# URL Rewriting
#
# Regex-based path transformation and query string manipulation.
#
# Operations execute in declared order:
#
#   /v1/users?debug=true&trace=1
#        |
#        v
#   +-------------------------+
#   | regex_replace           |  /v1/users -> /v2/users
#   +-------------------------+
#        |
#        v
#   +-------------------------+
#   | strip_query_params      |  ?debug=true&trace=1 -> (empty)
#   +-------------------------+
#        |
#        v
#   +-------------------------+
#   | add_query_params        |  -> ?source=gateway
#   +-------------------------+
#        |
#        v
#   /v2/users?source=gateway
#
# Usage:
#   cargo run -p praxis-proxy -- -c examples/configs/transformation/url-rewriting.yaml
#   curl http://localhost:8080/v1/users?debug=true
#   # Request reaches backend as /v2/users?source=gateway
#
# NOTE: The router checks rewritten_path before the original
# URI, so "rewrite then route" pipelines work: place a rewrite
# filter before the router and the router will match against
# the rewritten path.
#
# If both path_rewrite and url_rewrite appear in the same
# pipeline, only the last one's rewrite takes effect.
# Validation rejects this by default; set
# allow_rewrite_override: true on the later filter to permit
# it. Security consideration: filter order matters; the last
# rewrite wins, so misordering can bypass path-based ACLs.

listeners:
  - name: default
    address: "127.0.0.1:8080"
    filter_chains:
      - main

filter_chains:
  - name: main
    filters:
      - filter: url_rewrite
        operations:
          - regex_replace:
              pattern: "^/v1/(.*)"
              replacement: "/v2/$1"
          - strip_query_params:
              - debug
              - trace
          - add_query_params:
              source: gateway

      - filter: router
        routes:
          - path_prefix: "/"
            cluster: backend

      - filter: load_balancer
        clusters:
          - name: backend
            endpoints:
              - "127.0.0.1:3000"

insecure_options:
  allow_private_endpoints: true # example proxies to local backends
