Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upAllow the CMS to include browsers cookies in requests sent to git-gateway #4115
Comments
|
Thanks @evaera.
This is actually part of our testing code. The place to implement the request should be here: We would accept a PR for this, as long as it is opt in via a configuration, e.g.: backend:
// example 1
include_cookies_in_request: true
// example 2
api_request_options: { credentials: "include" }Still not sure which of the examples I prefer |
|
Renamed the title to reflect the feature request |
|
This would probably require adding a new method |
evaera
added a commit
to evaera/netlify-cms
that referenced
this issue
Aug 8, 2020
Closes netlify#4115
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
When connecting to the git gateway through XHR requests, NetlifyCMS doesn't include cookies.
We are running our own instance of the git gateway, and we would like to move it behind our corporate network for security reasons. We use Identity-Aware Proxy, which identifies secured sessions with a cookie that's injected by IAP. Because of this, all XHR requests from NetlifyCMS to the git gateway fail because they aren't authenticated into our network.
This appears to be the piece of code that's causing this: https://github.com/netlify/netlify-cms/blob/master/cypress/plugins/gitGateway.js#L35.
fetchdoesn't include cookies by default. It only includes them if you pass thecredentials: "include"option.If NetlifyCMS could include cookies in its requests, it would allow us to increase the security of our website by keeping the CMS off of the public Internet. Either getting this change in directly, or having an option to do this, would be very helpful for us.
Thanks