Skip to content

out_opensearch: limit what a host placeholder can expand to - #192

Merged
Watson1978 merged 1 commit into
mainfrom
fix-host
Oct 7, 2026
Merged

Watson1978 merged 1 commit into
mainfrom
fix-host

Conversation

@kenhys

@kenhys kenhys commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Before: A placeholder in host/hosts was expanded and passed to the connection options as is. So a tag or a record field could add a host with ",", userinfo with "@" or a path with "/". The configured user, password and custom_headers were then sent to that host.

After: Each placeholder value is checked before the whole setting is expanded, so a value can only fill in a host name and a port. The rest of the setting, such as the "," between hosts or a scheme, userinfo and path the operator wrote, is left as it is. A placeholder used together with credentials logs a warning at startup.

@kenhys
kenhys marked this pull request as ready for review September 17, 2026 01:35
@kenhys
kenhys requested a review from Watson1978 September 17, 2026 01:35
Comment thread lib/fluent/plugin/out_opensearch.rb Outdated
Comment thread lib/fluent/plugin/out_opensearch.rb
Comment thread lib/fluent/plugin/out_opensearch.rb
Before: a placeholder in `host`/`hosts` was expanded as is, so a tag or
a record field could add a host with ",", userinfo with "@" or a path
with "/", move the request to another domain, or drop the host with an
empty value. The configured user, password and custom_headers were then
sent to that host.

After: each value is checked before the setting is expanded, so it can
only fill in the part of a host name that the placeholder stands for:
one label, a sub domain of a domain that the operator fixed with two or
more names, or a whole host name with a port. An IPv6 address is allowed
where the operator wrote the "[]" or the scheme that `URI()` needs. A
placeholder used with credentials also logs a warning at startup, and
the README asks for a fixed domain that the operator controls, because
two fixed names alone do not make a destination trusted.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>

@Watson1978 Watson1978 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍🏻

@Watson1978
Watson1978 merged commit d7426ce into main Oct 7, 2026
23 checks passed
@Watson1978
Watson1978 deleted the fix-host branch October 7, 2026 05:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants