Phase 4: remove proxyAuth header fallback — identity only from OIDC session

This commit is contained in:
inference-bot committed 2026-09-23 09:45:52 -06:00
1 parent ebddf0c698
commit 6b4dcac7a1
1 file changed
+9 -22
+9 -22
View File
@@ -40,29 +40,16 @@ app = FastAPI()
def get_identity(request: Request) -> str:
"""Return the authenticated user's identity (Cloudron username).
Priority: a validated OIDC session cookie (when the oidc addon is active),
then the proxyAuth header (legacy, and the fallback during the transition).
Reads the validated OIDC session cookie. No header fallback — the app no
longer trusts a client-supplied identity header (that path existed only
during the proxyAuth → OIDC transition and is now removed).
"""
# OIDC session cookie (only when the addon is configured).
if oidc.is_oidc_configured():
token = request.cookies.get(oidc.SESSION_COOKIE)
if token:
identity = oidc.read_session(token)
if identity:
return identity
# Legacy proxyAuth header fallback.
for header in (
"x-remote-user",
"x-forwarded-user",
"x-auth-request-user",
"x-auth-request-email",
"x-forwarded-email",
):
val = request.headers.get(header)
if val:
return val.strip()
return ""
if not oidc.is_oidc_configured():
return ""
token = request.cookies.get(oidc.SESSION_COOKIE)
if not token:
return ""
return oidc.read_session(token) or ""
def is_admin(request: Request) -> bool: