Skip to content

Commit 9fe7eb7

Browse files
authored
Update Code to 1.124.2 (#7846)
1 parent 1ccd4f0 commit 9fe7eb7

4 files changed

Lines changed: 18 additions & 4 deletions

File tree

CHANGELOG.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,20 @@ Code v99.99.999
2222

2323
## Unreleased
2424

25+
Code v1.124.2
26+
27+
### Security
28+
29+
- Strip code-server's session token from the cookie before proxying to a local
30+
port. Previously, when you used built-in password authentication, the cookie
31+
would be sent to the local proxied port, which meant if the service was
32+
malicious and not already running as your code-server user it could use the
33+
cookie to log into code-server and execute commands as your code-server user.
34+
35+
### Changed
36+
37+
- Update to Code 1.124.2
38+
2539
## [4.123.0](https://github.com/coder/code-server/releases/tag/v4.123.0) - 2026-06-03
2640

2741
Code v1.123.0

lib/vscode

Submodule vscode updated 1402 files

patches/disable-builtin-ext-update.diff

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ Index: code-server/lib/vscode/src/vs/workbench/contrib/extensions/browser/extens
77
===================================================================
88
--- code-server.orig/lib/vscode/src/vs/workbench/contrib/extensions/browser/extensionsWorkbenchService.ts
99
+++ code-server/lib/vscode/src/vs/workbench/contrib/extensions/browser/extensionsWorkbenchService.ts
10-
@@ -344,6 +344,10 @@ export class Extension implements IExten
10+
@@ -345,6 +345,10 @@ export class Extension implements IExten
1111
if (this.type === ExtensionType.System && this.productService.quality === 'stable' && !this.productService.builtInExtensionsEnabledWithAutoUpdates?.some(id => id.toLowerCase() === this.identifier.id.toLowerCase())) {
1212
return false;
1313
}

patches/webview.diff

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -70,8 +70,8 @@ Index: code-server/lib/vscode/src/vs/workbench/contrib/webview/browser/pre/index
7070
<meta charset="UTF-8">
7171

7272
<meta http-equiv="Content-Security-Policy"
73-
- content="default-src 'none'; script-src 'sha256-q+WTr+fBXpLLE3++yWNaxT6BTWQtsKscoeIlynBRk4E=' 'self'; frame-src 'self'; style-src 'unsafe-inline';">
74-
+ content="default-src 'none'; script-src 'sha256-m1DlJtsIJd46QuWYNcsaYIG1xI+9FyjKQu+cfp+zq5Q=' 'self'; frame-src 'self'; style-src 'unsafe-inline';">
73+
- content="default-src 'none'; script-src 'sha256-nXjtuhBilO++r8hfxl5VjEScSmdm07wDAk6jw228DgM=' 'self'; frame-src 'self'; style-src 'unsafe-inline';">
74+
+ content="default-src 'none'; script-src 'sha256-A6/szVNdTzyi4hDa+9OLbzS8tSd2iUV4CqimLNWex2Y=' 'self'; frame-src 'self'; style-src 'unsafe-inline';">
7575

7676
<!-- Disable pinch zooming -->
7777
<meta name="viewport"

0 commit comments

Comments
 (0)