Replace SaaS-only feature flag with workhorse trusted_forwarded_hosts config

What does this MR do and why?

Replace SaaS-only feature flag with workhorse trusted_forwarded_hosts config

MR 240732 gated the Duo Workflow WebSocket Origin/X-Forwarded-Host check behind Gitlab.com?/development? and a feature flag, leaving self-managed instances with no opt-in even though they sit behind the same kind of host-rewriting proxy. Move the trust decision into workhorse's own config.toml (trusted_forwarded_hosts), mirroring the existing trusted_cidrs_for_x_forwarded_for setting, so any operator can enable it and the check no longer depends on Rails-side SaaS detection.

This requires a GitLab instance operator to set the trusted_forwarded_hosts setting for the workhorse TOML. Which is the right control for this feature. If this setting is not set, then no origin checks, then the default Gorilla checks apply:

https://github.com/gorilla/websocket/blob/e064f32e3674d9d79a8fd417b5bc06fa5c6cad8f/doc.go#L142C53-L148

References

Screenshots or screen recordings

Before After

How to set up and validate locally

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading