fix(webview): revoke proxy capabilities on logout and stamp Referrer-Policy

WebviewCapabilityStore.revokeOwner() shipped for two releases with a docstring
claiming logout called it and no caller at all. The capability is a bearer
credential exempt from cookie auth with a rolling TTL refreshed on every use, so
a proxy URL that leaked (browser history, a screenshot, a dashboard with a loose
referrer policy) stayed valid for as long as anything kept polling it.

- POST /api/logout revokes the caller's capabilities (all of them in single-user
  mode), the admin forced logout revokes the target user's, and user deletion
  revokes whatever that user had open. revokeOwner returns the count for the
  admin audit line.
- Proxied responses carry `Referrer-Policy: same-origin` and the upstream's own
  policy is dropped: every URL inside the frame carries the capability, and a
  dashboard on no-referrer-when-downgrade or unsafe-url handed it to any
  third-party host it linked. Verified with Playwright that a sandboxed frame
  under an upstream `unsafe-url` sends no Referer to a third party while the
  root-absolute fetch and the CSS-triggered 404 fallback still reach the
  dashboard.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WKtW48T1UjAaecHAJxKobE
This commit is contained in:
Codeman maintainer
2026-09-04 15:21:13 +02:00
parent 550e08a791
commit 2ab21c1b32
6 changed files with 209 additions and 4 deletions
+6 -1
View File
@@ -35,6 +35,7 @@ import {
UserStoreError,
} from '../../user-store.js';
import { getAuthUser, requireAdmin, revokeUserSessions } from '../route-helpers.js';
import { webviewCapabilities } from '../../webview-capabilities.js';
import { appendAdminAudit } from '../admin-audit.js';
import { SseEvent } from '../sse-events.js';
import type { AuthPort } from '../ports/auth-port.js';
@@ -179,7 +180,10 @@ export function registerAdminRoutes(app: FastifyInstance, ctx: SessionPort & Aut
if (!gate(req, reply)) return;
const { username } = req.params as { username: string };
const revoked = revokeUserSessions(ctx.authSessions, username);
audit(req, 'user.logout', username, { revoked });
// Web-tab proxy capabilities are a second credential the cookie purge does not
// touch; a forced logout that left them alive would not be a logout.
const revokedWebviews = webviewCapabilities.revokeOwner(normalizeUsername(username));
audit(req, 'user.logout', username, { revoked, revokedWebviews });
return { success: true, data: { revoked } };
});
@@ -201,6 +205,7 @@ export function registerAdminRoutes(app: FastifyInstance, ctx: SessionPort & Aut
await ctx.cleanupSession(id, true, 'admin_delete_user').catch(() => {});
}
revokeUserSessions(ctx.authSessions, username);
webviewCapabilities.revokeOwner(normalizeUsername(username));
if (deleteSpace) await deleteUserSpace(username);
audit(req, 'user.delete', username, { deleteSpace, killedSessions: owned.length });
ctx.broadcast(SseEvent.AdminUsersChanged, {});
+5
View File
@@ -31,6 +31,7 @@ import {
} from '../../types.js';
import { Session, isAltScreenStripMode, isExternalCliMode, isMuxAltScreenOnlyStripMode } from '../../session.js';
import { SseEvent } from '../sse-events.js';
import { webviewCapabilities } from '../../webview-capabilities.js';
import {
CreateSessionSchema,
SessionNameSchema,
@@ -821,6 +822,10 @@ export function registerSessionRoutes(
if (sessionToken) {
ctx.authSessions?.delete(sessionToken);
}
// The web-tab proxy authenticates on capabilities, not on this cookie, so a
// logout has to retire them too or every dashboard URL opened during this
// login keeps relaying without one (WebviewCapabilityStore.revokeOwner).
webviewCapabilities.revokeOwner(ownerFor(req));
reply.clearCookie(AUTH_COOKIE_NAME, { path: '/' });
return {};
});
+13
View File
@@ -93,6 +93,10 @@ const DROP_RESPONSE_HEADERS = new Set([
'access-control-allow-headers',
'access-control-expose-headers',
'access-control-max-age',
// The capability rides in every proxied URL, so the upstream's own referrer
// policy must not decide whether third parties receive it. Ours is stamped in
// buildDownstreamResponseHeaders.
'referrer-policy',
]);
/** The same-origin path prefix an iframe loads for a given capability. */
@@ -352,6 +356,15 @@ export function buildDownstreamResponseHeaders(
headers[lower] = value;
}
// Every URL inside the frame carries the capability, and a dashboard that sets
// `no-referrer-when-downgrade` or `unsafe-url` would hand it to any third-party
// host it links or embeds. `same-origin` keeps the Referer on requests back to
// Codeman (the 404 fallback and `refererPath` rely on it; both compare URL
// origins, which an opaque-origin frame still satisfies) and strips it for
// everyone else. A `<meta name="referrer">` inside the document can still
// override this; that is the dashboard author's own decision about their page.
headers['referrer-policy'] = 'same-origin';
const setCookie = setCookies.map((cookie) => rewriteSetCookie(cookie, capability, secureContext));
return { headers, setCookie, csp };
+22 -3
View File
@@ -13,7 +13,8 @@
*
* - 128 bits of `randomBytes` entropy, base64url, never derived from anything.
* - Held in memory only. A restart invalidates every outstanding capability.
* - Rolling TTL: refreshed on use, expired after inactivity.
* - Rolling TTL: refreshed on use, expired after inactivity, and revoked outright
* on logout, admin logout and user deletion (`revokeOwner`).
* - Bound to the minting user, so multi-user ownership survives the exemption.
* - Grants exactly one thing: relaying bytes to that one saved URL. It reaches no
* session, no file, no API surface.
@@ -81,15 +82,33 @@ export class WebviewCapabilityStore {
}
}
/** Revoke every capability minted by a user (called on logout / user deletion). */
revokeOwner(owner: string): void {
/**
* Revoke every capability bound to an identity. Called from `POST /api/logout`
* (the caller's own identity, which in single-user mode is `undefined`, i.e.
* every capability there is), from the admin logout route, and from user
* deletion.
*
* ⚠️ This method shipped for two releases with NO caller while its docstring
* claimed logout invoked it. The rolling TTL is refreshed on every use, so a
* proxy URL that leaked (browser history, a shared screenshot, a dashboard with
* a loose referrer policy) stayed valid indefinitely as long as something kept
* polling it. Logging out is the user's one deliberate "invalidate what I
* opened" gesture, and it has to reach here; `test/webview-capability-revocation.test.ts`
* pins each call site.
*
* @returns how many capabilities were revoked (for the admin audit line).
*/
revokeOwner(owner: string | undefined): number {
let revoked = 0;
for (const [webviewId, token] of [...this.byWebview]) {
const record = this.capabilities.peek(token);
if (record?.owner === owner) {
this.capabilities.delete(token);
this.byWebview.delete(webviewId);
revoked++;
}
}
return revoked;
}
get size(): number {