# Need help with intercepting a 301 redirect

**URL:** <https://discuss.pomerium.com/t/need-help-with-intercepting-a-301-redirect/233>\
**Category:** Support\
**Created:** [January 23, 2023, 1:06pm UTC](https://discuss.pomerium.com/t/need-help-with-intercepting-a-301-redirect/233 "2023-01-23T13:06:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![torch](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@torch](https://discuss.pomerium.com/u/torch)\
**Post date:** [January 23, 2023, 1:06pm UTC](https://discuss.pomerium.com/t/need-help-with-intercepting-a-301-redirect/233/1 "2023-01-23T13:06:49Z")

</div>

## I’m struggling to intercept a redirect from a backend site.

I have a route from  
`https://example.pomerium.mydomain.com`  
to  
`https://test.example.com`  
Normally, when I access `something.example.com`, I will be redirected to either

`/login`  
or  
`/app/` (when I’m already logged in)

But when I access `https://example.pomerium.mydomain.com`

I get a 301 redirect to `https://test.example.com/app/`, which puts me “outside” Pomerium again

If I’m not logged in, I’m redirected to /login, which initially doesn’t work, but I got around it with a response header rewrite:

```auto
  rewrite_response_headers:
  - header: Location
    prefix: https://test.example.com/login
    value: http://example.pomerium.mydomain.com/login

```

Now if I access /app directly, everything seems to work:  
`https://example.pomerium.mydomain.com/app/`

But I would like to not have to instruct the users to manually include /app/  
I experimented with path\_redirect and some other redirects, but while the config doesn’t break ( I can start the application), it also doesn’t seem to work the way I want it to.

## What did you expect to happen?

I expected Pomerium to “catch” the redirect and translate it to `https://example.pomerium.mydomain.com/app/`

## What’s your environment like?

- Pomerium version (retrieve with `pomerium --version`): 0.20.0-1668445494+9413123c
- Server Operating System/Architecture/Cloud: RHEL 8.7

## What’s your config.yaml?

```auto
routes:
- from: https://example.pomerium.mydomain.com
  to: https://test.example.com
  rewrite_response_headers:
  - header: Location
    prefix: https://test.example.com/login
    value: http://example.pomerium.mydomain.com/login
  policy:
  - allow:
      or:
      - domain:
          is: mydomain.com
  redirect:
    path: /
    path_redirect: /app/

```

## What did you see in the logs?

```logs
Nothing useful in the logs

```

## Additional context

Are there any examples as to how to configure the redirects? I struggle to make sense of the docs for this feature:

- `path_redirect` (string): the incoming path portion of the URL will be swapped with the given value.  
Does this mean that ANY path after the host will be swapped, or can you set a from and to value here (like I’ve tried to do in my config)?

---

<div class="post-metadata">

**Author:** ![denis](https://avatars.discourse-cdn.com/v4/letter/d/5e9695/32.png) [@denis](https://discuss.pomerium.com/u/denis)\
**Post date:** [January 23, 2023, 1:38pm UTC](https://discuss.pomerium.com/t/need-help-with-intercepting-a-301-redirect/233/2 "2023-01-23T13:38:25Z")

</div>

You may set preserve\_host\_header option so that your app would know the original name of the host. It may not work as your upstream is HTTPS and they’ll come into conflict.

Pomerium does not have conditional rewrite rules currently.

Is this some kind of standard app we can try to look at or it’s something internal ?

---

<div class="post-metadata">

**Author:** ![torch](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@torch](https://discuss.pomerium.com/u/torch)\
**Post date:** [January 23, 2023, 2:04pm UTC](https://discuss.pomerium.com/t/need-help-with-intercepting-a-301-redirect/233/3 "2023-01-23T14:04:59Z")

</div>

Thanks for the response

I did try `preserve_host_header`, but it didn’t work, unfortunately.

The app in question is whip media from [mediamorph.com](http://mediamorph.com) ([Buy TV Content Rights, Buy Movie Rights | Whip Media](https://www.whipmedia.com/the-exchange/)). They use IP whitelisting, so the URL (akin to “[mycompany.mediamorph.com](http://mycompany.mediamorph.com)”) is only available from some of my company’s predefined IP addresses, so it might be hard for you to test.

If it’s of any use, here are the headers:

```auto
Request headers
Request URL: https://mediamorph.pomerium.mycompany.com/
Request Method: GET
Status Code: 301 (from disk cache)
Remote Address: 92.220.230.54:443
Referrer Policy: strict-origin-when-cross-origin

```

```auto
content-length: 243
content-type: text/html; charset=iso-8859-1
date: Mon, 23 Jan 2023 07:52:54 GMT
location: https://mycompany.mediamorph.com/app/
server: envoy
x-envoy-upstream-service-time: 136
x-frame-options: SAMEORIGIN
x-request-id: 2251a9e5-02d2-4faf-124c-a8b6b05c2ba2
x-xss-protection: 1; mode=block

```

---

<div class="post-metadata">

**Author:** ![calebdoxsey](https://avatars.discourse-cdn.com/v4/letter/c/7bcc69/32.png) [@calebdoxsey](https://discuss.pomerium.com/u/calebdoxsey)\
**Post date:** [January 23, 2023, 6:51pm UTC](https://discuss.pomerium.com/t/need-help-with-intercepting-a-301-redirect/233/4 "2023-01-23T18:51:19Z")

