Keep platform cookies away from external upstreams - #52
Merged
Merged
Conversation
mode="external" proxies now drop the platform's own cookies (session, CSRF, shared-password) from forwarded requests and drop upstream Set-Cookie headers that would set them on the platform origin. A custom [auth] session_cookie_name is honoured. make_proxy_app gains an optional cookie_filter; process-mode proxies are unchanged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- Drop nameless Set-Cookie values (=enlace_session=x is sent by browsers as enlace_session=x and would shadow the real cookie). - External apps: withhold X-CSRF-Token upstream; drop Clear-Site-Data and Service-Worker-Allowed from upstream responses. - make_proxy_app gains drop_request_headers / drop_response_headers. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
mode="external"apps proxy to a server outside the platform. The proxy forwarded every request header, including the visitor'sCookie, and passed every upstream response header back on the platform origin.This change:
cookie_filter(name -> bool),drop_request_headersanddrop_response_headerstomake_proxy_app; rejected cookies are removed from the forwardedCookieheader, and upstreamSet-Cookieheaders naming them — or naming no cookie at all — are dropped;platform_cookie_filter()(dropsenlace_session,enlace_csrf,shared_auth_*);ExternalStrategyuse it (honouring a custom[auth] session_cookie_name), withholdX-CSRF-Tokenupstream, and dropClear-Site-Data/Service-Worker-Allowedfrom upstream responses.Process-mode (local, part of the platform) and asgi-mode apps are unchanged. Upstream-owned cookies and other headers still pass both ways (including
Authorization, which an external API may use for its own tokens).Limit (by design, not fixed here): an external app is still served on the platform origin, so HTML/JS it returns runs same-origin with the platform (it can issue credentialed same-origin requests, and read the non-HttpOnly CSRF cookie). This PR stops the platform credential from being handed to the upstream and stops response headers from overwriting/wiping it; it does not isolate a hostile upstream. Only a separate origin (own subdomain, or linking to the upstream directly) does that.
Tests:
enlace/tests/test_proxy_cookies.py(fails on main). Independent refute-review done; its findings (namelessSet-Cookie,Clear-Site-Data,Service-Worker-Allowed, CSRF header) are fixed in the second commit. Dependents checked locally against this branch: enlace_auth (377 passed), enlace_docker (53 passed, 2 skipped).🤖 Generated with Claude Code