diff --git a/app/main.py b/app/main.py index 90d7701..2c3c101 100644 --- a/app/main.py +++ b/app/main.py @@ -39,29 +39,16 @@ app = FastAPI() def get_user_identity(request: Request) -> str: """Return the logged-in user's identity (Cloudron username). - Priority: a validated OIDC session cookie (when the oidc addon is active), - then the proxyAuth header (legacy fallback during the transition). + Reads the validated OIDC session cookie. No header fallback — the app no + longer trusts a client-supplied identity header (that path existed only + during the proxyAuth → OIDC transition and is now removed). """ - # OIDC session cookie (only when the addon is configured). - if oidc.is_oidc_configured(): - token = request.cookies.get(oidc.SESSION_COOKIE) - if token: - identity = oidc.read_session(token) - if identity: - return identity - - # Legacy proxyAuth header fallback. - for header in ( - "x-remote-user", - "x-forwarded-user", - "x-auth-request-user", - "x-auth-request-email", - "x-forwarded-email", - ): - val = request.headers.get(header) - if val: - return val.strip() - return "" + if not oidc.is_oidc_configured(): + return "" + token = request.cookies.get(oidc.SESSION_COOKIE) + if not token: + return "" + return oidc.read_session(token) or "" # ---------------------------------------------------------------------------