Skip to content

Install over plain http on a LAN address: the session cookie does not stick #665

Description

@compscidr

Problem

The session cookie is marked Secure unless SESSION_SECURE=false is set. Browsers only keep a Secure cookie over https or on localhost. Someone installing on a home server and opening http://192.168.1.20:7000 therefore cannot get past the setup code (#664): the code is accepted, the cookie is dropped, and the same page comes back. Before #664 the same thing made every login fail on such a site.

The setup-code page explains this in small print, but nothing detects it.

Ideas

  • Decide Secure per request: set it when the request arrived over https (directly, or X-Forwarded-Proto: https from a trusted proxy) and leave it off otherwise.
  • Or detect the loop (right code, no cookie on the next request) and show a clear message with the fix.

Follow-up to #664.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions