mirror of
https://github.com/kataras/iris.git
synced 2026-01-09 13:05:56 +00:00
As the default value is TLS 1.0, which is considered insecure, it is recommended to explicitly set the MinVersion to a secure version of TLS
This commit is contained in:
@@ -22,7 +22,7 @@ import (
|
||||
// Look `ProxyHandlerRemote` too.
|
||||
func ProxyHandler(target *url.URL, config *tls.Config) *httputil.ReverseProxy {
|
||||
if config == nil {
|
||||
config = &tls.Config{}
|
||||
config = &tls.Config{MinVersion: tls.VersionTLS11}
|
||||
}
|
||||
|
||||
director := func(req *http.Request) {
|
||||
@@ -89,7 +89,7 @@ func modifyProxiedRequest(req *http.Request, target *url.URL) {
|
||||
// Look `ProxyHandler` too.
|
||||
func ProxyHandlerRemote(target *url.URL, config *tls.Config) *httputil.ReverseProxy {
|
||||
if config == nil {
|
||||
config = &tls.Config{}
|
||||
config = &tls.Config{MinVersion: tls.VersionTLS11}
|
||||
}
|
||||
|
||||
director := func(req *http.Request) {
|
||||
|
||||
@@ -27,6 +27,7 @@ func TestProxy(t *testing.T) {
|
||||
|
||||
config := &tls.Config{
|
||||
InsecureSkipVerify: true,
|
||||
MinVersion: tls.VersionTLS11,
|
||||
MaxVersion: tls.VersionTLS12,
|
||||
}
|
||||
proxy := host.NewProxy("", u, config)
|
||||
|
||||
@@ -25,7 +25,7 @@ func newTester(t *testing.T, baseURL string, handler http.Handler) *httpexpect.E
|
||||
|
||||
if strings.HasPrefix(baseURL, "http") { // means we are testing real serve time
|
||||
transporter = &http.Transport{
|
||||
TLSClientConfig: &tls.Config{InsecureSkipVerify: true},
|
||||
TLSClientConfig: &tls.Config{InsecureSkipVerify: true, MinVersion: tls.VersionTLS11},
|
||||
}
|
||||
} else { // means we are testing the handler itself
|
||||
transporter = httpexpect.NewBinder(handler)
|
||||
|
||||
Reference in New Issue
Block a user