Phase 4: remove proxyAuth header fallback — identity only from OIDC session

This commit is contained in:
inference-bot committed 2026-09-23 14:14:59 -06:00
1 parent 506eced854
commit 7c7f8840c3
1 file changed
+9 -22
+9 -22
View File
@@ -39,29 +39,16 @@ app = FastAPI()
def get_user_identity(request: Request) -> str: def get_user_identity(request: Request) -> str:
"""Return the logged-in user's identity (Cloudron username). """Return the logged-in user's identity (Cloudron username).
Priority: a validated OIDC session cookie (when the oidc addon is active), Reads the validated OIDC session cookie. No header fallback — the app no
then the proxyAuth header (legacy fallback during the transition). longer trusts a client-supplied identity header (that path existed only
during the proxyAuth → OIDC transition and is now removed).
""" """
# OIDC session cookie (only when the addon is configured). if not oidc.is_oidc_configured():
if oidc.is_oidc_configured(): return ""
token = request.cookies.get(oidc.SESSION_COOKIE) token = request.cookies.get(oidc.SESSION_COOKIE)
if token: if not token:
identity = oidc.read_session(token) return ""
if identity: return oidc.read_session(token) or ""
return identity
# Legacy proxyAuth header fallback.
for header in (
"x-remote-user",
"x-forwarded-user",
"x-auth-request-user",
"x-auth-request-email",
"x-forwarded-email",
):
val = request.headers.get(header)
if val:
return val.strip()
return ""
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------