https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=12620
--- Comment #22 from Adolfo Rodríguez Taboada <[email protected]> --- Hi David, Thanks for catching this in comment #18 — koha-conf.xml is clearly a stronger boundary than a system preference, so I've gone ahead and made the change. Attached three patches (the first obsoletes 201633, which is the same base fix just rebased): * Bug 12620: Proxy Add-on for Koha z39.50/SRU servers — the base patch, rebased onto current main. * Bug 12620: (follow-up) Move HttpForwardProxy from a system preference to koha-conf.xml — removes the syspref entirely (sysprefs.sql, web_services.pref, the atomicupdate), adds a documented http_forward_proxy entry to koha-conf.xml, and updates C4::Breeding::_create_connection / admin/z3950servers.pl / z3950servers.tt to read it from C4::Context->config instead of Koha.Preference. The per-server do_not_use_proxy checkbox/column is unchanged. * Bug 12620: (QA follow-up) Add test coverage for http_forward_proxy — _create_connection had no test coverage at all for the proxy branch, for either the syspref or the config version. Added 4 assertions mocking ZOOM::Connection::connect and C4::Context->config. Tested manually too: without http_forward_proxy set, the checkbox doesn't show and there's no proxy attempt; with it pointed at a local Squid allowing CONNECT to port 210, a real Z39.50 search tunnels through it (confirmed in Squid's access log); with "Do not use proxy" checked, the connection goes direct. One thing for the record, not to argue against making the change — koha-conf.xml is the right call either way: HttpForwardProxy as a syspref was already gated behind the parameters permission, not editable by just any logged-in user. The real difference is "staff with syspref admin rights via the web UI" vs "someone with actual server/filesystem access", which is a meaningful drop in blast radius, but it wasn't wide open before either. Worth keeping in mind since staff with syspref access already have plenty of other preferences that could do comparable damage if misused (arbitrary URLs, LDAP config, etc.) — this closes one more of those doors, it's not the only one standing open. Let me know if this addresses your concern or if you'd like anything else changed before a signoff. Thanks, Adolfo -- You are receiving this mail because: You are watching all bug changes. _______________________________________________ Koha-bugs mailing list -- [email protected] To unsubscribe send an email to [email protected] website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
