Add headersToClient support in SecurityPolicy for ext_authz session cookie extension #7644
johnbolsonito
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
When using external authorization (ext_authz) with custom auth services that manage sessions via cookies, there's currently no way to forward Set-Cookie headers from the auth service back to the client on successful authorization. This prevents implementing session cookie extension/refresh patterns.
The Pattern is Valid:
Raw Envoy supports it (allowed_client_headers_on_success)
Istio supports it (headersToDownstreamOnAllow)
Proposed Solution:
Add a headersToClient field to SecurityPolicy's extAuth configuration:
Beta Was this translation helpful? Give feedback.
All reactions