coder / coder/code-server

Allow configuring login cookie with an expiry duration

未关闭
#7,301 0 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看
enhancement
主要语言
TypeScript
星标
79.3k
派生
6.8k
平均合并
2 天 6 小时
30 天内合并 PR
41

描述

## What is your suggestion?

Allow configuring an (optional) expiry age for the login cookie so that it persists beyond a browser session. This is handy for not re-entering the password every time.

**Possible change**:
https://github.com/coder/code-server/blob/main/src/node/http.ts#L328

```ts
...
return {
domain: getCookieDomain(url.host, req.args["proxy-domain"]),
path: normalize(url.pathname) || "/",
sameSite: "lax",
// Load, if provided, max age for login cookie. 0 means it becomes a Session cookie (according to Express docs)
maxAge: getConfigCookieMaxAgeAsMilliseconds() || 0,
}
```

## Why do you want this feature?

I want to maintain my login status even after closing the browser (as the Cookie is currently session-only). Say keep the login cookie for a week or a month. Adding a max-age changes the cookie from `Session` to persistent for the given duration using Express' `maxAge` parameter ([docs](https://expressjs.com/en/api.html#res.cookie)).

## Are there any workarounds to get this functionality today?

No, none directly. User can manually edit the cookie in Devtools

## Are you interested in submitting a PR for this?

I'm not that familiar with how to make new configuration argument and also how the config args are read (there's some middleware for `args` IIRC, but not sure how to use that). But I can give it a go, with some help.

The above given change should be roughly all that's needed, sans the config reading.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。