFields {
configurationSnippetAnnotation : {
Validator : parser . ValidateNull ,
Scope : parser . AnnotationScopeLocation ,
Risk : parser . AnnotationRiskCritical , // Critical, this annotation is not validated at all and allows arbitrary configutations
Documentation : ` This annotation allows setting a custom NGINX configuration on a location block. This annotation does not contain any validation and it's usage is not recommended! ` ,
} ,
} ,
}
2017-02-23 18:10:32 +00:00
type snippet struct {
2023-07-22 03:32:07 +00:00
r resolver . Resolver
annotationConfig parser . Annotation
2017-02-23 18:10:32 +00:00
}
// NewParser creates a new CORS annotation parser
2017-11-08 20:58:57 +00:00
func NewParser ( r resolver . Resolver ) parser . IngressAnnotation {
2023-07-22 03:32:07 +00:00
return snippet {
r : r ,
annotationConfig : configurationSnippetAnnotations ,
}
2017-02-23 18:10:32 +00:00
}
// Parse parses the annotations contained in the ingress rule
// used to indicate if the location/s contains a fragment of
// configuration to be included inside the paths of the rules
2019-06-09 22:49:59 +00:00
func ( a snippet ) Parse ( ing * networking . Ingress ) ( interface { } , error ) {
2023-07-22 03:32:07 +00:00
return parser . GetStringAnnotation ( configurationSnippetAnnotation , ing , a . annotationConfig . Annotations )
}
func ( a snippet ) GetDocumentation ( ) parser . AnnotationFields {
return a . annotationConfig . Annotations
}
func ( a snippet ) Validate ( anns map [ string ] string ) error {
maxrisk := parser . StringRiskToRisk ( a . r . GetSecurityConfiguration ( ) . AnnotationsRiskLevel )
return parser . CheckAnnotationRisk ( anns , maxrisk , configurationSnippetAnnotations . Annotations )
2017-02-23 18:10:32 +00:00
}