f0ebd808d7
This CSRF cookie needs to be included on the request to the callback endpoint triggered by the redirect from the OIDC upstream provider. This is not allowed by `Same-Site=Strict` but is allowed by `Same-Site=Lax` because it is a "cross-site top-level navigation" [1]. We didn't catch this earlier with our Dex-based tests because the upstream and downstream issuers were on the same parent domain `*.svc.cluster.local` so the cookie was allowed even with `Strict` mode. [1]: https://tools.ietf.org/html/draft-ietf-httpbis-cookie-same-site-00#section-3.2 Signed-off-by: Matt Moyer <moyerm@vmware.com> |
||
---|---|---|
.. | ||
auth | ||
callback | ||
csrftoken | ||
discovery | ||
jwks | ||
oidctestutil | ||
provider | ||
kube_storage.go | ||
nullstorage_test.go | ||
nullstorage.go | ||
oidc.go |