Skip to content

Check a WebSocket's origin against the host of urls.endpoint - #749

Merged
czpython merged 1 commit into
mainfrom
websocket-origin-from-endpoint
Sep 28, 2026
Merged

czpython merged 1 commit into
mainfrom
websocket-origin-from-endpoint

Conversation

@czpython

Copy link
Copy Markdown
Owner

Some identity edges forward requests with Host set to the app's upstream address. Teleport App Access sends Host: 127.0.0.1:8000 while the browser sends Origin: https://druks.example.com. is_same_origin compared Origin with Host, so it refused every WebSocket upgrade: the chat conversation socket and the login window screen.

is_same_origin now compares Origin with the host of urls.endpoint, the address the browser reaches Druks at. When urls.endpoint is empty, it compares with Host as before. The comparison stays host-only, because a TLS edge hands Druks ws while the browser's Origin says https.

docs/configuration.md states the rule on the urls.endpoint row.

Closes #745.

An edge such as Teleport App Access forwards requests with Host set to the app's upstream address, so every WebSocket upgrade failed the same-origin check. The check now compares Origin with the host of urls.endpoint, the address the browser reaches Druks at, and falls back to Host only when urls.endpoint is empty.
@mintlify

mintlify Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
druks 🟢 Ready View Preview Sep 28, 2026, 8:39 AM

💡 Tip: Enable Automations to automatically generate PRs for you.

@czpython
czpython enabled auto-merge (squash) September 28, 2026 08:44
@czpython
czpython merged commit e494f9e into main Sep 28, 2026
4 checks passed
@czpython
czpython deleted the websocket-origin-from-endpoint branch September 28, 2026 08:44

This branch was successfully deployed

1 active deployment
staging - docs — 22f98e5f Deployed Sep 28, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

WebSockets are refused behind an edge that rewrites Host

1 participant