Skip to content

Include browser port in sign-on dialog URL - #4

Open
cgalo5758 wants to merge 1 commit into
fedwiki:mainfrom
cgalo5758:fix/dialog-url-port
Open

Include browser port in sign-on dialog URL#4
cgalo5758 wants to merge 1 commit into
fedwiki:mainfrom
cgalo5758:fix/dialog-url-port

Conversation

@cgalo5758

Copy link
Copy Markdown
Contributor

Following on from the secure cookies change: a farm can now run over plain http on any port, but the sign-on dialog still opens on the portless farm domain. On http://site.localtest.me:8092 the popup goes to port 80 and never loads.

The client used one value for both the dialog host and the cookie domain. A dialog URL needs the port, but a cookie domain= attribute must not have one, so appending the port server-side would break the cookies. This splits them: cookieDomain stays portless (wikiHost, falling back to location.hostname) and the dialog host adds location.port when present. expectOrigin follows from the dialog URL, and the wikiName cookie value keeps location.host with the port, which done.html needs for its postMessage target.

This also fixes the standalone fallback, which put host:port into the cookie domain= attribute. Browsers reject that, so those cookies were silently dropped on non-default ports.

This is the client half: in farm mode the farm runner also strips the port from each site's url option, so trusted origins stay portless. There's a matching PR for that in fedwiki/wiki. On default ports nothing changes.

Tested: npm run build:client and prettier pass (npm test... there is nothing for that yet... so not doing it)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant