kirilju 8f8d1f4eb3 fix: strip the port from the request host when matching cookie domains (#3546)
* Strip the port from the request host when matching cookie domains

GetCookieDomain suffix-matches the request host against each configured
cookie domain. When a reverse proxy rewrites the Host header to the
upstream's address, that host arrives as "host:port" and never matches,
so the request falls through to the "did not match any of the specific
cookie domains" warning and the shortest configured domain is used.

One way to hit this is Traefik's Errors middleware: it fetches a page
from a Service on port 443 with passHostHeader disabled, and forwards
the Host as "<host>:443". The request reaches oauth2-proxy correctly and
the resulting cookie is still usable, but every such request logs an
error that suggests a misconfiguration when none exists.

warnInvalidDomain, a few lines below in the same file, already calls
net.SplitHostPort on the host before comparing it to the cookie domain.
This makes GetCookieDomain consistent with it.

Tests cover a Host header with a port, an X-Forwarded-Host header with a
port, a non-standard port, and a host with a port that matches no
configured domain.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* chore: add changelog entry for #3546

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* test: keep the new port entries at the end of the table

The port cases were inserted between the Host and X-Forwarded-Host
variants of the existing suffix-match case, which split a pair that
reads as one. Move them after the last existing entry instead.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* test: pin that a port part can no longer match a cookie domain

SplitHostPort does not require the port to be numeric, so a host such as
"evil.com:.cookies.test" used to suffix-match a configured cookie domain
through its port part, and the cookie was then set for that domain. Matching
now runs against the host alone, so it does not.

Covers both the Host header and X-Forwarded-Host, since GetRequestHost
returns one or the other into the same comparison.

A Host of this shape cannot be expressed through the request URL, because
http.NewRequest rejects it as an invalid port, so the table gains a rawHost
field that assigns req.Host after the request is built. That is how a server
populates it from the wire, and pkg/upstream and pkg/middleware already set
req.Host the same way in their tests.

Thanks to @Lrifton92 for spotting this.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

---------

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>
2026-09-30 17:31:29 +02:00
2024-01-20 20:10:37 +00:00
2026-08-20 08:06:19 +02:00
2026-01-17 11:04:43 +01:00
2014-06-09 16:25:26 -04:00
2026-04-17 10:56:42 +02:00
2026-08-12 19:13:44 +02:00
2026-04-13 18:24:51 +02:00
2026-04-13 18:24:51 +02:00

Continuous Integration Go Report Card GoDoc MIT licensed Maintainability Code Coverage OpenSSF Scorecard OpenSSF Best Practices FOSSA Status

OAuth2 Proxy

OAuth2 Proxy is a flexible, open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. It provides a simple and secure way to protect your web applications with OAuth2 / OIDC authentication. As a reverse proxy, it intercepts requests to your application and redirects users to an OAuth2 provider for authentication. As a middleware, it can be seamlessly integrated into your existing infrastructure to handle authentication for multiple applications.

OAuth2 Proxy supports a lot of OAuth2 as well as OIDC providers. Either through a generic OIDC client or a specific implementation for Google, Microsoft Entra ID, GitHub, login.gov and others. Through specialised provider implementations OAuth2 Proxy can extract more details about the user like preferred usernames and groups. Those details can then be forwarded as HTTP headers to your upstream applications.

Simplified Architecture

Get Started

OAuth2 Proxy's Installation Docs cover how to install and configure your setup. Additionally you can take a further look at the example setup files.

Releases

Binaries

We publish OAuth2 Proxy as compiled binaries on GitHub for all major architectures as well as more exotic ones like ppc64le as well as s390x.

Check out the latest release.

Images

From v7.6.0 and up the base image has been changed from Alpine to GoogleContainerTools/distroless. This image comes with even fewer installed dependencies and thus should improve security. The image therefore is also slightly smaller than Alpine. For debugging purposes (and those who really need it. e.g. armv6) we still provide images based on Alpine. The tags of these images are suffixed with -alpine.

Since 2023-11-18 we build nightly images directly from the master branch and provide them at quay.io/oauth2-proxy/oauth2-proxy-nightly. These images are considered unstable and therefore should NOT be used for production purposes unless you know what you're doing.

Sponsors

Would you like to sponsor the project then please contact us at sponsors@oauth2-proxy.dev

SAP

SAP Open Source Program

Former Sponsors

Microsoft

Microsoft Azure credits for open source projects

Getting Involved

Slack

Join the #oauth2-proxy Slack channel to chat with other users of OAuth2 Proxy or reach out to the maintainers directly. Use the public invite link to get an invite for the CNCF space.

OAuth2 Proxy is a community-driven project. We rely on the contribut️ions of our users to continually improve it. While review times can vary, we appreciate your patience and understanding. As a volunteer-driven project, we strive to keep this project stable and might take longer to merge changes.

If you want to contribute to the project. Please see our Contributing guide.

Thanks to all the people who already contributed ❤

Made with contrib.rocks.

Security

If you believe you have found a vulnerability within OAuth2 Proxy or any of its dependencies, please do NOT open an issue or PR on GitHub, please do NOT post any details publicly.

Security disclosures MUST be done in private. If you have found an issue that you would like to bring to the attention of the maintainers, please compose an email and send it to the list of people listed in our MAINTAINERS.md file.

For more details read our full Security Docs

Security Notice for v6.0.0 and older

If you are running a version older than v6.0.0 we strongly recommend to the current version.

See open redirect vulnerability for details.

Repository History

2018-11-27: This repository was forked from bitly/OAuth2_Proxy. Versions v3.0.0 and up are from this fork and will have diverged from any changes in the original fork. A list of changes can be seen in the CHANGELOG.

2020-03-29: This project was formerly hosted as pusher/oauth2_proxy but has been renamed to oauth2-proxy/oauth2-proxy. Going forward, all images shall be available at quay.io/oauth2-proxy/oauth2-proxy and binaries will be named oauth2-proxy.

Code of Conduct

Participation in the OAuth2 Proxy project is governed by the CNCF Code of Conduct.

License

OAuth2 Proxy is distributed under The MIT License.

FOSSA Status

Trademarks

OAuth2 Proxy is a Cloud Native Computing Foundation Sandbox project.

CNCF

The Linux Foundation® (TLF) has registered trademarks and uses trademarks. For a list of TLF trademarks, see Trademark Usage.

S
Description
A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many more identity providers.
Readme MIT
48 MiB
Languages
Go 98.3%
Makefile 0.8%
HTML 0.4%
Shell 0.3%
Dockerfile 0.2%