mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-01 12:11:19 +02:00
* Strip the port from the request host when matching cookie domains GetCookieDomain suffix-matches the request host against each configured cookie domain. When a reverse proxy rewrites the Host header to the upstream's address, that host arrives as "host:port" and never matches, so the request falls through to the "did not match any of the specific cookie domains" warning and the shortest configured domain is used. One way to hit this is Traefik's Errors middleware: it fetches a page from a Service on port 443 with passHostHeader disabled, and forwards the Host as "<host>:443". The request reaches oauth2-proxy correctly and the resulting cookie is still usable, but every such request logs an error that suggests a misconfiguration when none exists. warnInvalidDomain, a few lines below in the same file, already calls net.SplitHostPort on the host before comparing it to the cookie domain. This makes GetCookieDomain consistent with it. Tests cover a Host header with a port, an X-Forwarded-Host header with a port, a non-standard port, and a host with a port that matches no configured domain. Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com> * chore: add changelog entry for #3546 Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com> * test: keep the new port entries at the end of the table The port cases were inserted between the Host and X-Forwarded-Host variants of the existing suffix-match case, which split a pair that reads as one. Move them after the last existing entry instead. Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com> * test: pin that a port part can no longer match a cookie domain SplitHostPort does not require the port to be numeric, so a host such as "evil.com:.cookies.test" used to suffix-match a configured cookie domain through its port part, and the cookie was then set for that domain. Matching now runs against the host alone, so it does not. Covers both the Host header and X-Forwarded-Host, since GetRequestHost returns one or the other into the same comparison. A Host of this shape cannot be expressed through the request URL, because http.NewRequest rejects it as an invalid port, so the table gains a rawHost field that assigns req.Host after the request is built. That is how a server populates it from the wire, and pkg/upstream and pkg/middleware already set req.Host the same way in their tests. Thanks to @Lrifton92 for spotting this. Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com> --------- Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>