mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix!: only trust x-forwarded-host from configured trusted proxies (#26204)
Subdomain app routing derived the app identity from httpapi.RequestHost, which returned the client-supplied X-Forwarded-Host header verbatim. No middleware validated or stripped that header, so a request from an untrusted peer could forge it. Since the application_connect cookie is scoped to the wildcard apps domain, JavaScript in a share=authenticated app could fetch() with a forged X-Forwarded-Host pointing at a victim's owner-only app; coderd routed and authorized the request as the victim and returned the private app response same-origin to the attacker. Replace RequestHost with httpmw.EffectiveHost, which honors X-Forwarded-Host only when the original socket peer is a configured trusted origin, otherwise falling back to the received Host header. This ties host trust to the same RealIPConfig model already used for X-Forwarded-For and -Proto. Wire it into HandleSubdomain for both coderd and wsproxy, and log both the effective host and the raw received_host. Add coverage: EffectiveHost unit tests assert the trust decision uses the socket peer rather than the spoofable forwarded client IP, and a HandleSubdomain test confirms a forged X-Forwarded-Host from an untrusted peer never reaches token resolution. Refs: https://linear.app/codercom/issue/PLAT-259
This commit is contained in:
+2
-2
@@ -454,8 +454,8 @@ NETWORKING OPTIONS:
|
||||
True-Client-Ip, X-Forwarded-For.
|
||||
|
||||
--proxy-trusted-origins string-array, $CODER_PROXY_TRUSTED_ORIGINS
|
||||
Origin addresses to respect "proxy-trusted-headers". e.g.
|
||||
192.168.1.0/24.
|
||||
Origin addresses to respect "proxy-trusted-headers" and
|
||||
X-Forwarded-Host for subdomain app routing. e.g. 192.168.1.0/24.
|
||||
|
||||
--redirect-to-access-url bool, $CODER_REDIRECT_TO_ACCESS_URL
|
||||
Specifies whether to redirect requests that do not match the access
|
||||
|
||||
+2
-1
@@ -172,7 +172,8 @@ networking:
|
||||
# True-Client-Ip, X-Forwarded-For.
|
||||
# (default: <unset>, type: string-array)
|
||||
proxyTrustedHeaders: []
|
||||
# Origin addresses to respect "proxy-trusted-headers". e.g. 192.168.1.0/24.
|
||||
# Origin addresses to respect "proxy-trusted-headers" and X-Forwarded-Host for
|
||||
# subdomain app routing. e.g. 192.168.1.0/24.
|
||||
# (default: <unset>, type: string-array)
|
||||
proxyTrustedOrigins: []
|
||||
# Controls if the 'Secure' property is set on browser session cookies.
|
||||
|
||||
Reference in New Issue
Block a user