Skip to content

Fix authentication redirects and proxy handling for subfolder deployments - #258

Merged
bifrost0x merged 4 commits into
mainfrom
dev/issue-257-proxy-prefix
Oct 9, 2026
Merged

bifrost0x merged 4 commits into
mainfrom
dev/issue-257-proxy-prefix

Conversation

@bifrost0x

@bifrost0x bifrost0x commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Problem and outcome

Authentication redirects can lose or duplicate a deployment prefix. Socket.IO also bypasses the existing ProxyFix wrapper, so HTTP and Engine.IO see different public connection details.

Normalize completed authentication return paths on the server and let browser handlers use those public paths directly. Apply ProxyFix before Socket.IO dispatch. Add bounded connection-error notices, admission diagnostics, and complete Apache/HAProxy examples.

Scope and links

Refs #257.
Three separate commits cover authentication redirects, ProxyFix ordering, and diagnostics/documentation/regression coverage. No release milestone assigned.

Validation

Tested file contents match head 07378fd04badd6292a9bca178f8fe633e9615e8c, based on 94c16fef6f3178a068d223a50f0f21ef64d82d83.

  • 57 prefix regression cases passed, including root, /webssh, /tools/webssh, query preservation, unsafe targets, trust depths 0/1/2, authenticated polling, and negative origin/path checks.
  • 687 JavaScript tests and 11 selected root-deployment browser tests passed. JavaScript lint, vendor integrity, and diff checks passed.
  • Python 3.14: 3,458 passed, 6 failed, 53 skipped. The same six failing cases also fail on the unchanged base under Python 3.12.
  • Python 3.11: 3,457 passed, 7 failed, 53 skipped. The additional parallel timing failure passed when rerun in isolation.
  • Prefix MFA coverage uses real TOTP/recovery codes and a simulated WebAuthn authenticator; provider callbacks use simulated providers.

Root redirects retain their existing paths. Cookie settings, CORS configuration, worker count, and authentication requirements are unchanged. ProxyFix ordering intentionally also affects root deployments behind a reverse proxy, which must supply headers consistent with TRUSTED_PROXIES.

@bifrost0x
bifrost0x marked this pull request as ready for review October 9, 2026 07:07
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T07:09:47.351604Z 07378fd Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@bifrost0x bifrost0x linked an issue Oct 9, 2026 that may be closed by this pull request
@bifrost0x bifrost0x self-assigned this Oct 9, 2026
@bifrost0x bifrost0x added bug Something isn't working dependencies Pull requests that update a dependency file docker Docker and container image updates labels Oct 9, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 07378fd04b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread app/auth_redirects.py
@bifrost0x
bifrost0x merged commit 7fe92b1 into main Oct 9, 2026
26 checks passed
@bifrost0x
bifrost0x deleted the dev/issue-257-proxy-prefix branch October 9, 2026 07:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working dependencies Pull requests that update a dependency file docker Docker and container image updates

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

Deployment: subfolder behind reverse-proxy (haproxy preferred)

1 participant