Repository navigation
Harden host handling, GitHub email linking, and password reset - #1099
Merged
Merged
Conversation
Add an optional ALLOWED_HOSTS env var. The request host is used only if it's in ALLOWED_HOSTS, is the Fly.io app hostname, or is localhost; otherwise the canonical host is used. Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security hardening for auth-related flows.
getDomainUrl(used for emailed verification links, passkey config, and the image optimizer's allowed origins) now uses the request'sHost/X-Forwarded-Hostonly if it is in the new optionalALLOWED_HOSTSenv var, is${FLY_APP_NAME}.fly.dev, or is localhost. Otherwise it uses the canonical host (firstALLOWED_HOSTSentry, then the Fly hostname, thenlocalhost:${PORT}). The new variable is documented inenv.server.ts,.env.example,docs/deployment.md,docs/security.md, and decision048-allowed-hosts.md./forgot-password. It's added tostrongPaths.safeRedirectfor itsredirectTo.SECURITY.mdpointing to GitHub private vulnerability reporting.Downstream apps
Apps generated from the Epic Stack won't get these changes automatically. We recommend:
getDomainUrlchange inapp/utils/misc.tsx. If you serve a custom domain, setALLOWED_HOSTS(e.g.fly secrets set ALLOWED_HOSTS=example.com,www.example.com). If you don't, emailed links fall back to<app>.fly.devand passkeys won't work on the custom domain.app/utils/providers/github.server.ts, useemails.find((e) => e.primary && e.verified)./forgot-passwordtostrongPathsinserver/index.ts.app/utils/auth.server.ts) and the theme switchsafeRedirect(app/routes/resources/theme-switch.tsx).Test Plan
forgot-password.test.ts: emailed links use only trusted hosts.callback.test.ts: an unverified GitHub primary email doesn't sign in or link an existing user.reset-password.test.ts: sessions are deleted on reset.theme-switch.test.ts: cross-originredirectTois rejected.start:mocks): emailed links ignore an untrusted forwarded host.npm run lint,npm run typecheck, andvitest runall pass.Checklist