Account for hosts with/without ports in origin check
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Accessibilité débutants
- 25/100
- Type d'issue
- Bug
- Clarté
- Plutôt claire
- Activité
- À l'abandon
- Stack technique
- typescript
- Domaine
- security
Piste de recherche
Commencez par reproduire la comparaison entre Origin et Host avec la configuration NGINX proxy_set_header fournie, puis examinez les issues associées 6161, 6023, 6064 et 6014. Déterminez le traitement attendu des ports par défaut et non par défaut ; le travail est terminé lorsque la vérification de l’origine du websocket accepte systématiquement les configurations correspondantes valides sans affaiblir ses garanties de sécurité.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Is there an existing issue for this?
- I have searched the existing issues
OS/Web Information
N/A
Steps to Reproduce
You can simulate with this NGINX config:
proxy_set_header X-Forwarded-Host $host:$server_port;
Expected
If your origin is https://domain.tld and your host is domain.tld:443 the check should pass. Same for http://domain.tld and domain.tld:80.
Also I think NGINX's $host actually does not include ports so it will fail if your config only has $host and if you host on a port other than 443 and 80 since you would get an origin like https://domain.tld:8080 and the host would be domain.tld.
To fix the first we could just check the protocol on the origin and then add/remove 443 or 80.
For the second we could ignore the port altogether since I think the vulnerability does not happen across ports...
But I am not sure we should do anything; maybe the correct course of action is to edit the proxy config so the host and origin headers match. I have looked at other software but they all seem to do exact matches without messing around with the port. We could just edit the documentation to use $http_host.
Actual
The origin and domain are matched exactly so they do not match. Ends up causing the web sockets to fail with 1006.
Logs
No response
Screenshot/Video
No response
Does this issue happen in VS Code or GitHub Codespaces?
- I cannot reproduce this in VS Code.
- I cannot reproduce this in GitHub Codespaces.
Are you accessing code-server over HTTPS?
- I am using HTTPS.
Notes
https://github.com/coder/code-server/issues/6161
Might be causing issues reported in https://github.com/coder/code-server/issues/6023 and https://github.com/coder/code-server/issues/6064 as well.
And possibly https://github.com/coder/code-server/issues/6014
- Langage dominant
- TypeScript
- Étoiles
- 79.4k
- Forks
- 6.9k
- Merge moyen
- 2 j 13 h
- PR mergées (30 j)
- 39
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de coder/code-server
-
Difficulté 1/5 Moins d'une heure Accessibilité débutants 92/100
coder/code-server#8017 · 2 commentaires ·
-
Bump proxy-addr to 2.0.8 Ouvertesecurity
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
coder/code-server#8013 · 4 commentaires ·
-
enhancement
Difficulté 5/5 Plus d'une semaine Accessibilité débutants 35/100
coder/code-server#7976 · 2 commentaires ·
-
enhancement
Difficulté 5/5 Plus d'une semaine Accessibilité débutants 35/100
coder/code-server#7962 · 3 commentaires ·
-
bug needs-investigation
Difficulté 4/5 3-5 jours Accessibilité débutants 55/100
coder/code-server#7955 · 1 commentaire ·
Toutes les issues de coder/code-server
Issues similaires
-
VerificationGate: ATTRIBUTION quote guard never matches a normal quotation (\b around the quote) Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
danielmiessler/LifeOS#2234 ·
-
T: Bug
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 65/100
-
Difficulté 1/5 Moins d'une heure Accessibilité débutants 85/100
-
Mend: dependency security vulnerability untriaged
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100