| Merge commit from fork Add a node_id check to kong/clustering/rpc/manager.lua and kong/clustering/control_plane.lua. Add a hostname format check to prevent potential injection vulnerabilities. [FTI-7219]!(https://konghq.atlassian.net/browse/FTI-7219) (cherry picked from commit dfd4f41) Signed-off-by: zhen.zhong <zhen.zhong@konghq.com> | 11 天前 |
| Merge commit from fork removing the inbound content-length header will cause CL.0 request smuggling, because the body is treated as zero length. https://konghq.atlassian.net/browse/FTI-7377 tests(core): add more tests for hop-by-hop header related smuggling Co-authored-by: Zhefeng Chen <chzf_zju@163.com> | 11 天前 |
| fix(ai-proxy): OpenAI chat completion's tool_choice was not converted to Anthropic's (#14694) Signed-off-by: Zexuan Luo <zexuan.luo@konghq.com> | 11 个月前 |
| perf(*): faster string splitting and an iterator (#14388) ### Summary On my testing the `splitn` implemented here is about 10x faster than the Penlight's `stringx.split`. splitn: 193 ms (new function) isplitn: 379 ms (iterator over splitn) split: 1638 ms (penlight) re.split: 1072 ms (ngx.re) I also tested implementing `isplit` iterator without splitn and table allocation, but in my testing that didn't yield better performance. Signed-off-by: Aapo Talvensaari <aapo.talvensaari@gmail.com> | 1 年前 |
| fix(clustering/sync): use 8 bytes integer to store delta's versions (#14321) KAG-6427 --------- Co-authored-by: Chrono <chrono_cpp@me.com> | 1 年前 |
| feat(plugin/redirect): plugin to redirect requests to a new location (#13900) * feat(plugin/redirect): plugin to redirect requests to a new location * feat(plugin/redirect): remove the "merge" strategy | 1 年前 |
| tests(vault): fix mockbin.org issue (#14872) * tests(vault): remove external dependency on mockbin.org (#17194) * tests(vault): add HTTP request in mock vault get() to simulate (#17309) KAG-8720 --------- Co-authored-by: hanjian <hanjian.liu@konghq.com> | 4 个月前 |
| tests(clustering): rpc test framework (#14030) KAG-5551 | 1 年前 |
| chore(spec): generate_keys supports EC key (#14184) | 1 年前 |
| docs(spec/README): fix incorrect environment variable name | 3 年前 |
| tests(*): shutdown timerng instance after test completion (#14005) | 1 年前 |
| tests(helpers): rename directory `details` to `internal` (#13665) https://konghq.atlassian.net/browse/KAG-5330 | 2 年前 |
| refactor(pluginservers): code refactor & testing (#12858) Context ------- The overall goal of this commit is to refactor the external plugins implementation, with the following goals in mind: - Make plugin server code more approachable to unfamiliar engineers and easier to evolve with confidence - Harden configuration; ensure configuration defects are caught before Kong is started - Extend testing coverage This is related to ongoing work on the Go PDK, with similar goals in mind. Summary ------- This commit implements the following overall changes to plugin server code: - Move configuration related code into conf loader, so that configuration loading and validation happens at startup time, rather than lazily, when plugin data is loaded or pluginservers are started. Add tests for current behavior. - Move process-management code - for starting up plugin servers as well as querying external plugins info - into the `process.lua` module. - Introduce a `kong.runloop.plugin_servers.rpc` module that encapsulates RPC initialization and protocol-specific implementations. This further simplifies the main plugin server main module. - Factor exposed API and phase handlers bridging code into a new `plugin` module, which encapsulates an external plugin representation, including the expected fields for any Kong plugin, plus external plugin-specific bits, such as the RPC instance. Part of this external plugin-specific part is the instance life cycle management. With this structure, the `kong.runloop.plugin_servers` main module contains only general external plugin code, including a list of loaded external plugins, and associated start/stop functions for plugin servers. Testing ------- This commit also implements the following improvements to tests: - Restructure fixtures to accommodate new external plugin servers -- namely, targeting for now in the existing Python and Javascript - Add new test cases for external plugins: * External plugin configuration: add test cases for current behavior; in particular: - Fail if no `query_cmd` is provided; - Warn if no `start_cmd` is provided - this is by design, as external plugins servers can be managed outside of Kong * Plugin server start / stop - for both Go and Python plugins * External plugin info querying for both Go and Python plugins * External plugin execution - for both Go and Python plugins Internal flow ------------- `.plugin_servers.init:` loads all external plugins, by calling .plugin_servers.process and `.plugin_servers.plugin` `.plugin_servers.process`: queries external plugins info with the command specified in `_query_cmd` proeprties `.plugin_servers.plugin`: with info obtained as described above, `.plugin:new` returns a kong-compatible representation of an external plugin, with phase handlers, PRIORITY, and wrappers to the PDK. Calls `.plugin_servers.rpc` to create an RPC through which Kong communicates with the plugin process `.plugin_servers.rpc`: based on info contained in the plugin (protocol field), creates the correct RPC for the given external plugin `.plugin_servers.rpc.pb_rpc`: protobuf rpc implementation - used by Golang `.plugin_servers.rpc.mp.rpc`: messagepack rpc implementation - used by JS and Python `.plugin_servers.init`: calls `.plugin_servers.process` to start external plugin servers `.plugin_servers.process`: optionally starts all external plugin servers (if a `_start_cmd` is found) uses the resty pipe API to manage the external plugin process | 1 年前 |
| tests(clustering/sync): add hybrid mode test for most used plugins (#14328) KAG-6446 | 1 年前 |
| chore(build): remove ngx_wasm_module from default builds (#14347) | 1 年前 |
| chore(docs) add setup for development doc generation | 6 年前 |
| test(integration): re-enable some tests by renaming their filename (#9906) Co-authored-by: Michael Martin <flrgh@protonmail.com> | 3 年前 |
| fix(http_mock): bug fixes and add tapping feature (#11182) Introduce tapping for testing, especially OIDC's behavior when sending requests to IDP. - assert in mock server do not return truthy value which fails l`ocal v=assert(f())` - add aliases `has_one_without_*` for `not_all_* `assertions - more strict error handling - fix some issues on docs rendering Co-authored-by: Thijs Schreijer <thijs@thijsschreijer.nl> | 3 年前 |
| fix(*): drop luasocket in cli (#11177) This is the follow-up PR of https://github.com/Kong/kong/pull/11127 Changing the socket type from luasocket to openresty cosocket causes some test fail weirdly. After investigating, it's mainly because the cosocket support yield and setkeepalive. See the comments in tests. FTI-4937 | 3 年前 |
| fix(opentelemetry): increase default queue batch size migration to update the wrongly set default queue batch size to 200 adapt test to run only for 3.x | 2 年前 |