{{ message }}
fix(coderd): reject workspace proxy hostname prefixes - #27544
Merged
geokat merged 3 commits intoJul 28, 2026
Conversation
Require access URL matches to end at a hostname boundary, preventing attacker-controlled prefix domains from receiving application-connect API keys through auth redirects. Add regression coverage for access URL and wildcard hostname prefixes. Refs: https://linear.app/codercom/issue/PLAT-384
BobbyHo
reviewed
Jul 27, 2026
BobbyHo
reviewed
Jul 27, 2026
BobbyHo
approved these changes
Jul 27, 2026
BobbyHo
left a comment
Contributor
There was a problem hiding this comment.
LGTM — just left a couple of non-blocking comments about adding some test coverage.
Review feedback: add a test truncating mid-label, where the leftover starts with an ordinary character (and the candidate has a true delegated TLD). Co-authored-by: Bobby Ho <bobbidinho@gmail.com>
BobbyHo
self-requested a review
July 27, 2026 21:47
BobbyHo
approved these changes
Jul 27, 2026
BobbyHo
left a comment
Contributor
There was a problem hiding this comment.
lgtm. Thank you for adding the new test cases.
jdomeracki-coder
approved these changes
Jul 28, 2026
jdomeracki-coder
left a comment
Contributor
There was a problem hiding this comment.
I think that the patch is good enough as is
Long term it would probably make sense to avoid performing security sensitive checks using SQL entirely - instead we should move this check to Go
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

A workspace proxy hostname prefix could be accepted as a valid proxy
access URL. An authenticated user could then be redirected to an
attacker-controlled domain with an application-connect API key in the
URL.
Require proxy access URL matches to have a hostname boundary after the
candidate hostname, allowing only the end of the URL, a port, or a
path.
Add regression coverage for proxy access URL and wildcard hostname
prefixes.
Refs: https://linear.app/codercom/issue/PLAT-384