[PR #5915] [MERGED] [proxy] set session cookie path to root #27118

Open
opened 2026-08-05 07:08:13 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/5915
Author: @alsruf36
Created: 4/18/2026
Status: Merged
Merged: 4/23/2026
Merged by: @lixmal

Base: mainHead: fix/proxy-cookie-path


📝 Commits (2)

  • 3fb9dc2 [proxy] set session cookie path to root
  • 2c125d1 [proxy] add regression test for session cookie path

📊 Changes

2 files changed (+10 additions, -0 deletions)

View changed files

📝 proxy/internal/auth/middleware.go (+1 -0)
📝 proxy/internal/auth/middleware_test.go (+9 -0)

📄 Description

Describe your changes

Explicitly set Path: "/" on the session cookie written by the reverse proxy's auth middleware.

Without an explicit Path, browsers default to the path of the request URI that set the cookie (MDN reference). This means a user authenticating at example.com/app/page gets a cookie scoped to /app, and subsequent requests to sibling paths like /api or /_app/* are treated as unauthenticated — breaking SPAs, share links, and any service that fetches resources from multiple top-level paths.

This was originally flagged by CodeRabbit during review of #5587 as an outside-diff comment, but wasn't picked up before merge.

Closes #5626

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (one-line behavioral fix to existing helper; no user-facing API change)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • Bug Fixes
    • Fixed session cookie scope to apply across all application paths, ensuring consistent session persistence for users navigating throughout the application.

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/5915 **Author:** [@alsruf36](https://github.com/alsruf36) **Created:** 4/18/2026 **Status:** ✅ Merged **Merged:** 4/23/2026 **Merged by:** [@lixmal](https://github.com/lixmal) **Base:** `main` ← **Head:** `fix/proxy-cookie-path` --- ### 📝 Commits (2) - [`3fb9dc2`](https://github.com/netbirdio/netbird/commit/3fb9dc2159cb57d8808afe372d8cb112a45d177d) [proxy] set session cookie path to root - [`2c125d1`](https://github.com/netbirdio/netbird/commit/2c125d123f45926d2b39cec1d779888676d9aabd) [proxy] add regression test for session cookie path ### 📊 Changes **2 files changed** (+10 additions, -0 deletions) <details> <summary>View changed files</summary> 📝 `proxy/internal/auth/middleware.go` (+1 -0) 📝 `proxy/internal/auth/middleware_test.go` (+9 -0) </details> ### 📄 Description ## Describe your changes Explicitly set `Path: "/"` on the session cookie written by the reverse proxy's auth middleware. Without an explicit `Path`, browsers default to the path of the request URI that set the cookie ([MDN reference](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#pathpath-value)). This means a user authenticating at `example.com/app/page` gets a cookie scoped to `/app`, and subsequent requests to sibling paths like `/api` or `/_app/*` are treated as unauthenticated — breaking SPAs, share links, and any service that fetches resources from multiple top-level paths. This was originally flagged by CodeRabbit during review of #5587 as an outside-diff comment, but wasn't picked up before merge. ## Issue ticket number and link Closes #5626 ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (one-line behavioral fix to existing helper; no user-facing API change) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed session cookie scope to apply across all application paths, ensuring consistent session persistence for users navigating throughout the application. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 07:08:13 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#27118