Make auth cookie SameSite configurable
Add same-site to auth cookie config with lax as the default, PROBOD_AUTH_COOKIE_SAMESITE bootstrap mapping, and validation that rejects none unless Secure is enabled. Signed-off-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Bryan FRIMIN <bryan@frimin.fr>
This commit is contained in:
committed by
Bryan Frimin
parent
cd6c46212a
commit
62d0ab68c4
@@ -23,8 +23,34 @@ package probodconfig
|
||||
import (
|
||||
"encoding/base64"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"strings"
|
||||
)
|
||||
|
||||
type CookieSameSite string
|
||||
|
||||
const (
|
||||
CookieSameSiteLax CookieSameSite = "lax"
|
||||
CookieSameSiteStrict CookieSameSite = "strict"
|
||||
CookieSameSiteNone CookieSameSite = "none"
|
||||
)
|
||||
|
||||
func ParseCookieSameSite(raw string) (CookieSameSite, error) {
|
||||
switch strings.ToLower(strings.TrimSpace(raw)) {
|
||||
case "", string(CookieSameSiteLax):
|
||||
return CookieSameSiteLax, nil
|
||||
case string(CookieSameSiteStrict):
|
||||
return CookieSameSiteStrict, nil
|
||||
case string(CookieSameSiteNone):
|
||||
return CookieSameSiteNone, nil
|
||||
default:
|
||||
return "", fmt.Errorf(
|
||||
"invalid same-site value %q: must be lax, strict, or none",
|
||||
raw,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
type AuthConfig struct {
|
||||
Cookie CookieConfig `json:"cookie"`
|
||||
Password PasswordConfig `json:"password"`
|
||||
@@ -55,11 +81,38 @@ type OAuth2SigningKeyConfig struct {
|
||||
}
|
||||
|
||||
type CookieConfig struct {
|
||||
Domain string `json:"domain,omitempty"`
|
||||
Secret string `json:"secret"`
|
||||
Duration int `json:"duration"`
|
||||
Name string `json:"name,omitempty"`
|
||||
Secure bool `json:"secure"`
|
||||
Domain string `json:"domain,omitempty"`
|
||||
Secret string `json:"secret"`
|
||||
Duration int `json:"duration"`
|
||||
Name string `json:"name,omitempty"`
|
||||
Secure bool `json:"secure"`
|
||||
SameSite CookieSameSite `json:"same-site,omitempty"`
|
||||
}
|
||||
|
||||
func (c CookieConfig) HTTPSameSite() (http.SameSite, error) {
|
||||
switch c.SameSite {
|
||||
case "", CookieSameSiteLax:
|
||||
return http.SameSiteLaxMode, nil
|
||||
case CookieSameSiteStrict:
|
||||
return http.SameSiteStrictMode, nil
|
||||
case CookieSameSiteNone:
|
||||
return http.SameSiteNoneMode, nil
|
||||
default:
|
||||
return 0, fmt.Errorf("invalid cookie same-site value %q", c.SameSite)
|
||||
}
|
||||
}
|
||||
|
||||
func (c CookieConfig) Validate() error {
|
||||
sameSite, err := c.HTTPSameSite()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
if sameSite == http.SameSiteNoneMode && !c.Secure {
|
||||
return fmt.Errorf("cookie same-site none requires secure cookies")
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
type PasswordConfig struct {
|
||||
|
||||
Reference in New Issue
Block a user