mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: Strip session_token cookie from app proxy requests (#3528)
Fixes coder/security#1.
This commit is contained in:
+9
-2
@@ -15,8 +15,15 @@ import (
|
||||
"nhooyr.io/websocket"
|
||||
)
|
||||
|
||||
// SessionTokenKey represents the name of the cookie or query parameter the API key is stored in.
|
||||
const SessionTokenKey = "session_token"
|
||||
// These cookies are Coder-specific. If a new one is added or changed, the name
|
||||
// shouldn't be likely to conflict with any user-application set cookies.
|
||||
// Be sure to strip additional cookies in httpapi.StripCoder Cookies!
|
||||
const (
|
||||
// SessionTokenKey represents the name of the cookie or query parameter the API key is stored in.
|
||||
SessionTokenKey = "session_token"
|
||||
OAuth2StateKey = "oauth_state"
|
||||
OAuth2RedirectKey = "oauth_redirect"
|
||||
)
|
||||
|
||||
// New creates a Coder client for the provided URL.
|
||||
func New(serverURL *url.URL) *Client {
|
||||
|
||||
Reference in New Issue
Block a user