Class GuardAction
java.lang.Object
org.frontcache.guard.GuardAction
What a matching guard rule does with the request: reject it, redirect it, or explicitly let it
through (an exemption placed above a broader rule).
-
Nested Class Summary
Nested Classes -
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptionstatic GuardActionallow()getBody()intgetType()static GuardActionstatic GuardActionstatic StringrequestURL(RequestContext context) Full request URL, as the client would have to type it to get back here.resolveTarget(RequestContext context) Expands ${uri} / ${query} / ${url} / ${url:enc} / ${host} in the redirect target.toString()
-
Field Details
-
DISPOSITION_REJECTED
disposition written to the failed-requests log (the is_cached column)- See Also:
-
DISPOSITION_REDIRECTED
- See Also:
-
DISPOSITION_DRY_RUN
- See Also:
-
-
Method Details
-
reject
-
redirect
-
allow
-
getType
-
getStatus
public int getStatus() -
getBody
-
getTarget
- Returns:
- redirect target as configured, placeholders NOT expanded
-
getDisposition
- Returns:
- the disposition string for the log line, or null for ALLOW (not logged)
-
resolveTarget
Expands ${uri} / ${query} / ${url} / ${url:enc} / ${host} in the redirect target.- Parameters:
context- current request- Returns:
- target ready for the Location header
-
requestURL
Full request URL, as the client would have to type it to get back here. Built here rather than taken from RequestContext.getCurrentRequestURL(), which FrontCacheEngine only populates later and only for cacheable requests - guards run before that. Note the two independent substitutions relative to what the socket saw: the host (seepublicHost(RequestContext)) and the scheme. Behind a TLS-terminating proxy the connection reaching this process is plaintext, so the scheme comes from RequestContext.getPublicProtocol() (X-Forwarded-Proto from a trusted peer, or front-cache.public-scheme) and only then from the connection. On the hobbyray edges roughly one request in ten arrived over the plaintext leg, and each one produced an http:// return URL for an https-only site. -
toString
-