Decide request TLS in one place, per request (closes #269)
All checks were successful
check / check (push) Successful in 3m46s
All checks were successful
check / check (push) Successful in 3m46s
Two places decided whether a request was TLS, by two different means, and they disagreed. The session cookie's Secure attribute was fixed at startup from !Config.IsDev(). "dev" is the environment when WEBHOOKER_ENVIRONMENT is unset, so a deployment terminating TLS at a proxy without also setting the environment shipped the authentication cookie with no Secure attribute -- on the same response as a CSRF cookie that had one. It failed silently: everything kept working, so nothing prompted anyone to look. The CSRF middleware's per-request check compared X-Forwarded-Proto with == "https" exactly, so "HTTPS", "https, http" and "https,https" all took the plaintext path. Uppercase is legal for a case-insensitive token and the comma forms are what a proxy chained behind another proxy emits by appending rather than replacing. On that path gorilla/csrf stops enforcing the strict Referer check on a site that genuinely is HTTPS. Both now go through internal/reqtls.IsTLS, which folds case and takes the leftmost comma-separated element -- the hop nearest the client, and so the one a cookie's Secure attribute is about. A third package is needed because internal/middleware already imports internal/session, so session cannot import middleware back. Per-request beat a startup warning for the session cookie because it turned out to need no restructuring: gorilla/sessions gives every session its own copy of the store's Options and renders the cookie from that copy, and every session-cookie write here already goes through Session.Save or Session.Regenerate, both of which hold the request. The store's template Secure becomes true so that a write path added later which forgets to track the transport fails visibly instead of silently dropping Secure. The flag tracks the transport in both directions rather than latching on. Secure over plaintext is discarded by the browser without an error, which would make a plain-HTTP local run impossible to log into -- and would also void the deletion cookies in Destroy and Regenerate, leaving a session the user just tried to end still live. A third site that makes this decision, internal/handlers' BaseURL construction, assigns the raw header straight into the URL scheme. It is left alone here and filed separately.
This commit is contained in:
59
internal/reqtls/reqtls.go
Normal file
59
internal/reqtls/reqtls.go
Normal file
@@ -0,0 +1,59 @@
|
||||
// Package reqtls answers one question, in one place, for the whole
|
||||
// application: did this request reach the service over TLS?
|
||||
//
|
||||
// It exists because that question used to be answered independently in
|
||||
// several packages, by hand, and the answers disagreed. The session
|
||||
// cookie's Secure attribute was decided at startup from the configured
|
||||
// environment while the CSRF cookie's was decided per-request, so a
|
||||
// deployment behind a TLS proxy in the default environment emitted one
|
||||
// Secure cookie and one non-Secure cookie on the same response.
|
||||
// Everything kept working, which is exactly why nobody noticed.
|
||||
//
|
||||
// Any code that needs a scheme or a Secure flag must call IsTLS rather
|
||||
// than reading the request itself.
|
||||
package reqtls
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"strings"
|
||||
)
|
||||
|
||||
// forwardedProtoHeader is the de-facto standard header by which a
|
||||
// TLS-terminating reverse proxy reports the protocol the CLIENT used.
|
||||
const forwardedProtoHeader = "X-Forwarded-Proto"
|
||||
|
||||
// IsTLS reports whether the client-facing connection uses TLS: either
|
||||
// the request arrived over TLS directly, or a reverse proxy terminated
|
||||
// TLS and said so in X-Forwarded-Proto.
|
||||
//
|
||||
// The header is only as trustworthy as whatever sits in front of the
|
||||
// listener. A proxy that overwrites it -- which is what the deployment
|
||||
// documentation requires -- makes it authoritative; a listener exposed
|
||||
// directly to clients lets any client assert it. That is the same
|
||||
// exposure every X-Forwarded-* consumer carries.
|
||||
func IsTLS(r *http.Request) bool {
|
||||
return r.TLS != nil || forwardedProto(r) == "https"
|
||||
}
|
||||
|
||||
// forwardedProto reduces X-Forwarded-Proto to a bare, comparable
|
||||
// protocol token, or "" when the header is absent or blank.
|
||||
//
|
||||
// Two shapes that real infrastructure emits do not survive an exact
|
||||
// comparison against "https", and both name a TLS client connection:
|
||||
//
|
||||
// - "HTTPS", because the header value is a case-insensitive token and
|
||||
// nothing obliges a proxy to emit it lowercased.
|
||||
// - "https, http", because a proxy chained behind another proxy
|
||||
// APPENDS its own hop instead of replacing the value. As with
|
||||
// X-Forwarded-For, the leftmost element is the one nearest the
|
||||
// client, so it is the element that describes the browser's
|
||||
// connection -- the only hop a cookie's Secure attribute is about.
|
||||
//
|
||||
// Landing on the plaintext path for either of those spellings is not a
|
||||
// cosmetic error: it stops gorilla/csrf enforcing the strict Referer
|
||||
// check on a site that genuinely is HTTPS.
|
||||
func forwardedProto(r *http.Request) string {
|
||||
first, _, _ := strings.Cut(r.Header.Get(forwardedProtoHeader), ",")
|
||||
|
||||
return strings.ToLower(strings.TrimSpace(first))
|
||||
}
|
||||
Reference in New Issue
Block a user