Skip to content

Support fixed public-origin website sessions - #45

Merged
cppla merged 1 commit into
mainfrom
codex/cover-public-origin
Oct 2, 2026
Merged

cppla merged 1 commit into
mainfrom
codex/cover-public-origin

Conversation

@cppla

@cppla cppla commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Outcome

Add opt-in --cover-public-origin for an owned website's public HTTPS virtual host. Upstream URL, dialing, certificate verification and SNI remain fixed; only outbound HTTP Host and two trusted forwarding fields use the configured public origin.

The default constructor, concrete ReverseProxy type, upstream Host and base-path/query behavior remain unchanged. No tunnel wire-protocol change.

Boundaries

  • Root-only canonical ASCII HTTP(S) upstream / HTTPS public origins; strict DNS/IP/port validation and immutable configuration.
  • Website-only Host guard (421), single present same-public Origin guard (403), and original Origin/Referer Connection-nomination rejection before hop stripping.
  • Remove untrusted Forwarded, X-Forwarded-* and X-Real-IP from headers and declared request trailers; generate only fixed X-Forwarded-Host and HTTPS X-Forwarded-Proto.
  • No cookie, redirect, Origin, Referer, HTML or visitor-IP rewriting. Backend public-vhost/canonical-URL configuration, trusted-header whitelist and site CSRF/session policy remain required. Missing Origin is not proof of safety; do not merge security/trust trailers into headers.
  • Existing website WebSockets, OPTIONS asterisk, metadata/stream ownership and authenticated tunnel dispatch retain their paths. CLI/JSON/offline --check and rollback documented. Source-build feature, not in the v1.0.1 binary.

Validation

Frozen eight-file change plus module-input manifest; no dependency changes.

  • Go 1.25.13: final full make check and make race passed.
  • Public API matrix: 8 top-level groups, race x3; original map/config immutability, canonical authority/Origin, fixed destination, header/trailer scrub and byte-preserving site metadata.
  • Verified-TLS native H1/H2/H3: login + CSRF cookie/token + actual public redirect + session welcome + logout; bad Host/Origin never reaches the website or tunnel dialer. Real H1 WebSocket masked/unmasked frame echo. Connection nominations are real H1 probes only.
  • Go 1.27.1 focused race x3: 16 top-level groups, 567 group-inclusive RUN/PASS entries, zero failures/skips.
  • Local Linux/arm64 isolated network-none container, CGO=0 (not race): same 16 groups x3, 567 RUN/PASS entries; source/compiler/script/binaries unchanged, owned container removed.
  • Fresh isolated installed Chrome using the actual frozen CLI binary and loopback-only public hostname: sign in 303 → authenticated 200 → refresh 200 → logout 303 → signed-out 401 → refresh 401. Observed host-only __Host session cookie with Secure/HttpOnly/SameSite=Strict, absent after logout. Browser UI uses ignoreHTTPSErrors in a context confined to the owned self-signed fixture; separate native readiness/wire controls verify TLS. No claim of full browser cookie-policy enforcement or browser certificate validation.
  • Same owned actual-wire replayed-body/trailer diagnostic failed before new-mode trailer filtering and passed after, retaining ordinary trailer/payload. Old-API wrong-vhost session control is an optional compatibility gap, not a default-mode vulnerability.
  • Independent production, CLI/docs, API and wire-test reviews found no remaining must-fix.

GitHub validation completed on the exact PR head 25176cc6a1cb9ec40c05ebf0533fe0aa108d3371 and source-equivalent synthetic merge 7ce277d6c95492ca528e348aed06ec3a25e52561 (tree d7207923756171e183138a48551ff93c95425b76, parents base + head): CI 11/11, CodeQL, and existing native Linux netem control all passed on attempt 1. Automated review is COMMENTED with no findings and zero review threads, not human APPROVED. Its generic security-boundary reminder was independently reviewed; operators still must validate their backend trust and site policy before enabling. No release/tag, SSH, remote deployment, public-network experiment, traffic corpus or passive-fingerprint/parity claim.

Merged main verification

Merged as 0a23ee20d28f642557e5dc7841cb842cd293a6d9, same source tree d7207923756171e183138a48551ff93c95425b76, parent 236bfc2335ec3c8a6fba834eb4248ae5f2384b6f. Local main is clean and source-manifest-equivalent; Go 1.25.13 focused race x3 passed again (567 RUN/PASS, zero failures/skips). Fresh push/attempt-1 main CI 11/11, main CodeQL, and main native netem control all passed. Actual key CI job logs directly checked out this main SHA, including Go double-version/race package execution, container integration, both architecture builds and OCI export. No release/tag or remote deployment was created.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 21:42

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The security-sensitive Host, Origin, and trusted-forwarding boundary warrants final human validation despite comprehensive tests.

Review effort: Balanced
Findings: None

What changed in this PR

Adds an opt-in public HTTPS identity for website cover sessions while preserving fixed upstream routing and TLS.

Changes:

  • Adds strict public-origin validation, Host/Origin guards, and forwarding-header sanitization.
  • Integrates CLI/JSON configuration and offline validation.
  • Adds comprehensive API, protocol, session, WebSocket, and configuration tests.
File Description
internal/​cover/​public_origin.go Implements public-origin policy and validation.
internal/​cover/​handler.go Applies public Host and trusted forwarding fields.
internal/​cover/​public_origin_test.go Tests policy, routing, sanitization, and concurrency.
internal/​tunnel/​web_cover_public_origin_test.go Tests sessions and protocols over verified TLS.
cmd/​autocar/​server.go Adds CLI/JSON configuration support.
cmd/​autocar/​web_public_origin_test.go Tests command validation and preflight behavior.
docs/​WEB_COVER.md Documents requirements and security boundaries.
docs/​DEPLOYMENT.md Adds deployment and rollback guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@cppla
cppla merged commit 0a23ee2 into main Oct 2, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants