fix: revert automatically set 'host-prefix-cookie' in https deployments" (#22225)

Reverts coder/coder#22224
This commit is contained in:
Jakub Domeracki
2026-02-20 20:12:51 +01:00
committed by GitHub
parent 67044d80a0
commit ceb417f8ba
2 changed files with 4 additions and 3 deletions
+3 -3
View File
@@ -2916,9 +2916,9 @@ func (c *DeploymentValues) Options() serpent.OptionSet {
Flag: "host-prefix-cookie",
Env: "CODER_HOST_PREFIX_COOKIE",
Value: serpent.BoolOf(&c.HTTPCookies.EnableHostPrefix),
DefaultFn: func() string {
return strconv.FormatBool(c.AccessURL.Scheme == "https")
},
// Ideally this is true, however any frontend interactions with the coder api would be broken.
// So for compatibility reasons, this is set to false.
Default: "false",
Group: &deploymentGroupNetworking,
YAML: "hostPrefixCookie",
Annotations: serpent.Annotations{}.Mark(annotationExternalProxies, "true"),
+1
View File
@@ -1065,6 +1065,7 @@ Controls the 'SameSite' property is set on browser session cookies.
| Type | <code>bool</code> |
| Environment | <code>$CODER_HOST_PREFIX_COOKIE</code> |
| YAML | <code>networking.hostPrefixCookie</code> |
| Default | <code>false</code> |
Recommended to be enabled. Enables `__Host-` prefix for cookies to guarantee they are only set by the right domain.