</div>

Can you use a rule like this so it matches any path?

```yaml
rewrite_response_headers:
  - header: Location
    prefix: https://test.example.com/
    value: http://example.pomerium.mydomain.com/

```

Then both `/login` and `/app/` would get redirected. Alternatively you could add two routes:

```yaml
rewrite_response_headers:
  - header: Location
    prefix: https://test.example.com/login
    value: http://example.pomerium.mydomain.com/login
  - header: Location
    prefix: https://test.example.com/app/
    value: http://example.pomerium.mydomain.com/app/

```

---

<div class="post-metadata">

**Author:** ![torch](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@torch](https://discuss.pomerium.com/u/torch)\
**Post date:** [January 24, 2023, 9:57am UTC](https://discuss.pomerium.com/t/need-help-with-intercepting-a-301-redirect/233/5 "2023-01-24T09:57:12Z")

</div>

Thanks, @calebdoxsey, your first suggestion seems to work:

```auto
routes:
- from: https://mediamorph.pomerium.mydomain.com
  to: https://test.mediamorph.com
  rewrite_response_headers:
  - header: Location
    prefix: https://test.mediamorph.com/
    value: https://mediamorph.pomerium.mydomain.com/

```

Not sure why this is necessary, though. I would have assumed that this would be covered by the from/to parameters, which are identical, except for the trailing slashes…

The alternative with two rules did **not** work for me, for some reason.

Anyway, thanks for the assist!

---

<div class="post-metadata">

**Author:** ![torch](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@torch](https://discuss.pomerium.com/u/torch)\
**Post date:** [January 24, 2023, 11:28am UTC](https://discuss.pomerium.com/t/need-help-with-intercepting-a-301-redirect/233/6 "2023-01-24T11:28:23Z")

</div>

Seems I was a bit too quick to declare this resolved…

Yes, the rewrite\_response\_headers-fix works for the first URL, but when I try to duplicate the rule for a slightly different one, it doesn’t work:

```auto
- from: https://mediamorph-abc.pomerium.mydomain.com
  to: https://test-abc.mediamorph.com
  rewrite_response_headers:
  - header: Location
    prefix: https://test-abc.mediamorph.com/
    value: https://mediamorph-abc.pomerium.mydomain.com/

```

The only obvious difference between the two is the dash ( - ) in the URL. Is this a known limitation, or have I stumbled upon a bug?

---

<div class="post-metadata">

**Author:** ![torch](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@torch](https://discuss.pomerium.com/u/torch)\
**Post date:** [January 25, 2023, 1:50pm UTC](https://discuss.pomerium.com/t/need-help-with-intercepting-a-301-redirect/233/7 "2023-01-25T13:50:24Z")

</div>

Ok, so I’ve half narrowed down where this goes wrong.

The function `replace_prefix` in  
`https://github.com/pomerium/pomerium/blob/main/config/envoyconfig/luascripts/rewrite-headers.lua`

```auto
function replace_prefix(str, prefix, value)
    return str:gsub("^"..prefix, value)
end

```

uses gsub. I’m not a lua expert, but apparently the dash/hyphen needs to be escaped for this to work:

If I test the function locally, I see the following behaviour:

Substitution **without** dash works fine

```auto
replace_prefix("https://nodash.domain.com/app/", "https://nodash.domain.com/", "https://rewritten.mydomain.com/")
https://rewritten.mydomain.com/app/	1

```

Substitution **with** dash fails ( The original string is returned unaltered)

```auto
replace_prefix("https://with-dash.domain.com/app/", "https://with-dash.domain.com/", "https://rewritten.mydomain.com/")
https://with-dash.domain.com/app/	0

```

But if I escape the dash with a %, it works again

```auto
replace_prefix("https://with-dash.domain.com/app/", "https://with%-dash.domain.com/", "https://rewritten.mydomain.com/")
https://rewritten.mydomain.com/app/	1

```

So in theory, I should be able to escape the dash in my config

```auto
  rewrite_response_headers:
  - header: Location
    prefix: https://test%-abc.mediamorph.com/
    value: https://mediamorph-abc.pomerium.mydomain.com/

```

This doesn’t work however, so maybe the % is being stripped away at some point, before it reaches the replace\_prefix function…?

Anyway, perhaps you would consider this solution to get around the issue…?

> <https://stackoverflow.com/questions/29072601/lua-string-gsub-with-a-hyphen>

I believe URLs with dashes are fairly common, so I would imagine this could be helpful for others as well.

---

<div class="post-metadata">

**Author:** ![torch](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@torch](https://discuss.pomerium.com/u/torch)\
**Post date:** [January 26, 2023, 8:59am UTC](https://discuss.pomerium.com/t/need-help-with-intercepting-a-301-redirect/233/8 "2023-01-26T08:59:08Z")

</div>

I was able to get around this by enclosing the prefix in double quotes and escaping the dash in config.yaml ( single quotes did not work)

```auto
    rewrite_response_headers:
      - header: Location
        prefix: "https://test%-abc.mediamorph.com/"
        value: https://mediamorph-abc.pomerium.mydomain.com/

```

I still think it would be nice if the replace-script had handled this, but at least my setup works now.
