From 6b4dcac7a12e6211e62baf4e0446dbeef33dd2a4 Mon Sep 17 00:00:00 2001 From: inference-bot Date: Wed, 23 Sep 2026 09:45:52 -0600 Subject: [PATCH] =?UTF-8?q?Phase=204:=20remove=20proxyAuth=20header=20fall?= =?UTF-8?q?back=20=E2=80=94=20identity=20only=20from=20OIDC=20session?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- app/main.py | 31 +++++++++---------------------- 1 file changed, 9 insertions(+), 22 deletions(-) diff --git a/app/main.py b/app/main.py index df1565b..00b3e63 100644 --- a/app/main.py +++ b/app/main.py @@ -40,29 +40,16 @@ app = FastAPI() def get_identity(request: Request) -> str: """Return the authenticated user's identity (Cloudron username). - Priority: a validated OIDC session cookie (when the oidc addon is active), - then the proxyAuth header (legacy, and the fallback during the transition). + Reads the validated OIDC session cookie. No header fallback — the app no + longer trusts a client-supplied identity header (that path existed only + during the proxyAuth → OIDC transition and is now removed). """ - # OIDC session cookie (only when the addon is configured). - if oidc.is_oidc_configured(): - token = request.cookies.get(oidc.SESSION_COOKIE) - if token: - identity = oidc.read_session(token) - if identity: - return identity - - # Legacy proxyAuth header fallback. - for header in ( - "x-remote-user", - "x-forwarded-user", - "x-auth-request-user", - "x-auth-request-email", - "x-forwarded-email", - ): - val = request.headers.get(header) - if val: - return val.strip() - return "" + if not oidc.is_oidc_configured(): + return "" + token = request.cookies.get(oidc.SESSION_COOKIE) + if not token: + return "" + return oidc.read_session(token) or "" def is_admin(request: Request) -> bool: