Skip to content

v1.2.0 — Shared-Domain Sign-In & Origin Checks

Choose a tag to compare

@Tarcroi Tarcroi released this 22 Sep 09:47
· 1 commit to main since this release

Highlights

  • One sign-in across two hosts of one domain. Set SKRUN_SESSION_COOKIE_DOMAIN (example.com) and a dashboard on one host and the API on another share a single browser session; set SKRUN_PUBLIC_URL and every URL the server hands out — OAuth redirect_uri, device-login link, schema servers — stops depending on a Host header the caller chose. Both are validated at startup; a bad pair refuses to boot with a message naming what it got.
  • Cookie-authenticated changes are checked for cross-site origin, on every deployment. A POST/PUT/PATCH/DELETE carrying the session cookie must show a browser signal (Sec-Fetch-Site, a matching Origin) or a content type a cross-site form cannot produce — SameSite=Lax does not stop a forged form between two hosts of one domain. API keys and dev-token are untouched.
  • Expired run files are deleted on a schedule. Output directories and uploaded inputs no longer wait for their next read to expire: a sweep runs every five minutes and a restart clears what a previous process left. FILES_RETENTION_S / INPUT_FILES_RETENTION_S are now deletion bounds.
  • /docs runs only code we control. The interactive API docs pin their renderer to one version and one integrity hash under a Content Security Policy, and no longer relay "Try it" requests or fonts through third-party hosts.
  • The CLI consent cookie is host-locked (__Host- prefix), and a failed OAuth exchange no longer echoes the exception to the browser.

Breaking

  • A non-browser client that authenticates with the session cookie and sends a form-style body (or no Content-Type) on a change is refused with 403. Add -H "Content-Type: application/json" — or use an sk_live_ key. Clients using Authorization are unaffected.

Migration

  • Nothing to configure: both new variables are optional and unset means the previous behaviour.
  • If you set SKRUN_SESSION_COOKIE_DOMAIN in production, the cookie is renamed __Secure-skrun_session: everyone signs in once more, once. Check what else lives under that DNS zone first — docs/self-hosting.md says what to look at.
  • The image's start script now states what a boot really requires: the database and storage settings always, CORS_ORIGIN under NODE_ENV=production, no provider key ever.

Stats

  • 1972 unit + integration tests pass (was 1907 at v1.1.0)
  • 144 E2E in-memory, plus the live multi-provider suite
  • OpenAPI 3.1 spec at 1.2.0

Install

npx @skrun-dev/cli@1.2.0 --version
# or
npm i -g @skrun-dev/cli@1.2.0

Full changelog: CHANGELOG.md