Skip to content

Conversation

@tongyuze
Copy link

@tongyuze tongyuze commented Aug 6, 2025

eSTS expects we send x-client-os: Windows instead of win32 as there are no OS called win 32. win32 is not a recognized OS string in the current server-side platform detection logic.

@tongyuze tongyuze requested a review from a team as a code owner August 6, 2025 20:36
Copy link
Contributor

@rayluo rayluo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stakeholders discussed offline and are evaluating alternative options. So, I am leaving a Request Changes review here for now, so that my other teammates will not merge this PR as-is.

@tongyuze tongyuze closed this Aug 14, 2025
@rayluo
Copy link
Contributor

rayluo commented Aug 14, 2025

Summary of the offline discussion.

  • We consider have service-side consume the client-side "win32" value which has existed since day one.
  • Regardless, the user-agent value and x-client-os value, which is what CA relies on for platform detection in this case, is easily spoofable even without a proxy, which is why our public guidance advises against using platform information for Conditional Access controls.

@rayluo rayluo deleted the yuto/change-os-header branch August 14, 2025 18:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants