agent build

This commit is contained in:
2026-08-28 12:21:44 +05:30
parent b6f8655909
commit f7df96c973
138 changed files with 24164 additions and 207 deletions

View File

@@ -55,6 +55,34 @@ func (s *Server) secureCookies() bool { return s.cfg.AppEnv != "development" }
// only mode a browser will send cross-site, and it requires Secure — which is
// why an origin allowlist forces Secure on regardless of AppEnv.
func (s *Server) sessionSameSite() http.SameSite {
// An explicit HTTP_COOKIE_SAMESITE wins, because the derivation below
// cannot see the one thing that decides the answer: whether the frontend
// is on the same SITE as this API.
//
// CORS is about ORIGIN and SameSite is about SITE, and they are not the
// same question. platform.krowforce.com calling mcp.krowforce.com is
// cross-origin — so it needs the CORS allowlist — and same-site, so a Lax
// cookie is sent on its requests anyway. Deriving None from "CORS is
// configured" gives up the only CSRF protection this API has, in exchange
// for nothing that deployment needed.
//
// So the allowlist decides the DEFAULT and an operator decides the value.
// This also closes a trap: config.Load has always parsed and validated
// HTTP_COOKIE_SAMESITE, and nothing read it — a deployment that set it saw
// it silently ignored.
switch s.cfg.HTTP.CookieSameSite {
case "none":
return http.SameSiteNoneMode
case "strict":
return http.SameSiteStrictMode
case "lax":
return http.SameSiteLaxMode
}
// Unset. A configured CORS allowlist means a browser on another origin is
// expected, and None is the only mode that survives a genuinely cross-site
// one. Safe as a default because it is only reached when nobody has said
// otherwise.
if len(s.cfg.HTTP.CORSOrigins) > 0 {
return http.SameSiteNoneMode
}