Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

Account for hosts with/without ports in origin check

Ouverte
#6,166 2 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
25/100
Type d'issue
Bug
Clarté
Plutôt claire
Activité
À l'abandon
Stack technique
typescript
Domaine
security

Piste de recherche

Commencez par reproduire la comparaison entre Origin et Host avec la configuration NGINX proxy_set_header fournie, puis examinez les issues associées 6161, 6023, 6064 et 6014. Déterminez le traitement attendu des ports par défaut et non par défaut ; le travail est terminé lorsque la vérification de l’origine du websocket accepte systématiquement les configurations correspondantes valides sans affaiblir ses garanties de sécurité.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

bug
Is there an existing issue for this?
  • I have searched the existing issues
OS/Web Information

N/A

Steps to Reproduce

You can simulate with this NGINX config:

proxy_set_header X-Forwarded-Host $host:$server_port;
Expected

If your origin is https://domain.tld and your host is domain.tld:443 the check should pass. Same for http://domain.tld and domain.tld:80.

Also I think NGINX's $host actually does not include ports so it will fail if your config only has $host and if you host on a port other than 443 and 80 since you would get an origin like https://domain.tld:8080 and the host would be domain.tld.

To fix the first we could just check the protocol on the origin and then add/remove 443 or 80.

For the second we could ignore the port altogether since I think the vulnerability does not happen across ports...

But I am not sure we should do anything; maybe the correct course of action is to edit the proxy config so the host and origin headers match. I have looked at other software but they all seem to do exact matches without messing around with the port. We could just edit the documentation to use $http_host.

Actual

The origin and domain are matched exactly so they do not match. Ends up causing the web sockets to fail with 1006.

Logs

No response

Screenshot/Video

No response

Does this issue happen in VS Code or GitHub Codespaces?
  • I cannot reproduce this in VS Code.
  • I cannot reproduce this in GitHub Codespaces.
Are you accessing code-server over HTTPS?
  • I am using HTTPS.
Notes

https://github.com/coder/code-server/issues/6161

Might be causing issues reported in https://github.com/coder/code-server/issues/6023 and https://github.com/coder/code-server/issues/6064 as well.

And possibly https://github.com/coder/code-server/issues/6014

Langage dominant
TypeScript
Étoiles
79.4k
Forks
6.9k
Merge moyen
2 j 13 h
PR mergées (30 j)
39

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de coder/code-server

Toutes les issues de coder/code-server

Issues similaires

Plus d'issues TypeScript

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.