forked from sneak/upaas
- CSRF over plain HTTP (#189): gorilla/csrf assumed https for its same-origin check, so setup and every POST returned 403 over plain HTTP. Gate csrf.PlaintextHTTPRequest on a new UPAAS_PLAINTEXT_HTTP config value; the default keeps https, correct for a TLS-terminating reverse proxy. The README plain-HTTP recipe now sets it. - git image never pulled (#190): ensureImage pulls alpine/git (pinned digest unchanged) when absent, before the clone container is created. - port-mapping 500 (#192): the ports delete form used {{ .CSRFField }} inside {{range .Ports}}, where the dot is a *models.Port; use {{ $.CSRFField }} like the labels and volumes blocks. - env-var 403 (#191): the editor read the CSRF token from $el (the submitting form, which has none) instead of $root, sending an empty token; read from $root. Model: opus-4-8
This commit is contained in:
@@ -255,12 +255,34 @@ func (m *Middleware) SessionAuth() func(http.Handler) http.Handler {
|
||||
}
|
||||
|
||||
// CSRF returns CSRF protection middleware using gorilla/csrf.
|
||||
//
|
||||
// gorilla/csrf assumes the request scheme is https for its same-origin check
|
||||
// unless the request is marked plaintext. A TLS-terminating reverse proxy
|
||||
// (the default deployment) presents https to the browser, so the default is
|
||||
// correct there. When µPaaS is reached over plain HTTP — directly, or behind a
|
||||
// proxy that does not terminate TLS — set UPAAS_PLAINTEXT_HTTP so the origin
|
||||
// check compares against http:// and setup over plain HTTP works.
|
||||
func (m *Middleware) CSRF() func(http.Handler) http.Handler {
|
||||
return csrf.Protect(
|
||||
protect := csrf.Protect(
|
||||
[]byte(m.params.Config.SessionSecret),
|
||||
csrf.Secure(false), // Allow HTTP for development; reverse proxy handles TLS
|
||||
csrf.Secure(false), // cookie Secure flag; TLS is terminated upstream
|
||||
csrf.Path("/"),
|
||||
)
|
||||
|
||||
if !m.params.Config.PlaintextHTTP {
|
||||
return protect
|
||||
}
|
||||
|
||||
return func(next http.Handler) http.Handler {
|
||||
protected := protect(next)
|
||||
|
||||
return http.HandlerFunc(func(
|
||||
writer http.ResponseWriter,
|
||||
request *http.Request,
|
||||
) {
|
||||
protected.ServeHTTP(writer, csrf.PlaintextHTTPRequest(request))
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// loginRateLimit configures the login rate limiter.
|
||||
|
||||
Reference in New Issue
Block a user