Skip to content

Topic

Header-Based Authorization

An access-control pattern in which an upstream component authenticates a request and records the outcome in an HTTP header that downstream routers and services then trust.

Current clusters

build1 publisher

Spoofed admin headers hit Traefik's catchall 500 times out of 500

Traefik 3.6's release material says child routers cannot be called directly. A test on 3.6.25 sent the exact header a child router matches, on a path outside the parent prefix, 500 times, and none of it reached the admin service.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+12
Incentives22
Confidence58