Skip to content

Commit 24672fd

Browse files
chore(nimbus): Revert "chore(nimbus): Set Cross-Origin-Opener-Policy response header (#12637)" (#12665)
Becuase * We set the cross origin header in the Django response headers to prevent auth token leaks * This does not actually solve the problem because the header must be set in Nginx, not Django This commit * Reverts adding the cross origin response header in Django fixes #12664 This reverts commit 64ed59c. Co-authored-by: Yashika Khurana <yashikakhuranayashika@gmail.com>
1 parent a4aa291 commit 24672fd

File tree

2 files changed

+2
-6
lines changed

2 files changed

+2
-6
lines changed

experimenter/experimenter/openidc/middleware.py

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -51,9 +51,7 @@ def __call__(self, request):
5151
request.user = user
5252

5353
if self.get_response:
54-
response = self.get_response(request)
55-
response.headers["Cross-Origin-Opener-Policy"] = "same-origin"
56-
return response
54+
return self.get_response(request)
5755

5856

5957
class OpenIDCRestFrameworkAuthenticator(SessionAuthentication):

experimenter/experimenter/openidc/tests/test_middleware.py

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,7 @@
1010

1111
class OpenIDCAuthMiddlewareTests(TestCase):
1212
def setUp(self):
13-
self.response = mock.Mock()
14-
self.response.headers = {}
13+
self.response = "Response"
1514
self.middleware = OpenIDCAuthMiddleware(lambda request: self.response)
1615

1716
mock_resolve_patcher = mock.patch("experimenter.openidc.middleware.resolve")
@@ -62,7 +61,6 @@ def test_user_created_with_correct_email_from_header(self):
6261
response = self.middleware(request)
6362

6463
self.assertEqual(response, self.response)
65-
self.assertEqual(response.headers["Cross-Origin-Opener-Policy"], "same-origin")
6664
self.assertEqual(User.objects.all().count(), 1)
6765

6866
self.assertEqual(request.user.email, user_email)

0 commit comments

Comments
 (0)