Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add cookie exclusion list in proxy config #1813

Closed
hueniverse opened this issue Jul 30, 2014 · 0 comments
Closed

Add cookie exclusion list in proxy config #1813

hueniverse opened this issue Jul 30, 2014 · 0 comments
Labels
feature New functionality or improvement security Issue with security impact

Comments

@hueniverse
Copy link
Contributor

When a server acts as a proxy and a host with cookies, the auth cookies leak to the upstream server when using passthrough mode. We need an option to specify which cookies should be whitelisted or blacklisted from being passed through.

The secure option is to require a whitelist but that is a breaking change so probably start by adding a blacklist.

This issue was closed.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
feature New functionality or improvement security Issue with security impact
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant