Replace SaaS-only feature flag with workhorse trusted_forwarded_hosts config
What does this MR do and why?
Replace SaaS-only feature flag with workhorse trusted_forwarded_hosts config
MR 240732 gated the Duo Workflow WebSocket Origin/X-Forwarded-Host check behind Gitlab.com?/development? and a feature flag, leaving self-managed instances with no opt-in even though they sit behind the same kind of host-rewriting proxy. Move the trust decision into workhorse's own config.toml (trusted_forwarded_hosts), mirroring the existing trusted_cidrs_for_x_forwarded_for setting, so any operator can enable it and the check no longer depends on Rails-side SaaS detection.
This requires a GitLab instance operator to set the
trusted_forwarded_hosts setting for the workhorse TOML. Which is the
right control for this feature. If this setting is not set, then no
origin checks, then the default Gorilla checks apply:
References
Screenshots or screen recordings
| Before | After |
|---|---|
How to set up and validate locally
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.