Sitelet https://web.archive.org/web/20200912000444/https://github.com/netlify/netlify-cms/issues/4115
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow the CMS to include browsers cookies in requests sent to git-gateway #4115

Open
evaera opened this issue Aug 4, 2020 · 3 comments
Open

Allow the CMS to include browsers cookies in requests sent to git-gateway #4115

evaera opened this issue Aug 4, 2020 · 3 comments

Comments

@evaera
Copy link

@evaera evaera commented Aug 4, 2020

When connecting to the git gateway through XHR requests, NetlifyCMS doesn't include cookies.

We are running our own instance of the git gateway, and we would like to move it behind our corporate network for security reasons. We use Identity-Aware Proxy, which identifies secured sessions with a cookie that's injected by IAP. Because of this, all XHR requests from NetlifyCMS to the git gateway fail because they aren't authenticated into our network.

This appears to be the piece of code that's causing this: https://github.com/netlify/netlify-cms/blob/master/cypress/plugins/gitGateway.js#L35. fetch doesn't include cookies by default. It only includes them if you pass the credentials: "include" option.

If NetlifyCMS could include cookies in its requests, it would allow us to increase the security of our website by keeping the CMS off of the public Internet. Either getting this change in directly, or having an option to do this, would be very helpful for us.

Thanks

@erezrokah
Copy link
Collaborator

@erezrokah erezrokah commented Aug 5, 2020

Thanks @evaera.

This appears to be the piece of code that's causing this: https://github.com/netlify/netlify-cms/blob/master/cypress/plugins/gitGateway.js#L35

This is actually part of our testing code.

The place to implement the request should be here:

token => unsentRequest.withHeaders({ Authorization: `Bearer ${token}` }, req) as ApiRequest,

We would accept a PR for this, as long as it is opt in via a configuration, e.g.:

backend:
  // example 1
  include_cookies_in_request: true
  // example 2
  api_request_options: { credentials: "include" }

Still not sure which of the examples I prefer

@erezrokah erezrokah changed the title NetlifyCMS doesn't send cookies in XHR requests to the git gateway Allow the CMS to include browsers cookies in requests sent to git-gateway Aug 5, 2020
@erezrokah
Copy link
Collaborator

@erezrokah erezrokah commented Aug 5, 2020

Renamed the title to reflect the feature request

@erezrokah
Copy link
Collaborator

@erezrokah erezrokah commented Aug 6, 2020

This would probably require adding a new method withCredentials (similar to withNoCache)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

2 participants
You can’t perform that action at this time.