coder / coder/code-server

Allow configuring login cookie with an expiry duration

未關閉
#7,301 0 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
enhancement
主要語言
TypeScript
星號
79.3k
分支
6.8k
平均合併
2 天 6 小時
30 天內合併 PR
41

描述

## What is your suggestion?

Allow configuring an (optional) expiry age for the login cookie so that it persists beyond a browser session. This is handy for not re-entering the password every time.

**Possible change**:
https://github.com/coder/code-server/blob/main/src/node/http.ts#L328

```ts
...
return {
domain: getCookieDomain(url.host, req.args["proxy-domain"]),
path: normalize(url.pathname) || "/",
sameSite: "lax",
// Load, if provided, max age for login cookie. 0 means it becomes a Session cookie (according to Express docs)
maxAge: getConfigCookieMaxAgeAsMilliseconds() || 0,
}
```

## Why do you want this feature?

I want to maintain my login status even after closing the browser (as the Cookie is currently session-only). Say keep the login cookie for a week or a month. Adding a max-age changes the cookie from `Session` to persistent for the given duration using Express' `maxAge` parameter ([docs](https://expressjs.com/en/api.html#res.cookie)).

## Are there any workarounds to get this functionality today?

No, none directly. User can manually edit the cookie in Devtools

## Are you interested in submitting a PR for this?

I'm not that familiar with how to make new configuration argument and also how the config args are read (there's some middleware for `args` IIRC, but not sure how to use that). But I can give it a go, with some help.

The above given change should be roughly all that's needed, sans the config reading.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。