I have an HAProxy in front of my application. I have TLS passthrough on the proxy and I'm doing termination at the app layer.
If the authorization is missing or invalid, I simply redirect with a 302 to my auth subdomain, which presents the user with a login page.
func unauthorizedPage(logger *zap.Logger, w http.ResponseWriter, req *http.Request) {
logger.Error("The user is not authorized to make this request - referring",
zap.String("refer", req.Host+req.URL.Path))
b64Url := b64.StdEncoding.EncodeToString([]byte(req.Host + req.URL.Path))
http.Redirect(w,
req,
fmt.Sprintf("https://auth.my-site.com:443?refer=%s", b64Url),
http.StatusFound)
}
My network is showing 23 requests and then the browser is throwing me a The page isn’t redirecting properly error.
The page it loads is just a simple JS login page (no redirects). How is it possible for this to happen?