Conversation
ArgoCD's server splits a session token whose value exceeds the ~4093-byte per-cookie browser limit across multiple cookies: the base "argocd.token" cookie holds "<chunkCount>:<chunk0>" and the remaining chunks live in "argocd.token-1", "argocd.token-2", and so on. This is common for SSO users who carry many group claims. extractToken previously read only the base "argocd.token" cookie, so for these users the value was the truncated "<count>:<chunk0>" fragment, JWT verification failed, and the request silently fell back to the backend — losing the cached list-applications fast path for exactly the heaviest users. Reconstruct the full token from all chunks, mirroring ArgoCD's own util/http.JoinCookies, so the proxy verifies the same token the backend would. A token that fits in one cookie (no "<count>:" prefix) and a malformed/absent cookie are both handled, the latter yielding an empty token so the request falls back to proxying unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
ArgoCD's server splits a session token whose value exceeds the browser's ~4093-byte per-cookie limit across multiple cookies:
argocd.tokencookie holds<chunkCount>:<chunk0>argocd.token-1,argocd.token-2, …This is common for SSO users who carry many group claims.
extractTokenpreviously read only the baseargocd.tokencookie. For these users the value was the truncated<count>:<chunk0>fragment, so JWT verification failed and the request silently fell back to proxying to the backend — losing the cached list-applications fast path for exactly the heaviest users (large group lists also mean the RBAC filtering matters most).Change
Reconstruct the full token from all chunks in
joinChunkedToken, mirroring ArgoCD's ownutil/http.JoinCookies, so the proxy verifies exactly the token the backend would.<count>:prefix) is returned unchanged.Authorization: Bearerheader still takes precedence over cookies.Tests
Extended
TestExtractTokenwith cases for multi-chunk reassembly, out-of-order cookies, header precedence over chunked cookies, and malformed chunk counts. Full suite andgo vetpass.