Fix the Duo verifier WebSocket check rejecting itself

What does this MR do and why?

The WebSocket connectivity check in gitlab:duo:verify_self_hosted_setup builds its own upgrade request with Host: #{uri.host}:#{uri.port} and Origin: #{Gitlab.config.gitlab.url}. URI#port returns the scheme default when the URL has none, so an external_url of https://gitlab.example.com produces Host: gitlab.example.com:443 against Origin: https://gitlab.example.com. Workhorse upgrades this endpoint with gorilla's default origin check, which passes only when the Origin host equals the Host header. The check is therefore rejected with 403 on every instance configured without an explicit port, and its remediation text sends the operator to their licence and proxy.

The fix builds the host header once, omitting the default port the way browsers do, and derives Origin from the same URI, so the two agree for both default-port and explicit-port instances. Two spec examples cover both shapes.

I reproduced this on omnibus 19.3.1-ee: the task reported 403 while Rails logged 200 for the request. Replaying the handshake with curl, only the Host-with-port plus Origin-without-port combination returned 403, and the three other combinations returned 101. With this change applied on the same instance the check reports the upgrade as accepted. I ran RuboCop and the spec against a source checkout with Postgres and Redis: both files clean, 11 examples, 0 failures. Against the unpatched check the new default-port example fails and the explicit-port example passes either way, so it stays as the regression guard.

This change was drafted with AI assistance (Claude Code). I reviewed the diff and ran the reproduction and the fix on the instance myself.

References

Closes #628161

Introduced in !243425 (merged)

Screenshots or screen recordings

Not applicable: a rake task with no UI.

How to set up and validate locally

  1. Set external_url without a port and enable Duo self-hosted.
  2. Run bundle exec rake gitlab:duo:verify_self_hosted_setup. Before: WebSocket endpoint rejected the connection (HTTP 403). After: the upgrade is reported as accepted.
  3. bundle exec rspec ee/spec/lib/gitlab/duo/administration/agent_platform_websocket_check_spec.rb

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading