mirror of
https://github.com/pocket-id/pocket-id.git
synced 2025-12-09 14:42:59 +03:00
[PR #175] [MERGED] fix: add __HOST prefix to cookies
#935
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/pocket-id/pocket-id/pull/175
Author: @stonith404
Created: 1/24/2025
Status: ✅ Merged
Merged: 1/24/2025
Merged by: @stonith404
Base:
main← Head:fix/host-cookies📝 Commits (2)
d34f8b4add__HOSTprefix to cookies4e568e5only use__Hostprefix if https is enabled📊 Changes
21 files changed (+80 additions, -46 deletions)
View changed files
📝
backend/internal/controller/user_controller.go(+10 -2)📝
backend/internal/controller/webauthn_controller.go(+11 -7)📝
backend/internal/middleware/jwt_auth.go(+2 -1)➕
backend/internal/utils/cookie/add_cookie.go(+13 -0)➕
backend/internal/utils/cookie/cookie_names.go(+16 -0)➖
backend/internal/utils/cookie_util.go(+0 -12)📝
frontend/src/hooks.server.ts(+2 -1)➕
frontend/src/lib/constants.ts(+2 -0)📝
frontend/src/routes/+layout.server.ts(+3 -2)📝
frontend/src/routes/authorize/+page.server.ts(+2 -1)📝
frontend/src/routes/settings/account/+page.server.ts(+3 -2)📝
frontend/src/routes/settings/admin/application-configuration/+page.server.ts(+2 -1)📝
frontend/src/routes/settings/admin/oidc-clients/+page.server.ts(+2 -1)📝
frontend/src/routes/settings/admin/oidc-clients/[id]/+page.server.ts(+2 -1)📝
frontend/src/routes/settings/admin/user-groups/+page.server.ts(+2 -1)📝
frontend/src/routes/settings/admin/user-groups/[id]/+page.server.ts(+2 -1)📝
frontend/src/routes/settings/admin/users/+page.server.ts(+2 -1)📝
frontend/src/routes/settings/admin/users/[id]/+page.server.ts(+2 -1)📝
frontend/src/routes/settings/audit-log/+page.server.ts(+2 -1)📝
reverse-proxy/Caddyfile(+0 -5)...and 1 more files
📄 Description
Fixes #171. Without the
__HOSTprefix another subdomain could write the "access_token" cookie which results in a redirection loop.🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.