Open
Description
We check and auth workspace cookie in workspace origin, but that cookie is httpOnly, which means this if
will not work
Code pointer
Cookie policy | Six requests from StartWorkspace.tsx |
---|---|
![]() |
![]() |
How to reproduce
- Open workspace https://gitpod.new with browser code
- Exec
curl lama.sh | sh
to listen to port - Go to Ports tab next to Terminal tab in browser
- Switch port private/public state and check with Browser DevTools / Network or Console
Metadata
Metadata
Assignees
Type
Projects
Status
No status