Files
cpp-httplib/test/proxy/docker-compose.yml
T
yhirose 88956ccad8 Self-host the httpbin auth-testing backend for BaseAuthTest/DigestAuthTest
These tests exercise the squid proxies by hitting /basic-auth and
/digest-auth on an external httpbin-style site. That site's identity has
already moved twice (httpbin.org -> httpcan.org, per #2300) chasing
uptime, and httpcan.org itself is now down (Cloudflare 502 from its
origin), failing CI with no code change involved.

Adds two containers to the existing squid docker-compose stack instead:
go-httpbin (mccutchen/go-httpbin) as the backend, and an nginx sidecar in
front of it under the single "httpbin" hostname so both the NoSSL tests
(port 80) and the SSL tests, which CONNECT-tunnel through the proxy to
port 443, resolve the same name -- go-httpbin only listens on one port at
a time, so it can't serve both protocols itself. nginx uses the repo's
existing self-signed test cert; the SSL client tests already disable
verification for it like other self-signed-cert tests in this suite.

go-httpbin was picked over the more feature-complete kennethreitz/httpbin
after finding the latter accepts a wrong digest-auth username as long as
the password matches -- confirmed with a direct curl against the
container, unrelated to anything in this repo. go-httpbin correctly
rejects both. The trade-off is losing SHA-512 digest-auth coverage here,
since go-httpbin only implements MD5 and SHA-256; nothing else in the
suite exercises SHA-512 digest auth against a live server. Response body
assertions are adjusted to go-httpbin's actual JSON shape (an added
"authorized" field, no "algorithm" field), and the domain changes from
httpcan.org to the self-hosted "httpbin".

This only affects 'make proxy'/'make proxy_mbedtls'/'make proxy_wolfssl'
and the Proxy Test CI workflow -- the default 'make' target is untouched.
2026-09-07 21:49:00 -04:00

42 lines
1.1 KiB
YAML

services:
squid_basic:
image: squid_basic
restart: always
ports:
- "3128:3128"
build:
context: ./
args:
auth: basic
squid_digest:
image: squid_digest
restart: always
ports:
- "3129:3129"
build:
context: ./
args:
auth: digest
# Self-hosted stand-in for the httpbin.org-style auth-testing endpoints
# (/basic-auth, /digest-auth) that BaseAuthTest/DigestAuthTest exercise
# through the proxies above, so those tests don't depend on an external
# site's uptime.
httpbin_backend:
image: mccutchen/go-httpbin:latest
restart: always
# TLS termination in front of httpbin_backend (which only speaks plain
# HTTP) so the SSL variants of those tests can CONNECT-tunnel through the
# proxies to "httpbin" on port 443, same as the NoSSL variants do on 80.
httpbin:
image: nginx:alpine
restart: always
depends_on:
- httpbin_backend
volumes:
- ./httpbin_nginx.conf:/etc/nginx/conf.d/default.conf:ro
- ../cert.pem:/etc/nginx/certs/cert.pem:ro
- ../key.pem:/etc/nginx/certs/key.pem:ro