agent build
This commit is contained in:
@@ -55,6 +55,34 @@ func (s *Server) secureCookies() bool { return s.cfg.AppEnv != "development" }
|
||||
// only mode a browser will send cross-site, and it requires Secure — which is
|
||||
// why an origin allowlist forces Secure on regardless of AppEnv.
|
||||
func (s *Server) sessionSameSite() http.SameSite {
|
||||
// An explicit HTTP_COOKIE_SAMESITE wins, because the derivation below
|
||||
// cannot see the one thing that decides the answer: whether the frontend
|
||||
// is on the same SITE as this API.
|
||||
//
|
||||
// CORS is about ORIGIN and SameSite is about SITE, and they are not the
|
||||
// same question. platform.krowforce.com calling mcp.krowforce.com is
|
||||
// cross-origin — so it needs the CORS allowlist — and same-site, so a Lax
|
||||
// cookie is sent on its requests anyway. Deriving None from "CORS is
|
||||
// configured" gives up the only CSRF protection this API has, in exchange
|
||||
// for nothing that deployment needed.
|
||||
//
|
||||
// So the allowlist decides the DEFAULT and an operator decides the value.
|
||||
// This also closes a trap: config.Load has always parsed and validated
|
||||
// HTTP_COOKIE_SAMESITE, and nothing read it — a deployment that set it saw
|
||||
// it silently ignored.
|
||||
switch s.cfg.HTTP.CookieSameSite {
|
||||
case "none":
|
||||
return http.SameSiteNoneMode
|
||||
case "strict":
|
||||
return http.SameSiteStrictMode
|
||||
case "lax":
|
||||
return http.SameSiteLaxMode
|
||||
}
|
||||
|
||||
// Unset. A configured CORS allowlist means a browser on another origin is
|
||||
// expected, and None is the only mode that survives a genuinely cross-site
|
||||
// one. Safe as a default because it is only reached when nobody has said
|
||||
// otherwise.
|
||||
if len(s.cfg.HTTP.CORSOrigins) > 0 {
|
||||
return http.SameSiteNoneMode
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user