Phase 4: remove proxyAuth header fallback — identity only from OIDC session
This commit is contained in:
1 parent
ebddf0c698
commit
6b4dcac7a1
1 file changed
+9
-22
+9
-22
@@ -40,29 +40,16 @@ app = FastAPI()
|
|||||||
def get_identity(request: Request) -> str:
|
def get_identity(request: Request) -> str:
|
||||||
"""Return the authenticated user's identity (Cloudron username).
|
"""Return the authenticated user's identity (Cloudron username).
|
||||||
|
|
||||||
Priority: a validated OIDC session cookie (when the oidc addon is active),
|
Reads the validated OIDC session cookie. No header fallback — the app no
|
||||||
then the proxyAuth header (legacy, and the fallback during the transition).
|
longer trusts a client-supplied identity header (that path existed only
|
||||||
|
during the proxyAuth → OIDC transition and is now removed).
|
||||||
"""
|
"""
|
||||||
# OIDC session cookie (only when the addon is configured).
|
if not oidc.is_oidc_configured():
|
||||||
if oidc.is_oidc_configured():
|
return ""
|
||||||
token = request.cookies.get(oidc.SESSION_COOKIE)
|
token = request.cookies.get(oidc.SESSION_COOKIE)
|
||||||
if token:
|
if not token:
|
||||||
identity = oidc.read_session(token)
|
return ""
|
||||||
if identity:
|
return oidc.read_session(token) or ""
|
||||||
return identity
|
|
||||||
|
|
||||||
# Legacy proxyAuth header fallback.
|
|
||||||
for header in (
|
|
||||||
"x-remote-user",
|
|
||||||
"x-forwarded-user",
|
|
||||||
"x-auth-request-user",
|
|
||||||
"x-auth-request-email",
|
|
||||||
"x-forwarded-email",
|
|
||||||
):
|
|
||||||
val = request.headers.get(header)
|
|
||||||
if val:
|
|
||||||
return val.strip()
|
|
||||||
return ""
|
|
||||||
|
|
||||||
|
|
||||||
def is_admin(request: Request) -> bool:
|
def is_admin(request: Request) -> bool:
|
||||||
|
|||||||
Reference in new issue
Block a user