Files
oauth2-proxy/pkg
kirilju 8f8d1f4eb3 fix: strip the port from the request host when matching cookie domains (#3546)
* Strip the port from the request host when matching cookie domains

GetCookieDomain suffix-matches the request host against each configured
cookie domain. When a reverse proxy rewrites the Host header to the
upstream's address, that host arrives as "host:port" and never matches,
so the request falls through to the "did not match any of the specific
cookie domains" warning and the shortest configured domain is used.

One way to hit this is Traefik's Errors middleware: it fetches a page
from a Service on port 443 with passHostHeader disabled, and forwards
the Host as "<host>:443". The request reaches oauth2-proxy correctly and
the resulting cookie is still usable, but every such request logs an
error that suggests a misconfiguration when none exists.

warnInvalidDomain, a few lines below in the same file, already calls
net.SplitHostPort on the host before comparing it to the cookie domain.
This makes GetCookieDomain consistent with it.

Tests cover a Host header with a port, an X-Forwarded-Host header with a
port, a non-standard port, and a host with a port that matches no
configured domain.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* chore: add changelog entry for #3546

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* test: keep the new port entries at the end of the table

The port cases were inserted between the Host and X-Forwarded-Host
variants of the existing suffix-match case, which split a pair that
reads as one. Move them after the last existing entry instead.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* test: pin that a port part can no longer match a cookie domain

SplitHostPort does not require the port to be numeric, so a host such as
"evil.com:.cookies.test" used to suffix-match a configured cookie domain
through its port part, and the cookie was then set for that domain. Matching
now runs against the host alone, so it does not.

Covers both the Host header and X-Forwarded-Host, since GetRequestHost
returns one or the other into the same comparison.

A Host of this shape cannot be expressed through the request URL, because
http.NewRequest rejects it as an invalid port, so the table gains a rawHost
field that assigns req.Host after the request is built. That is how a server
populates it from the wire, and pkg/upstream and pkg/middleware already set
req.Host the same way in their tests.

Thanks to @Lrifton92 for spotting this.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

---------

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>
2026-09-30 17:31:29 +02:00
..
2026-04-13 18:22:56 +02:00
2025-11-16 22:38:40 +01:00
2026-04-13 18:22:56 +02:00
2021-03-21 18:20:57 +00:00
2022-10-21 11:57:51 +01:00