This repository was archived by the owner on Jan 22, 2019. It is now read-only.
fix: don't send cookies if we have an access token#288
Merged
Conversation
chrismwendt
approved these changes
Oct 30, 2018
chrismwendt
left a comment
There was a problem hiding this comment.
LGTM, I don't think extensions need any special casing
ijsnow
added a commit
to sourcegraph/sourcegraph-public-snapshot
that referenced
this pull request
Oct 30, 2018
|
🎉 This PR is included in version 1.19.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Addresses https://github.com/sourcegraph/sourcegraph/issues/545
This PR fixes an error where we get 401s even though we have an access token. This can happen when using SAML auth and the SAML session expires. This is because Sourcegraph gets to the SAML auth provider before the access token which will respond with a 401 and stop the execution of other auth middlewares. The solution is to not send cookies if we have an access token.
@chrismwendt do we need to do this for anything with extensions? I tested with the go language server enabled through extensions and it seems to work but just want to make sure.