From 2dd5ffa8fd7fb5c626775af7456886490d6e4c3c Mon Sep 17 00:00:00 2001 From: kjdev Date: Mon, 31 Aug 2026 13:02:16 +0900 Subject: [PATCH 1/2] feat: register PRECONTENT handler via nxe-phase priority ordering The auth_rbac handler was registered on NGX_HTTP_PRECONTENT_PHASE with a plain ngx_array_push(), so its execution order relative to other same-phase modules (auth-gate, auth-cedar, internal-redirect) was whatever the reverse of --add-module/load_module ordering happened to produce, not something a config author could control. Vendor the shared nxe-phase submodule and register the handler with nxe_phase_add_handler(cf, NGX_HTTP_PRECONTENT_PHASE, NXE_PHASE_PRIO_RBAC, ngx_http_auth_rbac_handler, "auth_rbac"), matching the same migration already done in nginx-auth-cedar. Priority 750 places it after auth-gate (600) and auth-cedar (700), before internal-redirect (900). No return-value change is needed: the handler already returns NGX_DECLINED on both allow and deny paths. --- .gitmodules | 3 +++ Dockerfile | 1 + config | 22 +++++++++++++++++++--- nxe-phase | 1 + src/ngx_http_auth_rbac_module.c | 15 +++++++-------- 5 files changed, 31 insertions(+), 11 deletions(-) create mode 160000 nxe-phase diff --git a/.gitmodules b/.gitmodules index f5174b7..f4a6da4 100644 --- a/.gitmodules +++ b/.gitmodules @@ -1,3 +1,6 @@ [submodule "nxe-json"] path = nxe-json url = https://github.com/kjdev/nxe-json.git +[submodule "nxe-phase"] + path = nxe-phase + url = https://github.com/kjdev/nxe-phase.git diff --git a/Dockerfile b/Dockerfile index d36325c..4e7d5cd 100644 --- a/Dockerfile +++ b/Dockerfile @@ -31,6 +31,7 @@ EOS COPY config /build/ COPY src/ /build/src/ COPY nxe-json/ /build/nxe-json/ +COPY nxe-phase/ /build/nxe-phase/ WORKDIR /build/nginx RUN sh -ex <<'EOS' diff --git a/config b/config index aca86eb..fc22a42 100644 --- a/config +++ b/config @@ -1,23 +1,39 @@ ngx_addon_name=ngx_http_auth_rbac_module +# --- submodule: nxe-phase --- +nxe_phase_dir="$ngx_addon_dir/nxe-phase" +nxe_phase_tag="auth_rbac" + +if [ ! -f "$nxe_phase_dir/config.ngx" ]; then + echo "$0: error: $nxe_phase_dir/config.ngx not found" >&2 + exit 1 +fi + +. "$nxe_phase_dir/config.ngx" + ngx_module_type=HTTP -ngx_module_name="ngx_http_auth_rbac_module" +ngx_module_name="ngx_http_auth_rbac_module $nxe_phase_module_name" ngx_module_deps="\ + $nxe_phase_module_deps \ $ngx_addon_dir/src/ngx_http_auth_rbac_module.h \ $ngx_addon_dir/src/ngx_rbac_policy.h \ $ngx_addon_dir/src/ngx_rbac_matcher.h \ $ngx_addon_dir/src/ngx_rbac_role.h \ $ngx_addon_dir/src/ngx_rbac_variable.h \ " -ngx_module_incs="$ngx_addon_dir/src" +ngx_module_incs="\ + $nxe_phase_module_incs \ + $ngx_addon_dir/src \ +" ngx_module_srcs="\ + $nxe_phase_module_srcs \ $ngx_addon_dir/src/ngx_http_auth_rbac_module.c \ $ngx_addon_dir/src/ngx_rbac_policy.c \ $ngx_addon_dir/src/ngx_rbac_matcher.c \ $ngx_addon_dir/src/ngx_rbac_role.c \ $ngx_addon_dir/src/ngx_rbac_variable.c \ " -ngx_module_libs="" +ngx_module_libs="$nxe_phase_module_libs" # JSON role parsing via nxe-json (requires jansson). # Controlled by NGX_RBAC_JSON: diff --git a/nxe-phase b/nxe-phase new file mode 160000 index 0000000..d5ed785 --- /dev/null +++ b/nxe-phase @@ -0,0 +1 @@ +Subproject commit d5ed785c8f41272d23f6e47e750a20ccdd17ef42 diff --git a/src/ngx_http_auth_rbac_module.c b/src/ngx_http_auth_rbac_module.c index 856ec69..cc4d967 100644 --- a/src/ngx_http_auth_rbac_module.c +++ b/src/ngx_http_auth_rbac_module.c @@ -5,6 +5,8 @@ * nginx RBAC (Role-Based Access Control) module */ +#include "nxe_phase.h" + #include "ngx_http_auth_rbac_module.h" #include "ngx_rbac_policy.h" #include "ngx_rbac_matcher.h" @@ -226,19 +228,16 @@ ngx_http_auth_rbac_merge_loc_conf(ngx_conf_t *cf, void *parent, void *child) static ngx_int_t ngx_http_auth_rbac_init(ngx_conf_t *cf) { - ngx_http_handler_pt *h; - ngx_http_core_main_conf_t *cmcf; ngx_http_variable_t *var, *v; - cmcf = ngx_http_conf_get_module_main_conf(cf, ngx_http_core_module); - - h = ngx_array_push(&cmcf->phases[NGX_HTTP_PRECONTENT_PHASE].handlers); - if (h == NULL) { + if (nxe_phase_add_handler(cf, NGX_HTTP_PRECONTENT_PHASE, + NXE_PHASE_PRIO_RBAC, ngx_http_auth_rbac_handler, + "auth_rbac") + != NGX_OK) + { return NGX_ERROR; } - *h = ngx_http_auth_rbac_handler; - /* Register variables */ for (v = ngx_http_auth_rbac_vars; v->name.len; v++) { var = ngx_http_add_variable(cf, &v->name, v->flags); From 645af0f01cd42da3a656e8a327f3118cec266db1 Mon Sep 17 00:00:00 2001 From: kjdev Date: Mon, 31 Aug 2026 13:02:18 +0900 Subject: [PATCH 2/2] docs(CHANGELOG): note nxe-phase priority-based handler registration --- CHANGELOG.md | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 83be919..700ddc9 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,16 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this project adheres to [Semantic Versioning](https://semver.org/). +## [Unreleased] + +### Changed + +- The module now registers its PRECONTENT-phase handler at a fixed priority via the new `nxe-phase` submodule instead of relying on module load order, so its position relative to other dynamic modules sharing the same phase (`auth_gate`, `auth_cedar`, `internal_redirect`, ...) no longer depends on `load_module` ordering in `nginx.conf` + +### Dependencies + +- Add the `nxe-phase` submodule (shared phase-handler-ordering helper) + ## [0.2.1] - 2026-06-04 ### Dependencies