Skip to content

PAT-2167 Apps Proxy preview links (2/3): link verification and session cookie - #2663

Merged
pepamartinec merged 8 commits into
pepa/PAT-2167_preview-1-keysfrom
pepa/PAT-2167_preview-2-session
Sep 30, 2026
Merged

pepamartinec merged 8 commits into
pepa/PAT-2167_preview-1-keysfrom
pepa/PAT-2167_preview-2-session

Conversation

@pepamartinec

@pepamartinec pepamartinec commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Release Notes

https://linear.app/keboola/issue/PAT-2167
Depends on #2662

Part 2 of 3: link verification, the session cookie and the landing page. Nothing is wired into request handling yet.

Decisions a reviewer might otherwise question:

  • sub is compared byte-exact to apps-proxy's own canonical origin; the untrusted sub is never parsed. sandboxes-service emits https://<lowercase host> with no port or slash, so anything else is not a link we minted.
  • The session check has no WithIssuedAt(). iat is floored to the second, so a replica whose clock is a few ms behind would reject a fresh cookie. exp and the 12 h cap stay strict.
  • The cookie is re-issued once it is 5 min old, not after half the idle time. Otherwise the real idle timeout would be 2–4 h instead of 4 h.
  • The redeem check uses Sec-Fetch-Site, not Origin: the landing page sends no-referrer, so Chrome posts with Origin: null.
  • The landing page stays blank while it submits; text appears only without JavaScript or without a token.

Plans for customer communication

None.

Impact analysis

No impact. The new code is not called yet.

Change type

New feature

Justification

Let agents and the kbc-ui iframe open dev-mode apps through a short-lived signed link instead of the kai-preview handshake.

Deployment

Merge & automatic deploy.

Rollback plan

Revert of this PR.

Post release support plan

None.

@linear-code

linear-code Bot commented Sep 29, 2026

Copy link
Copy Markdown

PAT-2167

@pepamartinec
pepamartinec added this pull request to stack #2664 September 29, 2026 14:06
@pepamartinec
pepamartinec force-pushed the pepa/PAT-2167_preview-2-session branch 4 times, most recently from 6d57320 to 60f2e86 Compare September 29, 2026 15:29
@pepamartinec
pepamartinec marked this pull request as ready for review September 29, 2026 16:16
Copilot AI balanced review requested due to automatic review settings September 29, 2026 16:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@keboola-pr-reviewer-bot keboola-pr-reviewer-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: needs_human (risk 3/5) · profile psgo

Needs human: security-sensitive auth code (preview-link JWT verification + session cookies) in the load-bearing apps-proxy.

Concerns:

  • internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/link.go: New signed preview-link JWT verifier for apps-proxy — auth-critical, needs security review.
  • internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/session.go: New HS256 session-cookie issue/check logic; verify sliding/hard-cap and cookie flags.
  • internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/redeem.go: CSRF defense relies solely on Sec-Fetch-Site same-origin; confirm header cannot be spoofed.

Suggested reviewers: @, this PR needs a human reviewer because it adds signed preview-link verification and session-cookie auth to apps-proxy (policy: Auth & credentials + load-bearing apps-proxy auth). Please assign an on-rotation PSGO teammate via the Reviewers panel.

Comment thread internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/constants.go Outdated
Comment thread internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/session.go Outdated
@pepamartinec
pepamartinec force-pushed the pepa/PAT-2167_preview-2-session branch from b3c5dc6 to 891c8cd Compare September 30, 2026 10:01

@Matovidlo Matovidlo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@pepamartinec
pepamartinec merged commit 38ca27f into main Sep 30, 2026
26 of 27 checks passed
@pepamartinec
pepamartinec deleted the pepa/PAT-2167_preview-2-session branch September 30, 2026 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants