Repository navigation
Conversation
With WPORG_SSO_REQUIRE_PROXY=true, WPOrgSSO logs administrators out of any request that nginx doesn't mark as proxied with the WPORG_PROXIED_REQUEST FastCGI param, however they logged in. A session stolen from an administrator then doesn't work from outside the proxy. Agents aren't affected. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the Core Committers: Use this line as a base for the props when committing in SVN: To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
💤 Files with no reviewable changes (1)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughWPOrgSSO adds an optional proxy requirement for administrator access. When enabled, middleware logs out administrators whose requests lack the nginx proxy marker. The change adds configuration, provider checks, logout responses, deployment instructions, and tests. ChangesAdministrator proxy access
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Client
participant RequireWordPressOrgLogin
participant WPOrgSSOServiceProvider
participant Session
Client->>RequireWordPressOrgLogin: Send administrator request
RequireWordPressOrgLogin->>WPOrgSSOServiceProvider: Check proxy requirement
WPOrgSSOServiceProvider-->>RequireWordPressOrgLogin: Return configuration and marker result
RequireWordPressOrgLogin->>Session: Log out administrator and invalidate session
RequireWordPressOrgLogin-->>Client: Return JSON 401 or login redirect
Merge Risk: ⚪ Minimal · up to The proxy requirement appears mergeable after normal checks, provided nginx is configured before the setting is enabled. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The application adds a fail-closed control for administrator web requests, including sessions created through emergency login. No introduced bypass was established. Successful deployment still depends on trustworthy proxy classification, and coverage of privileged endpoints outside the web middleware remains unconfirmed. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Requires administrators to use the helpdesk through the proxy. Agents are still allowed in from anywhere, since most of them don't have proxy access.
How it works
WPORG_PROXIED_REQUESTFastCGI param to1for the proxy's IP addresses and0for everyone else, the same checkWPORG_PROXIED_REQUESTmakes on WordPress.org. The proxy IP list stays with Systems instead of being copied into the module.RequireWordPressOrgLogin. WhenWPORG_SSO_REQUIRE_PROXY=true, an administrator's request without the param set to1ends their session. They're sent to the login page with an error, and polls get a 401. This applies however they logged in, break-glass included, so a stolen admin session doesn't work from outside the proxy.WPORG_SSO_REQUIRE_PROXY=falselets administrators back in.false.Deploying
geomap and thefastcgi_paramon the FreeScout VM (example inModules/WPOrgSSO/README.md). The map needs the proxy's IPv6 addresses as well as IPv4.WPORG_SSO_REQUIRE_PROXY=true.Testing
npm run freescout:test(fromenvironments/). The newProxyTestcovers:🤖 Generated with Claude Code
Summary by CodeRabbit