- Set GinJWTMiddleware.SigningAlgorithm to "HS256" explicitly so a future
library default change (or an alg:none confusion attempt) cannot weaken
token validation. This matches the current gin-jwt default, so behaviour
is unchanged.
- Set CookieSameSite to Lax: same as the modern-browser default, but
pinned so server-side intent is clear and CSRF on cross-site POST is
blocked while top-level GET (OAuth callback) still works.
- Move the nz-o2s OAuth2 state cookie into writeOauth2StateCookie and
set HttpOnly=true. The frontend does not read this cookie, so HttpOnly
is strictly an XSS-hardening win with no behaviour change.
JWT Cookie HttpOnly/Secure are intentionally left default for now: the
frontend reads \`!!document.cookie\` to display login state and many
deployments terminate TLS at an upstream proxy — flipping those would
require a coordinated frontend change.
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
* feat: support listening https
* refactor
* modernize
* support snake case in config
* more precise control of config fields
* update goreleaser config
* remove kubeyaml
* fix: expose agent_secret
* chore