Skip to content

Fix CSRF token injection for __Host- prefixed cookies - #2082

Closed
joemahady-comm wants to merge 1 commit into
cloudfoundry:developfrom
joemahady-comm:cookie_tests
Closed

Fix CSRF token injection for __Host- prefixed cookies#2082
joemahady-comm wants to merge 1 commit into
cloudfoundry:developfrom
joemahady-comm:cookie_tests

Conversation

@joemahady-comm

Copy link
Copy Markdown
Contributor

Are you submitting this PR against the develop branch?

Yes.

What is this change about?

This change updates the SSO helper to inject both the legacy X-Uaa-Csrf cookie and the new __Host-X-Uaa-Csrf cookie during the AuthorizeScopes curl request.

Recent changes in UAA (specifically to fix double submit CSRF cookies) introduced the __Host- prefix for the CSRF cookie when running over HTTPS. Because CATs tests run with --insecure, UAA expects the __Host-X-Uaa-Csrf cookie to be present. Injecting both cookie names ensures the test continues to pass regardless of whether the UAA server expects the legacy cookie name or the new __Host- prefixed cookie name.

Please provide contextual information.

This fixes a test failure caused by UAA commit 5b0deddb3 ("Fix double submit csrf cookie") which enforces the __Host- prefix on the CSRF cookie for secure connections.

What version of cf-deployment have you run this cf-acceptance-test change against?

Please check all that apply for this PR:

  • introduces a new test --- Are you sure everyone should be running this test?
  • changes an existing test
  • requires an update to a CATs integration-config

Did you update the README as appropriate for this change?

  • YES
  • N/A

If you are introducing a new acceptance test, what is your rationale for including it CATs rather than your own acceptance test suite?

N/A - fixing an existing test helper.

CATs should validate common operator workflows.
CATs is not a regression test suite.
CATs is run by every component team to validate their releases before promotion.

How many more (or fewer) seconds of runtime will this change introduce to CATs?

0 seconds.

What is the level of urgency for publishing this change?

  • Urgent - unblocks current or future work
  • Slightly Less than Urgent

Tag your pair, your PM, and/or team!

Co-authored-by: Cursor <cursoragent@cursor.com>
@linux-foundation-easycla

Copy link
Copy Markdown

CLA Missing ID

  • ❌ The email address for the commit (acaab5b) is not linked to the GitHub account, preventing the EasyCLA check. Consult this Help Article and GitHub Help to resolve. (To view the commit's email address, add .patch at the end of this PR page's URL.) For further assistance with EasyCLA, please visit our EasyCLA portal and chat with our support bot.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant