Phase 4: remove proxyAuth header fallback — identity only from OIDC session
This commit is contained in:
1 parent
ebddf0c698
commit
6b4dcac7a1
1 file changed
+9
-22
+9
-22
@@ -40,29 +40,16 @@ app = FastAPI()
|
||||
def get_identity(request: Request) -> str:
|
||||
"""Return the authenticated user's identity (Cloudron username).
|
||||
|
||||
Priority: a validated OIDC session cookie (when the oidc addon is active),
|
||||
then the proxyAuth header (legacy, and the fallback during the transition).
|
||||
Reads the validated OIDC session cookie. No header fallback — the app no
|
||||
longer trusts a client-supplied identity header (that path existed only
|
||||
during the proxyAuth → OIDC transition and is now removed).
|
||||
"""
|
||||
# OIDC session cookie (only when the addon is configured).
|
||||
if oidc.is_oidc_configured():
|
||||
token = request.cookies.get(oidc.SESSION_COOKIE)
|
||||
if token:
|
||||
identity = oidc.read_session(token)
|
||||
if identity:
|
||||
return identity
|
||||
|
||||
# Legacy proxyAuth header fallback.
|
||||
for header in (
|
||||
"x-remote-user",
|
||||
"x-forwarded-user",
|
||||
"x-auth-request-user",
|
||||
"x-auth-request-email",
|
||||
"x-forwarded-email",
|
||||
):
|
||||
val = request.headers.get(header)
|
||||
if val:
|
||||
return val.strip()
|
||||
return ""
|
||||
if not oidc.is_oidc_configured():
|
||||
return ""
|
||||
token = request.cookies.get(oidc.SESSION_COOKIE)
|
||||
if not token:
|
||||
return ""
|
||||
return oidc.read_session(token) or ""
|
||||
|
||||
|
||||
def is_admin(request: Request) -> bool:
|
||||
|
||||
Reference in new issue
Block a user