Skip to content

Relax CSRF origin check for tunnels/Codespaces via TUNNEL env var - #5671

Merged
awwaiid merged 1 commit into
mainfrom
codespaces-origin-check
Aug 28, 2026
Merged

awwaiid merged 1 commit into
mainfrom
codespaces-origin-check

Conversation

@awwaiid

@awwaiid awwaiid commented Aug 28, 2026

Copy link
Copy Markdown
Collaborator

Ports the forgery_protection_origin_check relaxation from the design branch and sets TUNNEL in the devcontainer so Codespaces port forwarding works without CSRF 'session expired' errors.

Ports the forgery_protection_origin_check relaxation from the design
branch and sets TUNNEL in the devcontainer so Codespaces port
forwarding works without CSRF 'session expired' errors.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VCWmqFBvBDC9edudz1fea5
@awwaiid
awwaiid requested a review from armahillo August 28, 2026 14:47
@awwaiid
awwaiid merged commit 72bd713 into main Aug 28, 2026
22 checks passed
@awwaiid
awwaiid deleted the codespaces-origin-check branch August 28, 2026 14:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant