The proxy's protocol header is believed whoever sends it #60
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#60
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What happens
config/settings/prod.pysets, unconditionally:From then on, any request carrying
X-Forwarded-Proto: httpsis treated as secure —including one that arrived over plain HTTP straight from the client. Django's own
documentation is blunt about this: set it only if you are certain the proxy strips the
header from what it receives.
Why it matters on a self-hosted instance
The assumption is that a reverse proxy always sits in front. Plenty of Postulo deployments
will not: the Compose file publishes port 8000, and "just expose the port" is a normal
thing for somebody to do on their own network, or briefly through a port forward.
With the header believed, on such an instance:
SECURE_SSL_REDIRECTstops redirecting, because the request already claims to besecure;
Secureon a connection that is not, so thebrowser then refuses to send them back, and sign-in fails in a way that looks like a
bug;
request.is_secure()is a lie anywhere it is used, including in any absolute URL builtfor an email.
Shape
POSTULO_TRUST_PROXY_HEADER, default off, and only then setSECURE_PROXY_SSL_HEADER. An operator who runs a proxy sets one variable; one who doesnot is not quietly told a lie about their own traffic.
somebody will read it before they need it.
USE_X_FORWARDED_HOSTandX-Forwarded-Forwhile in here: the same argumentapplies to anything else taken on trust from in front, and the rate limits of the
companion issue key on the address they are told.
Classification
Bug, security. Breaking for anyone already behind a proxy if the default flips — so
the release note has to say it plainly and name the variable.