mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: add custom samesite options to auth cookies (#16885)
Allows controlling `samesite` cookie settings from the deployment config
This commit is contained in:
@@ -264,7 +264,7 @@ func (r *RootCmd) proxyServer() *serpent.Command {
|
||||
Tracing: tracer,
|
||||
PrometheusRegistry: prometheusRegistry,
|
||||
APIRateLimit: int(cfg.RateLimit.API.Value()),
|
||||
SecureAuthCookie: cfg.SecureAuthCookie.Value(),
|
||||
CookieConfig: cfg.HTTPCookies,
|
||||
DisablePathApps: cfg.DisablePathApps.Value(),
|
||||
ProxySessionToken: proxySessionToken.Value(),
|
||||
AllowAllCors: cfg.Dangerous.AllowAllCors.Value(),
|
||||
|
||||
@@ -252,6 +252,9 @@ NETWORKING OPTIONS:
|
||||
Specifies whether to redirect requests that do not match the access
|
||||
URL host.
|
||||
|
||||
--samesite-auth-cookie lax|none, $CODER_SAMESITE_AUTH_COOKIE (default: lax)
|
||||
Controls the 'SameSite' property is set on browser session cookies.
|
||||
|
||||
--secure-auth-cookie bool, $CODER_SECURE_AUTH_COOKIE
|
||||
Controls if the 'Secure' property is set on browser session cookies.
|
||||
|
||||
|
||||
@@ -156,7 +156,7 @@ func NewWorkspaceProxyReplica(t *testing.T, coderdAPI *coderd.API, owner *coders
|
||||
RealIPConfig: coderdAPI.RealIPConfig,
|
||||
Tracing: coderdAPI.TracerProvider,
|
||||
APIRateLimit: coderdAPI.APIRateLimit,
|
||||
SecureAuthCookie: coderdAPI.SecureAuthCookie,
|
||||
CookieConfig: coderdAPI.DeploymentValues.HTTPCookies,
|
||||
ProxySessionToken: token,
|
||||
DisablePathApps: options.DisablePathApps,
|
||||
// We need a new registry to not conflict with the coderd internal
|
||||
|
||||
@@ -70,7 +70,7 @@ type Options struct {
|
||||
TLSCertificates []tls.Certificate
|
||||
|
||||
APIRateLimit int
|
||||
SecureAuthCookie bool
|
||||
CookieConfig codersdk.HTTPCookieConfig
|
||||
DisablePathApps bool
|
||||
DERPEnabled bool
|
||||
DERPServerRelayAddress string
|
||||
@@ -310,8 +310,8 @@ func New(ctx context.Context, opts *Options) (*Server, error) {
|
||||
Logger: s.Logger.Named("proxy_token_provider"),
|
||||
},
|
||||
|
||||
DisablePathApps: opts.DisablePathApps,
|
||||
SecureAuthCookie: opts.SecureAuthCookie,
|
||||
DisablePathApps: opts.DisablePathApps,
|
||||
Cookies: opts.CookieConfig,
|
||||
|
||||
AgentProvider: agentProvider,
|
||||
StatsCollector: workspaceapps.NewStatsCollector(opts.StatsCollectorOptions),
|
||||
@@ -362,7 +362,7 @@ func New(ctx context.Context, opts *Options) (*Server, error) {
|
||||
},
|
||||
// CSRF is required here because we need to set the CSRF cookies on
|
||||
// responses.
|
||||
httpmw.CSRF(s.Options.SecureAuthCookie),
|
||||
httpmw.CSRF(s.Options.CookieConfig),
|
||||
)
|
||||
|
||||
// Attach workspace apps routes.
|
||||
|
||||
Reference in New Issue
Block a user