Fix CSRF token injection for __Host- prefixed cookies - #2082
Closed
joemahady-comm wants to merge 1 commit into
Closed
Fix CSRF token injection for __Host- prefixed cookies#2082joemahady-comm wants to merge 1 commit into
joemahady-comm wants to merge 1 commit into
Conversation
Co-authored-by: Cursor <cursoragent@cursor.com>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Are you submitting this PR against the develop branch?
Yes.
What is this change about?
This change updates the SSO helper to inject both the legacy X-Uaa-Csrf cookie and the new __Host-X-Uaa-Csrf cookie during the AuthorizeScopes curl request.
Recent changes in UAA (specifically to fix double submit CSRF cookies) introduced the __Host- prefix for the CSRF cookie when running over HTTPS. Because CATs tests run with --insecure, UAA expects the __Host-X-Uaa-Csrf cookie to be present. Injecting both cookie names ensures the test continues to pass regardless of whether the UAA server expects the legacy cookie name or the new __Host- prefixed cookie name.
Please provide contextual information.
This fixes a test failure caused by UAA commit 5b0deddb3 ("Fix double submit csrf cookie") which enforces the __Host- prefix on the CSRF cookie for secure connections.
What version of cf-deployment have you run this cf-acceptance-test change against?
Please check all that apply for this PR:
Did you update the README as appropriate for this change?
If you are introducing a new acceptance test, what is your rationale for including it CATs rather than your own acceptance test suite?
N/A - fixing an existing test helper.
CATs should validate common operator workflows.
CATs is not a regression test suite.
CATs is run by every component team to validate their releases before promotion.
How many more (or fewer) seconds of runtime will this change introduce to CATs?
0 seconds.
What is the level of urgency for publishing this change?
Tag your pair, your PM, and/or team!