From 1d5e536496c8355ea07aba1f69ae26792e0dff5f Mon Sep 17 00:00:00 2001 From: kjdev Date: Tue, 1 Sep 2026 06:07:15 +0900 Subject: [PATCH 1/2] feat: register phase handlers via nxe-phase for deterministic ordering Add the nxe-phase submodule and register the PREACCESS/ACCESS phase handlers through nxe_phase_add_handler() instead of a direct ngx_array_push(). This fixes execution order relative to other same-phase modules being dependent on --add-module/load_module order. --- .gitmodules | 3 +++ Dockerfile | 1 + config | 18 ++++++++++++++-- nxe-phase | 1 + src/ngx_http_auth_oauth2_token_module.c | 28 +++++++++++-------------- 5 files changed, 33 insertions(+), 18 deletions(-) create mode 160000 nxe-phase diff --git a/.gitmodules b/.gitmodules index f5174b7..f4a6da4 100644 --- a/.gitmodules +++ b/.gitmodules @@ -1,3 +1,6 @@ [submodule "nxe-json"] path = nxe-json url = https://github.com/kjdev/nxe-json.git +[submodule "nxe-phase"] + path = nxe-phase + url = https://github.com/kjdev/nxe-phase.git diff --git a/Dockerfile b/Dockerfile index 62a92ce..1880de9 100644 --- a/Dockerfile +++ b/Dockerfile @@ -30,6 +30,7 @@ EOS COPY config /build/ COPY src/ /build/src/ COPY nxe-json/ /build/nxe-json/ +COPY nxe-phase/ /build/nxe-phase/ WORKDIR /build/nginx RUN sh -ex <<'EOS' diff --git a/config b/config index 3ac2efa..4bbbcba 100644 --- a/config +++ b/config @@ -10,11 +10,23 @@ fi . "$nxe_json_dir/config.ngx" +# --- submodule: nxe-phase --- +nxe_phase_dir="$ngx_addon_dir/nxe-phase" +nxe_phase_tag="auth_oauth2_token" + +if [ ! -f "$nxe_phase_dir/config.ngx" ]; then + echo "$0: error: $nxe_phase_dir/config.ngx not found" >&2 + exit 1 +fi + +. "$nxe_phase_dir/config.ngx" + # --- module definition --- ngx_module_type=HTTP -ngx_module_name="ngx_http_auth_oauth2_token_module" +ngx_module_name="ngx_http_auth_oauth2_token_module $nxe_phase_module_name" ngx_module_deps="\ $nxe_json_module_deps \ + $nxe_phase_module_deps \ $ngx_addon_dir/src/ngx_http_auth_oauth2_token_module.h \ $ngx_addon_dir/src/ngx_auth_oauth2_token_introspect.h \ $ngx_addon_dir/src/ngx_auth_oauth2_token_exchange.h \ @@ -23,16 +35,18 @@ ngx_module_deps="\ " ngx_module_incs="\ $nxe_json_module_incs \ + $nxe_phase_module_incs \ $ngx_addon_dir/src \ " ngx_module_srcs="\ $nxe_json_module_srcs \ + $nxe_phase_module_srcs \ $ngx_addon_dir/src/ngx_http_auth_oauth2_token_module.c \ $ngx_addon_dir/src/ngx_auth_oauth2_token_introspect.c \ $ngx_addon_dir/src/ngx_auth_oauth2_token_exchange.c \ $ngx_addon_dir/src/ngx_auth_oauth2_token_http.c \ $ngx_addon_dir/src/ngx_auth_oauth2_token_cache.c \ " -ngx_module_libs="$nxe_json_module_libs" +ngx_module_libs="$nxe_json_module_libs $nxe_phase_module_libs" . auto/module diff --git a/nxe-phase b/nxe-phase new file mode 160000 index 0000000..d5ed785 --- /dev/null +++ b/nxe-phase @@ -0,0 +1 @@ +Subproject commit d5ed785c8f41272d23f6e47e750a20ccdd17ef42 diff --git a/src/ngx_http_auth_oauth2_token_module.c b/src/ngx_http_auth_oauth2_token_module.c index 037497b..c415d0d 100644 --- a/src/ngx_http_auth_oauth2_token_module.c +++ b/src/ngx_http_auth_oauth2_token_module.c @@ -7,6 +7,8 @@ #include #include +#include + #include "ngx_http_auth_oauth2_token_module.h" #include "ngx_auth_oauth2_token_introspect.h" #include "ngx_auth_oauth2_token_exchange.h" @@ -320,28 +322,22 @@ ngx_http_auth_oauth2_token_pre_conf(ngx_conf_t *cf) static ngx_int_t ngx_http_auth_oauth2_token_post_conf(ngx_conf_t *cf) { - ngx_http_handler_pt *h; - ngx_http_core_main_conf_t *cmcf; - - cmcf = ngx_http_conf_get_module_main_conf(cf, - ngx_http_core_module); - - h = ngx_array_push( - &cmcf->phases[NGX_HTTP_PREACCESS_PHASE].handlers); - if (h == NULL) { + if (nxe_phase_add_handler(cf, NGX_HTTP_PREACCESS_PHASE, + NXE_PHASE_PRIO_OAUTH2_TOKEN, + ngx_http_auth_oauth2_token_preaccess_handler, + "auth_oauth2_token") != NGX_OK) + { return NGX_ERROR; } - *h = ngx_http_auth_oauth2_token_preaccess_handler; - - h = ngx_array_push( - &cmcf->phases[NGX_HTTP_ACCESS_PHASE].handlers); - if (h == NULL) { + if (nxe_phase_add_handler(cf, NGX_HTTP_ACCESS_PHASE, + NXE_PHASE_PRIO_OAUTH2_TOKEN, + ngx_http_auth_oauth2_token_access_handler, + "auth_oauth2_token") != NGX_OK) + { return NGX_ERROR; } - *h = ngx_http_auth_oauth2_token_access_handler; - return NGX_OK; } From b72392842d8b2040914fe6ea4841db05a0704344 Mon Sep 17 00:00:00 2001 From: kjdev Date: Tue, 1 Sep 2026 06:07:18 +0900 Subject: [PATCH 2/2] docs(CHANGELOG): note nxe-phase submodule dependency --- CHANGELOG.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 67ea8e9..0e2d7ab 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/). ## [Unreleased] +### Dependencies + +- Add the `nxe-phase` submodule and register the PREACCESS/ACCESS phase handlers through `nxe_phase_add_handler()` (priority `NXE_PHASE_PRIO_OAUTH2_TOKEN` = 250) instead of a direct `ngx_array_push()`. nginx's `ngx_http_init_phase_handlers()` walks each phase's handler array tail-to-head, so the previous direct push made this module's execution order relative to other same-phase modules (e.g. auth-jwt, auth-apikey) depend on `--add-module` / `load_module` order rather than on `nginx.conf`. With `nxe-phase`, the order is fixed by the shared priority band regardless of build/load order. + ## [0.5.0] - 2026-07-13 ### Added