Skip to content

[Documentation:System] v26.10.01 Apache and nginx version notes - #797

Open
RichardJSun wants to merge 1 commit into
mainfrom
version-notes-v26.10.01
Open

RichardJSun wants to merge 1 commit into
mainfrom
version-notes-v26.10.01

Conversation

@RichardJSun

Copy link
Copy Markdown

Version notes for two [SYSADMIN ACTION] changes to the Apache and nginx configuration:

The installer doesn't update existing configs, so the page gives the manual edits. If the two PRs ship in different releases, the page can be split or renamed then.

bmcutler pushed a commit to Submitty/Submitty that referenced this pull request Oct 7, 2026
### Why is this Change Important & Necessary?
Related to #13391

Ratchet, the library the websocket server uses, rejects handshakes over
4096 bytes with a 413. This PR doesn't add that limit. The browser sends
every cookie for the host with the handshake, including cookies that
other RPI sites set on `.rpi.edu`. Submitty cannot remove those cookies.
The socket server reads only `submitty_websocket_token`.

### What is the New Behavior?
nginx forwards only `submitty_websocket_token` to the socket server, so
other cookies cannot make the handshake too large. The PHP websocket
client is unaffected, because the server identifies it by headers, not
cookies.

Existing servers keep their own nginx config, so a sysadmin adds the
line by hand. See
https://submitty.org/sysadmin/installation/version_notes/v26.10.01
(Submitty/submitty.github.io#797).

#### Screenshots and video
On submitty.cs.rpi.edu, the cookie list includes `_snow_id.1d43` from
another site on `.rpi.edu`:

<img width="1452" height="475" alt="Office hours queue with the
websocket warning; the cookie list includes _snow_id.1d43 on .rpi.edu"
src="https://github.com/user-attachments/assets/6d26fcbb-9729-43bd-84a7-d179ab8104e3"
/>

On a local dev server with the 3.4 KB cookie from step 2, the `main`
nginx config fails with 413, and a live queue announcement does not
arrive:


https://github.com/user-attachments/assets/4d2ba1a7-1d02-4a2a-b4eb-155ac21b6a62

<img width="800" alt="main nginx: HTTP 413 and no live update"
src="https://github.com/user-attachments/assets/37f09fac-da11-4d0d-94f2-2205e578cc1a"
/>

With this config, the websocket connects and the announcement arrives
live:


https://github.com/user-attachments/assets/c0dbfd7b-c01f-4a4e-896e-9819ee2564df

<img width="800" alt="This nginx config: HTTP 101 and the announcement
arrived live"
src="https://github.com/user-attachments/assets/94732aba-4aba-42e9-9143-e7d46510e0bc"
/>

### What steps should a reviewer take to reproduce or test the bug or
new feature?
1. Add the line from `.setup/nginx/submitty.conf` to the `location /ws`
block of `/etc/nginx/sites-available/submitty.conf`, then run `sudo
systemctl reload nginx`.
2. Run `Cookies.set('big_test_cookie', 'x'.repeat(3500))` in the browser
console.
3. Open the office hours queue. It connects. On `main` it fails with
413.
4. From a second browser, post a queue announcement as the instructor.
It appears without a reload.

### Automated Testing & Documentation
No new tests.

### Other information
**SYSADMIN ACTION:** see
https://submitty.org/sysadmin/installation/version_notes/v26.10.01.

This doesn't help once the whole `Cookie` header passes 8 KB. nginx and
Apache both reject such requests with a 400 by default, so every page
fails at that point, not just the websocket.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Seeking Reviewer

Development

Successfully merging this pull request may close these issues.

2 participants