The cookie-hardening release. Upgrading from 0.12.0 applies no migration and needs nothing run, and signed-in browsers stay signed in. A script that posts to /api with only a session cookie now needs an Origin header or the bearer header.
docker compose -f docker-compose-release.yml pull app
docker compose -f docker-compose-release.yml up -dRun it
git clone https://github.com/Cloud-City-Computing/c2.git
cd c2
cp .env.example .env # fill in DB and admin credentials and APP_URL; SMTP is optional
docker compose -f docker-compose-release.yml up -d
docker compose -f docker-compose-release.yml run --rm app npm run migrate -- --adopt-fresh-installThat pulls ghcr.io/cloud-city-computing/cloud-codex:0.13.0 and serves it on http://localhost:3000. The last line is a one-time step on a fresh install.
Security
- Another host under your domain can no longer set Codex's sign-in cookies (GHSA-xq3x-556x-fr4q, medium).
- A script on a sibling host could plant the OAuth state cookie or the session cookie, which allowed Google login CSRF and capturing a victim's GitHub token on the attacker's account.
- On https these cookies are now
__Host-oauth_state_<provider>and__Host-sessionToken, read only under those exact names. - The protection needs https. An instance served over plain http keeps the older names and stays exposed.
- Existing sessions keep working and move to the new name on their next visit.
LEGACY_SESSION_COOKIE=0turns off the older name for an instance whose domain has hosts you do not control.
- A write authenticated by the session cookie alone needs an accepted
Origin. The app's own requests and server-to-server callers are unaffected.
Also in this release
- A first boot no longer restarts the app while MySQL initialises (0.12.0's known gap): the MySQL healthcheck pings over TCP.
- A clean boot log and browser console: no dotenv banner, running without SMTP reads as a setting, and no refused GitHub requests when no GitHub account is linked.
- Fixed: signing in over plain http to an address other than
localhostkeeps its session. - Self-hosting docs match the code: SMTP is optional everywhere, every first-install snippet includes the adopt step and names
APP_URL, and the settings table lists every variable (pinned by tests).
Known gaps
linux/amd64only.- Documents edited only over the collaborative WebSocket have a stale
html_contentuntil an explicit save.
Full detail in CHANGELOG.md.