PAT-2167 Apps Proxy preview links (2/3): link verification and session cookie - #2663
Merged
pepamartinec merged 8 commits intoSep 30, 2026
Merged
Conversation
This was referenced Sep 29, 2026
pepamartinec
added this pull request to stack #2664
September 29, 2026 14:06
pepamartinec
force-pushed
the
pepa/PAT-2167_preview-2-session
branch
4 times, most recently
from
September 29, 2026 15:29
6d57320 to
60f2e86
Compare
pepamartinec
marked this pull request as ready for review
September 29, 2026 16:16
keboola-pr-reviewer-bot
left a comment
There was a problem hiding this comment.
Verdict: needs_human (risk 3/5) · profile psgo
Needs human: security-sensitive auth code (preview-link JWT verification + session cookies) in the load-bearing apps-proxy.
Concerns:
internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/link.go: New signed preview-link JWT verifier for apps-proxy — auth-critical, needs security review.internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/session.go: New HS256 session-cookie issue/check logic; verify sliding/hard-cap and cookie flags.internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/redeem.go: CSRF defense relies solely on Sec-Fetch-Site same-origin; confirm header cannot be spoofed.
Suggested reviewers: @, this PR needs a human reviewer because it adds signed preview-link verification and session-cookie auth to apps-proxy (policy: Auth & credentials + load-bearing apps-proxy auth). Please assign an on-rotation PSGO teammate via the Reviewers panel.
Matovidlo
reviewed
Sep 30, 2026
…it redeems the link
…s five minutes old
pepamartinec
force-pushed
the
pepa/PAT-2167_preview-2-session
branch
from
September 30, 2026 10:01
b3c5dc6 to
891c8cd
Compare
…ckage with the cookie helpers in cookie.go
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release Notes
https://linear.app/keboola/issue/PAT-2167
Depends on #2662
Part 2 of 3: link verification, the session cookie and the landing page. Nothing is wired into request handling yet.
Decisions a reviewer might otherwise question:
subis compared byte-exact to apps-proxy's own canonical origin; the untrustedsubis never parsed. sandboxes-service emitshttps://<lowercase host>with no port or slash, so anything else is not a link we minted.WithIssuedAt().iatis floored to the second, so a replica whose clock is a few ms behind would reject a fresh cookie.expand the 12 h cap stay strict.Sec-Fetch-Site, notOrigin: the landing page sendsno-referrer, so Chrome posts withOrigin: null.Plans for customer communication
None.
Impact analysis
No impact. The new code is not called yet.
Change type
New feature
Justification
Let agents and the kbc-ui iframe open dev-mode apps through a short-lived signed link instead of the kai-preview handshake.
Deployment
Merge & automatic deploy.
Rollback plan
Revert of this PR.
Post release support plan
None.