Commit Graph
2382 Commits
Author SHA1 Message Date
renovate[bot] cd53996ef4 chore(deps): update docker/setup-buildx-action action to v4.4.1 2026-09-30 15:44:12 +00:00
Apollo3zehnandApollo3zehn b0d87093a8 fix: propagate AdditionalClaims on session refresh (#3547)
AdditionalClaims were only extracted during the initial login. On
cookie refresh, buildSessionFromClaims did extract them into a new
session, but redeemRefreshToken only copied Email, User, Groups and
PreferredUsername back to the existing session, discarding the
AdditionalClaims.

This affects OIDC and MS Entra ID providers. Any header
injection relying on additional claims goes stale until the user
re-authenticates.

Signed-off-by: Apollo3zehn <Apollo3zehn@users.noreply.github.com>
Co-authored-by: Apollo3zehn <Apollo3zehn@users.noreply.github.com>
2026-09-30 17:40:17 +02:00
kirilju 8f8d1f4eb3 fix: strip the port from the request host when matching cookie domains (#3546)
* Strip the port from the request host when matching cookie domains

GetCookieDomain suffix-matches the request host against each configured
cookie domain. When a reverse proxy rewrites the Host header to the
upstream's address, that host arrives as "host:port" and never matches,
so the request falls through to the "did not match any of the specific
cookie domains" warning and the shortest configured domain is used.

One way to hit this is Traefik's Errors middleware: it fetches a page
from a Service on port 443 with passHostHeader disabled, and forwards
the Host as "<host>:443". The request reaches oauth2-proxy correctly and
the resulting cookie is still usable, but every such request logs an
error that suggests a misconfiguration when none exists.

warnInvalidDomain, a few lines below in the same file, already calls
net.SplitHostPort on the host before comparing it to the cookie domain.
This makes GetCookieDomain consistent with it.

Tests cover a Host header with a port, an X-Forwarded-Host header with a
port, a non-standard port, and a host with a port that matches no
configured domain.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* chore: add changelog entry for #3546

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* test: keep the new port entries at the end of the table

The port cases were inserted between the Host and X-Forwarded-Host
variants of the existing suffix-match case, which split a pair that
reads as one. Move them after the last existing entry instead.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* test: pin that a port part can no longer match a cookie domain

SplitHostPort does not require the port to be numeric, so a host such as
"evil.com:.cookies.test" used to suffix-match a configured cookie domain
through its port part, and the cookie was then set for that domain. Matching
now runs against the host alone, so it does not.

Covers both the Host header and X-Forwarded-Host, since GetRequestHost
returns one or the other into the same comparison.

A Host of this shape cannot be expressed through the request URL, because
http.NewRequest rejects it as an invalid port, so the table gains a rawHost
field that assigns req.Host after the request is built. That is how a server
populates it from the wire, and pkg/upstream and pkg/middleware already set
req.Host the same way in their tests.

Thanks to @Lrifton92 for spotting this.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

---------

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>
2026-09-30 17:31:29 +02:00
Jan LarwigandOlivier Mengué 61db1188cf chore(deps): replace k8s.io/apimachinery/pkg/util/errors with errors.Join (#3552)
Drop use of k8s.io/apimachinery/pkg/util/errors.NewAggregate and replace
to with errors.Join which is available in stdlib since Go 1.20.

This allows to drop one dependency (which itself brings its own
contraints in its go.mod) and use more standard behavior from stdlib.

Co-authored-by: Olivier Mengué <dolmen@cpan.org>
2026-09-30 17:26:31 +02:00
renovate[bot] 94b5f340c4 chore(deps): update qltysh/qlty-action action to v2.4.0 (#3550)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-30 17:05:18 +02:00
renovate[bot] a769636b5f chore(deps): update gomod (#3511)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-30 16:56:06 +02:00
Ahmad Srour 86adcc6c9e docs: fix nginx API 401 example (#3549)
Signed-off-by: Ahmad Srour <asrour@live.com>
2026-09-30 16:55:20 +02:00
Jan Larwig 55824eb0e3 ci: use upstream cncf/prow-github-actions; fix needs-kind label issue; consolidate prow workflow files
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-09-28 17:18:26 +02:00
Jan Larwig 4238ee1b32 ci: introducing cncf/prow-github-actions (#3536)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-09-24 08:18:51 +02:00
Jan Larwig 6420aae790 docs: update and consolidate security disclosure process notice (#3537)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-09-13 15:22:39 +02:00
Jan Larwig 33c2eb92de docs: remove support issues and redirect to slack instead
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
2026-09-03 15:51:12 +02:00
Jan Larwig 0a83bffdb0 docs: remove support issues and redirect to slack instead
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
2026-09-03 15:47:51 +02:00
Jan Larwig c5529b42b7 docs: ai policy
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-24 11:39:04 +02:00
github-actions[bot]andJan Larwig 81ff034fe2 release v7.15.4 (#3508)
* update to release version v7.15.4

* docs: add changelog for v7.15.4

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
v7.15.4
2026-08-20 08:06:19 +02:00
Lee Seonghyeon · 이성현andihopenre-eng 61caa9ed01 docs: clarify the default nginx split-cookie example (#3474)
Signed-off-by: ihopenre-eng <247072151+ihopenre-eng@users.noreply.github.com>
Co-authored-by: ihopenre-eng <247072151+ihopenre-eng@users.noreply.github.com>
2026-08-20 07:37:44 +02:00
nightcityblade 061685fed3 docs: clarify structured claim header serialization (#3501)
Signed-off-by: nightcityblade <jackchen@haloailabs.com>
2026-08-20 07:33:54 +02:00
nightcitybladeandnightcityblade d122f0c28e docs: clarify alpha upstream path syntax (#3504)
Signed-off-by: nightcityblade <nightcityblade@gmail.com>
Co-authored-by: nightcityblade <nightcityblade@gmail.com>
2026-08-20 07:32:33 +02:00
Jan Larwig f7ae0ae81e test: update traefik setup and use in-memory for all dex instances instead of etcd
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 10:38:26 +02:00
renovate[bot] ff9b942a84 chore(deps): update docker-compose 2026-08-18 10:38:26 +02:00
renovate[bot] aa9690aa46 chore(deps): update helm release dex to v0.24.1 (#3446)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-18 09:33:57 +02:00
renovate[bot] 5aeb458a7f chore(deps): update docker-compose (#3460)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-18 09:33:47 +02:00
renovate[bot] aad15f3f89 chore(deps): update alpine docker tag to v3.24.1 (#3421)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-18 09:33:31 +02:00
Jan Larwig c4043233cf ci: hardening by replacing all tags using immutable commit hashes (#3507)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:31:56 +02:00
Jan Larwig d707a36a4c test: fix expected error message wording
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:23:29 +02:00
Jan Larwig 304077498d ci: use go tool for running golangci-lint
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:23:29 +02:00
renovate[bot] 09aa14acf4 chore(deps): update gomod
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:23:29 +02:00
Josh SorefandJan Larwig 1f049e5ebd docs: update inviter link (#3500)
* Update inviter link

---------

Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
2026-08-12 19:13:44 +02:00
renovate[bot] 14af2951e5 chore(deps): update actions/checkout action to v7 (#3462)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-30 21:28:21 +02:00
renovate[bot] d2a4782f6a chore(deps): update gomod (#3461)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-30 21:24:21 +02:00
Joel Speed 10b68716e5 Merge pull request #3425 from oauth2-proxy/renovate/actions-upload-pages-artifact-5.x
chore(deps): update actions/upload-pages-artifact action to v5
2026-06-14 17:15:04 +01:00
renovate[bot] 3d011d978d chore(deps): update actions/upload-pages-artifact action to v5 2026-06-14 16:10:13 +00:00
Joel Speed 127f087464 Merge pull request #3407 from oauth2-proxy/renovate/docker-compose
chore(deps): update docker-compose
2026-06-14 17:08:33 +01:00
renovate[bot] 077cd9f9cc chore(deps): update docker-compose 2026-06-14 15:42:56 +00:00
Joel Speed 807931cda5 Merge pull request #3424 from oauth2-proxy/renovate/gomod
chore(deps): update gomod
2026-06-14 16:42:14 +01:00
renovate[bot] 2479410598 chore(deps): update gomod 2026-06-13 19:57:08 +00:00
Jan Larwig 09979d458a docs: update slack reference for CNCF
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-06-09 13:50:16 +02:00
github-actions[bot]andJan Larwig 66b3a17db0 release v7.15.3 (#3450)
* update to release version v7.15.3

* docs: changelog for v7.15.3

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
v7.15.3
2026-06-09 13:28:24 +02:00
Jan Larwig 61151b4869 Merge pull request #3447 from oauth2-proxy/chore/bump-go-to-1.26-and-migrate-of-reverse-proxy-handling
chore(dep): bump go to 1.26 and migrate of reverse proxy handling
2026-06-09 12:20:57 +02:00
Jan Larwig 0de18825f6 chore(deps): bump Go to 1.26 and migrate upstream reverse proxies to Rewrite
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-06-08 14:12:56 +02:00
Jan Larwig 9a14186a26 chore(goconsts): use proper constants for http methods
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-06-08 12:54:58 +02:00
Jan Larwig 65037b086c change affiliation 2026-04-17 10:56:42 +02:00
github-actions[bot]andJan Larwig 5961fd99b4 release v7.15.2 (#3413)
* update to release version v7.15.2

* doc: add changelog entry for v7.15.2

Signed-off-by: Jan Larwig <jan@larwig.com>

* fix(deps): override webpackbar to v7 for webpack 5.106.0 compatibility

As outlined in https://github.com/facebook/docusaurus/issues/11923

Signed-off-by: Jan Larwig <jan@larwig.com>

* chore: fix local test files for nginx setup

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
v7.15.2
2026-04-14 13:12:28 +02:00
Jan Larwig bdfde725c6 Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:29:01 +02:00
Jan Larwig cc0e0335ea Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:24:51 +02:00
Jan Larwig aff369dfa3 Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:22:56 +02:00
Jan Larwig 43596a7bab Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:20:36 +02:00
Jan LarwigandChristopher Schrewing 0337a95fc6 Merge commit from fork
* fix: clear session cookie at beginning of signinpage handler

Co-authored-by: Christopher Schrewing <christopher.schrewing@weidmueller.com>
Signed-off-by: Michael Bella <michael.bella@weidmueller.com>
Signed-off-by: Jan Larwig <jan@larwig.com>

* test: clear session cookie at beginning of signinpage handler

Signed-off-by: Jan Larwig <jan@larwig.com>

* doc: changelog entry for GHSA-f24x-5g9q-753f

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Michael Bella <michael.bella@weidmueller.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: Christopher Schrewing <christopher.schrewing@weidmueller.com>
2026-04-13 18:17:50 +02:00
Francesco Pasqualini 2e1261c4be fix: invalidate session on fatal OAuth2 refresh errors (#3333)
* fix: invalidate session on fatal OAuth2 refresh errors

When a token refresh fails with a fatal OAuth2 error (invalid_grant,
invalid_client), the session is now cleared from the session store
and the cookie is removed, forcing re-authentication.

Previously, fatal refresh errors were logged but the stale session
continued to be served, leaving users logged in indefinitely after
their session was revoked at the provider level.

Transient errors (network timeouts, server errors) continue to
preserve the existing session as before.

Fixes #1945

Signed-off-by: Francesco Pasqualini <frapas@gmail.com>

* fix: apply review nits and add CHANGELOG entry

Signed-off-by: Francesco Pasqualini <frapas@gmail.com>
Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Francesco Pasqualini <frapas@gmail.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-12 14:48:55 +02:00
Jan Larwig 26de082a78 chore(deps): update gomod dependencies (#3411)
-       github.com/coreos/go-oidc/v3 v3.17.0
+       github.com/coreos/go-oidc/v3 v3.18.0

-       github.com/go-jose/go-jose/v3 v3.0.4
+       github.com/go-jose/go-jose/v3 v3.0.5

-       github.com/go-viper/mapstructure/v2 v2.4.0
+       github.com/go-viper/mapstructure/v2 v2.5.0

-       golang.org/x/crypto v0.49.0
+       golang.org/x/crypto v0.50.0

-       golang.org/x/net v0.52.0
+       golang.org/x/net v0.53.0

-       google.golang.org/api v0.272.0
+       google.golang.org/api v0.275.0

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-12 14:21:47 +02:00
Justus 761bf3b42b build(deps): bump github.com/go-jose/go-jose/v4 to 4.1.4 (#3400)
Signed-off-by: Juqsi <91261422+Juqsi@users.noreply.github.com>
2026-04-08 21:25:17 +02:00