diff --git a/Backend/src/lib/Authentication.ts b/Backend/src/lib/Authentication.ts index c533321..6e506ea 100644 --- a/Backend/src/lib/Authentication.ts +++ b/Backend/src/lib/Authentication.ts @@ -70,8 +70,11 @@ export function normalizeUsername(username: string): string { } /** Compute the cookie domain scope from the configured DOMAIN. */ -export function cookieDomain(domain: string): string { - if (domain === "localhost") return "localhost"; +export function cookieDomain(domain: string): string | undefined { + // IP addresses cannot have a registrable parent domain. Treating the first + // octet as a subdomain would turn 100.74.255.106 into 74.255.106 and make + // browser sessions unusable on direct-IP test/self-hosted deployments. + if (domain === "localhost" || /^(?:\d{1,3}\.){3}\d{1,3}$/.test(domain)) return undefined; if (domain.split(".").length > 2) { // Subdomain deployment: scope to the registrable parent domain. return domain.split(".").slice(1).join("."); diff --git a/Backend/src/routes/api/auth.ts b/Backend/src/routes/api/auth.ts index 5a552b2..dfa4904 100644 --- a/Backend/src/routes/api/auth.ts +++ b/Backend/src/routes/api/auth.ts @@ -16,10 +16,11 @@ import { createLogger } from "../../lib/logger"; const log = createLogger("auth"); function setSessionCookie(ctr: any, hash: string) { + const domain = cookieDomain(DOMAIN); ctr.cookies.set( SESSION_COOKIE, new Cookie(hash, { - domain: cookieDomain(DOMAIN), + ...(domain ? { domain } : {}), httpOnly: true, path: "/", sameSite: "lax", diff --git a/UI/src/components/AgentModals.tsx b/UI/src/components/AgentModals.tsx index 8d65dbf..ad78967 100644 --- a/UI/src/components/AgentModals.tsx +++ b/UI/src/components/AgentModals.tsx @@ -210,12 +210,12 @@ curl -X POST ${origin}/v1/change-requests/{request_id}/consume -H "x-api-key: ${

)} -
+
{tabs.map((t) => (
{/* mobile nav */} -