Repository navigation
PAT-2167 Apps Proxy preview links (3/3): routing, session gate and docs - #2661
Merged
pepamartinec merged 2 commits intoSep 30, 2026
Merged
pepamartinec merged 2 commits into
pepamartinec merged 2 commits into
Conversation
pepamartinec
force-pushed
the
pepa/PAT-2167_app-preview-link
branch
from
September 29, 2026 13:57
abab227 to
8fc1189
Compare
This was referenced Sep 29, 2026
pepamartinec
changed the base branch from
main
to
pepa/PAT-2167_preview-2-session
September 29, 2026 13:59
pepamartinec
added this pull request to stack #2664
September 29, 2026 14:06
pepamartinec
force-pushed
the
pepa/PAT-2167_app-preview-link
branch
from
September 29, 2026 14:41
8fc1189 to
b8ed72e
Compare
pepamartinec
force-pushed
the
pepa/PAT-2167_app-preview-link
branch
from
September 29, 2026 15:06
b8ed72e to
cb4375e
Compare
pepamartinec
force-pushed
the
pepa/PAT-2167_app-preview-link
branch
from
September 29, 2026 15:18
cb4375e to
484871a
Compare
pepamartinec
force-pushed
the
pepa/PAT-2167_app-preview-link
branch
4 times, most recently
from
September 29, 2026 16:11
5e09995 to
0122146
Compare
pepamartinec
marked this pull request as ready for review
September 29, 2026 16:16
keboola-pr-reviewer-bot
left a comment
There was a problem hiding this comment.
Verdict: needs_human (risk 4/5) · profile psgo
Needs human: new signed-link session gate on the apps-proxy request path that bypasses apps' configured AuthRules in dev mode.
Impact flags: possible rollback re-introduction — see Check Run summary.
Concerns:
internal/pkg/service/appsproxy/proxy/apphandler/preview.go: New auth gate lets preview session skip app AuthRules in dev modeinternal/pkg/service/appsproxy/proxy/apphandler/apphandler.go: Routing reorder changes evaluation of /_proxy, kai-preview, session, AuthRulesdocs/apps-proxy/preview-link.md: Author-noted login-CSRF limitation left as follow-up, not yet fixed
Suggested reviewers: @pr-author
Matovidlo
approved these changes
Sep 30, 2026
pepamartinec
force-pushed
the
pepa/PAT-2167_app-preview-link
branch
from
September 30, 2026 10:01
0122146 to
d9c5e3b
Compare
…kip auth on dev-mode hosts
pepamartinec
force-pushed
the
pepa/PAT-2167_app-preview-link
branch
from
September 30, 2026 10:45
d9c5e3b to
07e9012
Compare
6 of 13 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release Notes
https://linear.app/keboola/issue/PAT-2167
Depends on #2663
Part 3 of 3: wires preview links into apps-proxy.
GET /_proxy/previewserves the landing page, thePOSTredeems the link into__Host-kbc-app-preview-session, and while the host is in dev mode that cookie skips the app's auth rules. The cookie is stripped from every request before anything reaches the app. Docs:docs/apps-proxy/preview-link.md.The routing order is the part to review.
/_proxy/*is routed before the preview session, so sign-out and the OIDC callback always reach apps-proxy, and sign-out clears the preview cookie. The kai-preview cookie check and iframe fallback moved below the preview session (otherwise the303 → /after a redeem inside the kbc-ui iframe would get the kai shim). Side effects: a kai-preview cookie no longer forwards any/_proxy/*path to the app, an iframe load on a/_proxy/*path no longer gets the shim, and on apps without auth handlers/_proxy/previewno longer reaches the app.Follow-up before sessions ever carry a user identity: close login CSRF. Any page can send a browser to someone else's link and the landing page submits it, so the browser gets that person's session. Harmless now (no identity), noted under Known limits. Candidate fix: auto-submit only when
Sec-Fetch-SiteisnoneorSec-Fetch-Destisiframe, otherwise show a button (same-siteis not enough: other*.hub.*hosts are same-site).Stack E2E on
dev-keboola-gcp-us-central1passed onabab227c(24 checks, 0 fail) with test limits 2m / 5m. Later changes (production limits, 5-min slide, review fixes) were not re-run on the stack.Plans for customer communication
None.
Impact analysis
No impact until a stack sets
APPS_PROXY_PREVIEW_JWKS_URL, apart from the kai-preview side effects above.APPS_PROXY_PREVIEW_ISSUERmust be byte-equal to sandboxes-service'siss, or every link gets 401. The kbc-ui iframe needs the UI origin inAPPS_PROXY_PREVIEW_ALLOWED_FRAME_ANCESTORS.Change type
New feature
Justification
Let agents and the kbc-ui iframe open dev-mode apps through a short-lived signed link instead of the kai-preview handshake.
Deployment
Merge & automatic deploy, after parts 1 and 2. Before enabling on a stack: production signing keys and the
APPS_PROXY_PREVIEW_*values.Rollback plan
Revert of this PR, or unset
APPS_PROXY_PREVIEW_JWKS_URL.Post release support plan
None.