fix(web): origin guard accepts an https page behind a TLS proxy; log only the site

- A portless Host now matches the default port of either the browser's
  scheme or Flask's, so nginx terminating TLS in front of a plain-http
  upstream (Origin https://pi.example -> 443, Flask sees http -> 80) no
  longer refuses every legitimate write. A non-default port still has to
  match exactly.
- The refusal log records only scheme://host[:port] of Origin/Referer, never
  a Referer's path or query (which can carry tokens), and repr()s the path.
- Docs: forward $http_host, not $host (nginx's $host drops the port).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-29 19:30:00 -04:00
co-authored by Claude Opus 5.5
parent de34eb4da6
commit 9ce8d6c3c4
5 changed files with 130 additions and 30 deletions
+4 -2
View File
@@ -38,8 +38,10 @@ accepts both, but the store flags the old spelling as deprecated
dashboard or userscript on another host) can no longer call the mutating
API; call it server-side instead. Anyone posting a form body to
`system/action` must switch to JSON. Behind a reverse proxy, forward the
original `Host` (`proxy_set_header Host $host;`); `X-Forwarded-Host` is
not trusted.
original `Host`, port included (`proxy_set_header Host $http_host;`;
nginx's `$host` drops the port); `X-Forwarded-Host` is not trusted. A
TLS-terminating proxy needs nothing more: a portless `Host` matches an
`https://` page.
### Fixes