Files
sim/apps
Theodore Li 67e02fab3a fix(execute): block cross-origin session-authenticated workflow runs (#5062)
* fix(execute): block cross-origin session-authenticated workflow runs

* fix(execute): scope session origin guard to provable cross-origin

Address review on #5062:
- Reject session-cookie execution only when provably cross-origin (Sec-Fetch-Site
  cross-site/same-site/none, or a mismatched Origin) instead of failing closed on
  absent headers. Fixes route tests that 403'd on header-less session requests, and
  reflects that this is CSRF protection, not anti-cookie-replay.
- Drop same-site from the trusted set: only same-origin is our front-end.
- Guard the Origin fallback in try/catch so a getBaseUrl() throw can't escape.
- Add a route-level cross-origin rejection test.
2026-06-15 15:39:43 -04:00
..