feat: Add strict transport security and secure cookie options (#741)

This commit is contained in:
Garrett Delfosse
2022-03-31 12:31:06 -05:00
committed by GitHub
parent bb6c12ddd4
commit 0d53795c0d
3 changed files with 6 additions and 0 deletions
+3
View File
@@ -56,6 +56,7 @@ func start() *cobra.Command {
tlsMinVersion string
useTunnel bool
traceDatadog bool
secureAuthCookie bool
)
root := &cobra.Command{
Use: "start",
@@ -132,6 +133,7 @@ func start() *cobra.Command {
Database: databasefake.New(),
Pubsub: database.NewPubsubInMemory(),
GoogleTokenValidator: validator,
SecureAuthCookie: secureAuthCookie,
}
if !dev {
@@ -334,6 +336,7 @@ func start() *cobra.Command {
cliflag.BoolVarP(root.Flags(), &useTunnel, "tunnel", "", "CODER_DEV_TUNNEL", true, "Serve dev mode through a Cloudflare Tunnel for easy setup")
_ = root.Flags().MarkHidden("tunnel")
cliflag.BoolVarP(root.Flags(), &traceDatadog, "trace-datadog", "", "CODER_TRACE_DATADOG", false, "Send tracing data to a datadog agent")
cliflag.BoolVarP(root.Flags(), &secureAuthCookie, "secure-auth-cookie", "", "CODER_SECURE_AUTH_COOKIE", false, "Specifies if the 'Secure' property is set on browser session cookies")
return root
}
+2
View File
@@ -29,6 +29,8 @@ type Options struct {
AWSCertificates awsidentity.Certificates
GoogleTokenValidator *idtoken.Validator
SecureAuthCookie bool
}
// New constructs the Coder API into an HTTP handler.
+1
View File
@@ -417,6 +417,7 @@ func (api *api) postLogin(rw http.ResponseWriter, r *http.Request) {
Path: "/",
HttpOnly: true,
SameSite: http.SameSiteLaxMode,
Secure: api.SecureAuthCookie,
})
render.Status(r, http.StatusCreated)