접속 IP 를 제한하는 결제사 API 를 로컬·스테이징에서 연동하려면 서버가 내보내는 요청의 출발지 IP 를 바꿔야 한다. 브라우저 프록시로는 바뀌지 않는 축이라 코어 환경설정으로 도입한다. 게이트는 디버그 모드이며 판정은 OutboundProxy 한 곳이 소유한다. 화면의 조건부 렌더링은 편의일 뿐이라 저장 API 직접 호출을 막지 못하므로, 실질 게이트를 판정 지점에 둔다. 주입·적용 지점은 결과만 소비한다. 적용은 Http::globalOptions 전역 옵션이라 확장의 Http:: 호출까지 함께 경유한다. 외부 연동 규약상 curl 핸들을 직접 다뤄야 하는 확장은 OutboundProxy::curlOptions 로 같은 프록시를 탄다 — KG이니시스 본인인증 승인 요청과 CBT 연결 점검을 이 통로로 편입했다. CBT 의 TCP 443 확인은 원시 소켓으로는 프록시를 태울 수 없어 curl CONNECT_ONLY 로 교체했다. 저장 전 연결 테스트는 저장값이 아니라 제출값을 검사하고, 그 프록시를 거쳤을 때 외부에 보이는 IP 를 함께 보고한다. 운영자가 결제사에 등록할 값이라 저장하고 나서 되짚지 않도록 했다. 적용과 같은 조립을 거치므로 확인한 구성과 저장 후 적용되는 구성이 어긋나지 않는다.
77 lines
2.5 KiB
PHP
77 lines
2.5 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Requests\Settings;
|
|
|
|
use App\Extension\HookManager;
|
|
use App\Rules\ValidOutboundProxyUrl;
|
|
use Illuminate\Contracts\Validation\ValidationRule;
|
|
use Illuminate\Foundation\Http\FormRequest;
|
|
|
|
/**
|
|
* 아웃바운드 프록시 연결 테스트 요청 검증
|
|
*
|
|
* 저장 전에 확인하는 것이 목적이므로 검사 대상은 저장된 설정이 아니라 이번에 제출된 값입니다.
|
|
* 검증 강도는 저장 경로(SaveSettingsRequest)와 같게 둡니다 — 테스트만 통과하고 저장에서
|
|
* 거부되거나 그 반대가 되면 운영자가 어느 쪽을 믿어야 할지 알 수 없습니다.
|
|
*
|
|
* @since 7.1.0
|
|
*/
|
|
class TestOutboundProxyRequest extends FormRequest
|
|
{
|
|
/**
|
|
* 권한 검사는 permission 미들웨어가 담당합니다.
|
|
*
|
|
* @return bool 항상 true
|
|
*/
|
|
public function authorize(): bool
|
|
{
|
|
return true;
|
|
}
|
|
|
|
/**
|
|
* Get the validation rules that apply to the request.
|
|
*
|
|
* @return array<string, ValidationRule|array<mixed>|string>
|
|
*/
|
|
public function rules(): array
|
|
{
|
|
$rules = [
|
|
'outbound_proxy' => ['required', 'string', 'max:500', new ValidOutboundProxyUrl],
|
|
'outbound_proxy_bypass' => ['nullable', 'array'],
|
|
'outbound_proxy_bypass.*' => ['string', 'max:255'],
|
|
];
|
|
|
|
return HookManager::applyFilters('core.settings.test_outbound_proxy_validation_rules', $rules, $this);
|
|
}
|
|
|
|
/**
|
|
* 검증 실패 메시지를 반환합니다.
|
|
*
|
|
* @return array<string, string>
|
|
*/
|
|
public function messages(): array
|
|
{
|
|
return [
|
|
'outbound_proxy.required' => __('validation.settings.outbound_proxy_required'),
|
|
'outbound_proxy.string' => __('validation.settings.outbound_proxy_string'),
|
|
'outbound_proxy.max' => __('validation.settings.outbound_proxy_max'),
|
|
'outbound_proxy_bypass.array' => __('validation.settings.outbound_proxy_bypass_array'),
|
|
'outbound_proxy_bypass.*.string' => __('validation.settings.outbound_proxy_bypass_item_string'),
|
|
'outbound_proxy_bypass.*.max' => __('validation.settings.outbound_proxy_bypass_item_max'),
|
|
];
|
|
}
|
|
|
|
/**
|
|
* 검증 속성명을 반환합니다.
|
|
*
|
|
* @return array<string, string>
|
|
*/
|
|
public function attributes(): array
|
|
{
|
|
return [
|
|
'outbound_proxy' => __('validation.attributes.outbound_proxy'),
|
|
'outbound_proxy_bypass' => __('validation.attributes.outbound_proxy_bypass'),
|
|
];
|
|
}
|
|
}
|