chore: make authz recorder opt in (#20310)

The authz recorder is causing a lot of memory to be allocated, and is a
memory leak for websocket connections.

This change makes it opt-in on a per request basis (ontop of `isDev`).
To get the authz headers, use `Copy as cURL` on chrome and append the
header `x-authz-checks=true`.
This commit is contained in:
Steven Masley
2025-10-21 14:15:37 +00:00
committed by GitHub
parent 650dc860bd
commit 86f0f39863
8 changed files with 43 additions and 7 deletions
+14
View File
@@ -487,6 +487,7 @@ type DeploymentValues struct {
Sessions SessionLifetime `json:"session_lifetime,omitempty" typescript:",notnull"`
DisablePasswordAuth serpent.Bool `json:"disable_password_auth,omitempty" typescript:",notnull"`
Support SupportConfig `json:"support,omitempty" typescript:",notnull"`
EnableAuthzRecording serpent.Bool `json:"enable_authz_recording,omitempty" typescript:",notnull"`
ExternalAuthConfigs serpent.Struct[[]ExternalAuthConfig] `json:"external_auth,omitempty" typescript:",notnull"`
SSHConfig SSHConfig `json:"config_ssh,omitempty" typescript:",notnull"`
WgtunnelHost serpent.String `json:"wgtunnel_host,omitempty" typescript:",notnull"`
@@ -3293,6 +3294,19 @@ Write out the current server config as YAML to stdout.`,
YAML: "key",
Hidden: true,
},
{
Name: "Enable Authorization Recordings",
Description: "All api requests will have a header including all authorization calls made during the request. " +
"This is used for debugging purposes and only available for dev builds.",
Required: false,
Flag: "enable-authz-recordings",
Env: "CODER_ENABLE_AUTHZ_RECORDINGS",
Default: "false",
Value: &c.EnableAuthzRecording,
// Do not show this option ever. It is a developer tool only, and not to be
// used externally.
Hidden: true,
},
}
return opts