Skip to content

feat(preview): carry the session token in the url fragment - #178

Draft
gwdp wants to merge 1 commit into
gwdp/require-token-401-pagefrom
gwdp/share-token-in-fragment
Draft

gwdp wants to merge 1 commit into
gwdp/require-token-401-pagefrom
gwdp/share-token-in-fragment

Conversation

@gwdp

@gwdp gwdp commented Sep 18, 2026 •

Copy link
Copy Markdown
Collaborator

Why

A shared link carried the token as ?token=, so it reached the tunnel's access logs, any proxy in front of it, and any chat app that unfurled the link. That token opens a route that runs shell commands on the host.

How

  • Share writes the token to the fragment, which browsers never send
  • The gate still reads only a query token, so the 401 page converts the fragment and re-navigates; the server trades it for a cookie as before
  • The client clears a fragment token on load, for a visit that already has the cookie
  • The query form is kept supported

Stacked on #165. x-ref expo/eas-cli#4434.

Test Plan

  • CI
  • Browser: /#token=… sends no token on the first request, loads the preview, and leaves a clean address bar
  • A wrong token in the fragment stops on the rejected page after one hop, no loop

@linear-code

linear-code Bot commented Sep 18, 2026

Copy link
Copy Markdown

ENG-26905

A fragment is never sent, so a shared link no longer puts the token in a request
line, a proxy log, or a link unfurler's fetch. The 401 page hands it over as the
query the gate reads, and the client clears it from the address bar on a visit
that already holds the cookie. The query form is unchanged, so the preview page
keeps passing it to the framed preview.
@gwdp
gwdp force-pushed the gwdp/require-token-401-page branch from 303c2bd to b4709d3 Compare September 21, 2026 19:04
@gwdp
gwdp force-pushed the gwdp/share-token-in-fragment branch from 3d94dc0 to a370ae7 Compare September 21, 2026 19:04

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant