fix(security): refine dynamic config URL trust policy and document trusted-origin behavior (#5973)

* fix(security): refine dynamic config URL trust policy and document trusted-origin behavior

* Update documentation for Authorization and Authentication.

* Add isSameOrigin to resolveConfigFetchPolicy return value.
This commit is contained in:
Joe Boccanfuso authored and GitHub committed 2026-04-27 07:06:06 -04:00
1 parent 5ba8339037
commit f3cca21e49
3 files changed
+46 -7

No files matched your search

@@ -85,14 +85,17 @@ Allowed entry format for `dangerouslyAllowedOriginsForAuthenticatedEnvironments`
Policy summary:
- In unauthenticated environments, any HTTP(S) `?url=` origin is allowed.
- In authenticated environments, `?url=` origins must be present in `dangerouslyAllowedOriginsForAuthenticatedEnvironments`, otherwise loading fails closed.
- In unauthenticated environments, config URLs are fetched with:
- In authenticated environments, same-origin `?url=` values are allowed by default.
- In authenticated environments, cross-origin `?url=` values must be present in `dangerouslyAllowedOriginsForAuthenticatedEnvironments`, otherwise loading fails closed.
- In unauthenticated environments, cross-origin config URLs are fetched with:
- `method: 'GET'`
- `mode: 'cors'`
- `credentials: 'omit'`
- `redirect: 'error'`
- `referrerPolicy: 'no-referrer'`
- In authenticated environments, allowlisted config URLs are fetched using simple fetch behavior.
- In unauthenticated environments, same-origin config URLs use a plain `fetch()` call (browser default `credentials: 'same-origin'`).
- Same-origin config URLs are fetched using simple fetch behavior (so same-origin session/cookie auth is preserved).
- In authenticated environments, allowlisted cross-origin config URLs are fetched using simple fetch behavior.
- Returned datasource configuration payloads are consumed as-is (no additional URL/config scrubbing).
Example: