An unset WEBHOOKER_ENVIRONMENT now resolves to prod rather than dev, so an operator who forgets the variable is not silently permissive. The only behaviour dev still changes is the CORS middleware, which answers every origin with Access-Control-Allow-Origin: *; that is now off unless dev is set explicitly. Cookie Secure and CSRF strictness are decided per request from the transport and are unaffected. Updated resolveEnvironment and its comment, the README configuration table and prose, and tests covering the default and the explicit dev. Comments that justified behaviour by the old dev default (the TRUSTED_PROXIES warning, a CSRF test) were corrected; that warning still fires in every environment when TRUSTED_PROXIES is empty. Model: opus-4-8
This commit is contained in:
@@ -585,12 +585,14 @@ func resolveMetricsAuth() (string, string, error) {
|
||||
)
|
||||
}
|
||||
|
||||
// resolveEnvironment reads WEBHOOKER_ENVIRONMENT, defaulting to
|
||||
// dev, and rejects unrecognised values.
|
||||
// resolveEnvironment reads WEBHOOKER_ENVIRONMENT, defaulting to prod
|
||||
// when it is unset so a deployment that forgets the variable is not
|
||||
// silently permissive; dev must be set explicitly. It rejects
|
||||
// unrecognised values.
|
||||
func resolveEnvironment() (string, error) {
|
||||
environment := os.Getenv("WEBHOOKER_ENVIRONMENT")
|
||||
if environment == "" {
|
||||
environment = EnvironmentDev
|
||||
environment = EnvironmentProd
|
||||
}
|
||||
|
||||
if environment != EnvironmentDev &&
|
||||
@@ -772,10 +774,10 @@ func (c *Config) warnEgressAllowlist(log *slog.Logger) {
|
||||
// everyone else's wrong passwords, and the receiver's limits become
|
||||
// service-wide ceilings.
|
||||
//
|
||||
// The warning is deliberately not gated on WEBHOOKER_ENVIRONMENT. That
|
||||
// variable defaults to dev, so gating on it would silence the warning
|
||||
// for exactly the operator who forgot to configure the deployment —
|
||||
// the case it exists to catch.
|
||||
// The warning is deliberately not gated on WEBHOOKER_ENVIRONMENT: an
|
||||
// operator who never configured the deployment is exactly the case it
|
||||
// exists to catch, so the exposure it announces is independent of the
|
||||
// environment setting.
|
||||
//
|
||||
// The default of trusting nobody is deliberate — trusting forwarded
|
||||
// headers from arbitrary peers lets any client choose its own bucket —
|
||||
|
||||
Reference in New Issue
Block a user