You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/cmd/proxy-to-grafana
Patrick O'Doherty 336b3b7df0
cmd/proxy-to-grafana: strip X-Webauth* headers from all requests (#15985)
Update proxy-to-grafana to strip any X-Webauth prefixed headers passed
by the client in *every* request, not just those to /login.

/api/ routes will also accept these headers to authenticate users,
necessitating their removal to prevent forgery.

Updates tailscale/corp#28687

Signed-off-by: Patrick O'Doherty <patrick@tailscale.com>
7 months ago
..
proxy-to-grafana.go cmd/proxy-to-grafana: strip X-Webauth* headers from all requests (#15985) 7 months ago
proxy-to-grafana_test.go cmd/proxy-to-grafana: strip X-Webauth* headers from all requests (#15985) 7 months ago