Conversation
…i/tokens endpoint Selkies after 2.0.0 takes the session token from the URL fragment as well as the query, and offers a fragment token on the data WebSocket as the subprotocol selkies.token.<base64url> beside selkies, so it never reaches a request line. Selkies 2.0.0 already serves the token table on its own port at /api/tokens and has no 8083 control port, and the v2 images' Nginx hands Selkies everything under api/ through one location, where the pages still had the websocket and files locations of the v1 images.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Do not merge until a Selkies release after 2.0.0 is out and in the images. Selkies 2.0.0 reads the session token only from the query, so the fragment token these pages describe does not work on the current images.
The Selkies pages describe the session token in the fragment,
#token=<token>(#display2-right&token=<token>after a display fragment), beside?token=. A fragment never reaches a request line: the client offers the token on the data WebSocket as the subprotocolselkies.token.<base64url>besideselkies, which the server selects and the image's Nginx passes through.The rest already holds for 2.0.0 and the v2 images:
POST /api/tokensand the master token (Authorization, orSelkies-Authorizationbeside a Basic login), on the Selkies port behind Nginx; the pages name that API where they had the 8083 control port.<subfolder>api/websockets.apilocation of the v2 branches'default.conf(master, ubunturesolute, fedora44, arch, kali, alpine324, dev) in place of the v1 branches'websocketandfileslocations, and notes thatapitakes request bodies of any size, unbuffered.Tested:
mkdocs build --strictwithdocs/requirements.txt: no warnings or errors, as onmain.main(3291323) behind the port 3000 server block of the baseimage'sroot/defaults/default.conf(master), with its placeholders filled asinit-nginxfills them, in nginx 1.31.6: in Chrome, Firefox, and WebKit,/#token=streams, the file listing is served on the cookie alone, the socket request isGET /api/websocketsofferingselkies, selkies.token.*and answered 101 withselkies, and no request line or Referer that nginx logged carries the token.POST /api/tokensthrough nginx answers 200. The same holds under a subfolder with the block'sauth_basiclines enabled, asPASSWORDenables them, behind a proxy that sets the container's Basic login on every request, as SealSkin's Caddy does.?token=streams as before.ghcr.io/linuxserver/webtop:ubuntu-kdeitself, running Selkiesmain(1251515) through the image's dev mode (DEV_MODE=selkies-dashboard), and again withmain's built dashboard and package mounted over 2.0.0's: in Chrome 154, Firefox 156, and WebKit,/#token=streams the KDE desktop, the file listing is served on the cookie alone, the socket request isGET /api/websocketswith no query, and no line of the image's nginx access log or of the container's log carries the token. The same holds withPASSWORDset, behind a proxy that sets the container's Basic login on every request.?token=streams as before.