Onion listener trust boundary

With ONION_LOCATION set, the app decides per request whether it came through the onion (Tor) listener. That decides Secure cookies, HSTS and the Onion-Location header. The client-supplied Host header never decides it: a request on the HTTPS listener could claim Host: <anything>.onion. Instead, nginx sets X-OW-Onion: 1 only in the onion server block and clears it in the regular one, like the IP headers of layer 1. Both hold only while the app port is reachable through this nginx alone (Offering an onion address).

Edit this page on GitHub