Re: Zope 2 WSGI investigation

Marius Gedminas <[email protected]>
Newsgroups gmane.comp.web.zope.devel
Message-ID <20120109114436.GA18285@platonas>
On Mon, Jan 09, 2012 at 10:01:29AM +0100, Sylvain Viollon wrote:
> Op 8 jan 2012, om 16:36 heeft Laurence Rowe het volgende geschreven:
> > On 3 January 2012 08:34, Sylvain Viollon <[email protected]> wrote:
> >> Op 1 jan 2012, om 20:39 heeft Martin Aspeli het volgende geschreven:
> 
> [...]
> 
> >>> 
> >>> * Supports simplified virtual hosting with X-VHM-Host
> >> 
> >>  That is not completely true. I support setting the hostname,
> >>  however to set a virtual path, you need to do this during
> >>  traversing, which is done in BaseRequest, that I don't change
> >>  (because it is a big large blob of code where you cannot really
> >>  plug anything in it, or change only a few line in it without
> >>  changing everything).
> >> 
> >>  In production we use mod_rewrite to rewrite the URL with an old
> >>  VirtualHostMonster url and pass it to mod_wsgi with the help of
> >>  the flags PT.
> > 
> > What advantage is there to setting the X-VHM-Host header over just
> > setting the Host header?
> 
>    You can't set a virtual path with the Host header, it is not valid
>    if you want to follow the RFC.  After as well, you can include the
>    port in it, but I think you are not sure if you can't really know
>    if you should create https URL or not, you don't have this
>    information (this is not required only to be on port 443, and if it
>    is I am not even sure the port is correctly added in the Host
>    header).

In the WSGI world it's usual to use the X-Forwarded-Scheme header to
determine the scheme (http or https), AFAIU.

See e.g. http://pythonpaste.org/wsgiproxy/#the-proxy
http://pythonpaste.org/deploy/modules/config.html#paste.deploy.config.PrefixMiddleware
http://packages.python.org/Deliverance/proxy.html
http://docs.pylonsproject.org/projects/pyramid_cookbook/en/latest/deployment/nginx.html

>    I think it would be safer to have a separate header for all this
>    information, and not touching the Host headers, that applications
>    might expect to be correct.
> 
>    Regards,
> 
>    Sylvain,
> 
> http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.23
> http://www.ietf.org/rfc/rfc2818.txt

Marius Gedminas
-- 
http://pov.lt/ -- Zope 3/BlueBream consulting and development

_______________________________________________
Zope-Dev maillist  -  [email protected]
https://mail.zope.org/mailman/listinfo/zope-dev
**  No cross posts or HTML encoding!  **
(Related lists -
 https://mail.zope.org/mailman/listinfo/zope-announce
 https://mail.zope.org/mailman/listinfo/zope )
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk8K0yQACgkQkVdEXeem148f1wCeKckAYjte/lTnXSEtZTmwnxZF
qrgAn3sCDMieG5LKH8m/7sh54P1jxGUw
=rBmB
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.