fix(proxy): SameSite=Lax on share_gate cookie to fix Safari/Firefox redirect
Deploy Caddyfile to valhalla / deploy (push) Successful in 2m19s
Deploy Caddyfile to valhalla / deploy (push) Successful in 2m19s
SameSite=Strict caused Safari and Firefox to drop the freshly-set cookie on the immediate same-site redirect when the top-level navigation originated from an external app (Discord). SameSite=Lax explicitly permits the cookie on same-site redirects regardless of the initiating context. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
d654e6df90
commit
847edff1f8
@@ -39,15 +39,17 @@
|
||||
# Shared-link gate — external users visit ?k=<SHARE_KEY> once to get a 30-day cookie.
|
||||
# Internal IPs and tailnet clients pass through unconditionally.
|
||||
# Usage: import share_gate (replaces import internal_only on shared services)
|
||||
# Uses {$SHARE_KEY} (parse-time substitution) — baked in at caddy reload/start when the
|
||||
# env var is set. Rotate: update SHARE_KEY in stack.env, push → Portainer redeploys → key changes.
|
||||
# Uses {$SHARE_KEY} (parse-time substitution) — baked in at caddy reload/start.
|
||||
# SameSite=Lax (not Strict): Strict causes Safari/Firefox to drop the cookie on the
|
||||
# redirect when the top-level navigation originated from an external app (Discord).
|
||||
# Rotate: update SHARE_KEY in stack.env, push → Portainer redeploys → new key.
|
||||
(share_gate) {
|
||||
@external not remote_ip 192.168.1.0/24 172.16.0.0/12 100.64.0.0/10 127.0.0.1
|
||||
handle @external {
|
||||
route {
|
||||
@has_key query k={$SHARE_KEY}
|
||||
handle @has_key {
|
||||
header Set-Cookie "share_access={$SHARE_KEY}; Path=/; Max-Age=2592000; HttpOnly; Secure; SameSite=Strict"
|
||||
header Set-Cookie "share_access={$SHARE_KEY}; Path=/; Max-Age=2592000; HttpOnly; Secure; SameSite=Lax"
|
||||
redir {http.request.uri.path} 302
|
||||
}
|
||||
@has_cookie expression `{http.request.cookie.share_access} == "{$SHARE_KEY}"`
|
||||
|
||||
Reference in New Issue
Block a user