Repository navigation
Support fixed public-origin website sessions - #45
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The security-sensitive Host, Origin, and trusted-forwarding boundary warrants final human validation despite comprehensive tests.
Review effort: Balanced
Findings: None
What changed in this PR
Adds an opt-in public HTTPS identity for website cover sessions while preserving fixed upstream routing and TLS.
Changes:
- Adds strict public-origin validation, Host/Origin guards, and forwarding-header sanitization.
- Integrates CLI/JSON configuration and offline validation.
- Adds comprehensive API, protocol, session, WebSocket, and configuration tests.
| File | Description |
|---|---|
internal/cover/public_origin.go |
Implements public-origin policy and validation. |
internal/cover/handler.go |
Applies public Host and trusted forwarding fields. |
internal/cover/public_origin_test.go |
Tests policy, routing, sanitization, and concurrency. |
internal/tunnel/web_cover_public_origin_test.go |
Tests sessions and protocols over verified TLS. |
cmd/autocar/server.go |
Adds CLI/JSON configuration support. |
cmd/autocar/web_public_origin_test.go |
Tests command validation and preflight behavior. |
docs/WEB_COVER.md |
Documents requirements and security boundaries. |
docs/DEPLOYMENT.md |
Adds deployment and rollback guidance. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Add opt-in
--cover-public-originfor an owned website's public HTTPS virtual host. Upstream URL, dialing, certificate verification and SNI remain fixed; only outbound HTTP Host and two trusted forwarding fields use the configured public origin.The default constructor, concrete ReverseProxy type, upstream Host and base-path/query behavior remain unchanged. No tunnel wire-protocol change.
Boundaries
Validation
Frozen eight-file change plus module-input manifest; no dependency changes.
make checkandmake racepassed.GitHub validation completed on the exact PR head
25176cc6a1cb9ec40c05ebf0533fe0aa108d3371and source-equivalent synthetic merge7ce277d6c95492ca528e348aed06ec3a25e52561(treed7207923756171e183138a48551ff93c95425b76, parents base + head): CI 11/11, CodeQL, and existing native Linux netem control all passed on attempt 1. Automated review is COMMENTED with no findings and zero review threads, not human APPROVED. Its generic security-boundary reminder was independently reviewed; operators still must validate their backend trust and site policy before enabling. No release/tag, SSH, remote deployment, public-network experiment, traffic corpus or passive-fingerprint/parity claim.Merged main verification
Merged as
0a23ee20d28f642557e5dc7841cb842cd293a6d9, same source treed7207923756171e183138a48551ff93c95425b76, parent236bfc2335ec3c8a6fba834eb4248ae5f2384b6f. Local main is clean and source-manifest-equivalent; Go 1.25.13 focused race x3 passed again (567 RUN/PASS, zero failures/skips). Fresh push/attempt-1 main CI 11/11, main CodeQL, and main native netem control all passed. Actual key CI job logs directly checked out this main SHA, including Go double-version/race package execution, container integration, both architecture builds and OCI export. No release/tag or remote deployment was created.