[PR #5915] [proxy] set session cookie path to root #27122

Closed
opened 2026-08-05 07:08:13 -04:00 by saavagebueno · 0 comments
Owner

Original Pull Request: https://github.com/netbirdio/netbird/pull/5915

State: closed
Merged: Yes


Describe your changes

Explicitly set Path: "/" on the session cookie written by the reverse proxy's auth middleware.

Without an explicit Path, browsers default to the path of the request URI that set the cookie (MDN reference). This means a user authenticating at example.com/app/page gets a cookie scoped to /app, and subsequent requests to sibling paths like /api or /_app/* are treated as unauthenticated — breaking SPAs, share links, and any service that fetches resources from multiple top-level paths.

This was originally flagged by CodeRabbit during review of #5587 as an outside-diff comment, but wasn't picked up before merge.

Closes #5626

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (one-line behavioral fix to existing helper; no user-facing API change)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • Bug Fixes
    • Fixed session cookie scope to apply across all application paths, ensuring consistent session persistence for users navigating throughout the application.
**Original Pull Request:** https://github.com/netbirdio/netbird/pull/5915 **State:** closed **Merged:** Yes --- ## Describe your changes Explicitly set `Path: "/"` on the session cookie written by the reverse proxy's auth middleware. Without an explicit `Path`, browsers default to the path of the request URI that set the cookie ([MDN reference](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#pathpath-value)). This means a user authenticating at `example.com/app/page` gets a cookie scoped to `/app`, and subsequent requests to sibling paths like `/api` or `/_app/*` are treated as unauthenticated — breaking SPAs, share links, and any service that fetches resources from multiple top-level paths. This was originally flagged by CodeRabbit during review of #5587 as an outside-diff comment, but wasn't picked up before merge. ## Issue ticket number and link Closes #5626 ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (one-line behavioral fix to existing helper; no user-facing API change) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed session cookie scope to apply across all application paths, ensuring consistent session persistence for users navigating throughout the application. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
saavagebueno added the pull-request label 2026-08-05 07:08:13 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#27122