RMAT-242: route CMO load-balancer sessions to the default upstream - #2183
Merged
Merged
Conversation
Release Candidate - CWA
RMAT-242: Fix for proxy on Prod
C-CMO-LBsessioncookie was detected as env 'cmo', which has no configured upstream, so the DDEI /CMS call proxied to an undefined host and returned no redirect (CmsException 'Could not extract CMS version ID'). In UAT the default upstream is cmo.cps.gov.uk, so route CMO sessions to the default env - restoring the pre-RMAT-242 behaviour.
kramduny-cps
previously approved these changes
Sep 16, 2026
cms-detection.js (the un-deployed 'next' config's cms-env primitive) had the same latent bug as the live cmsenv.js: cmo has no configured upstream, so mapping mod/cmo cookies to env 'cmo' would proxy to an undefined host. Route them to 'default' instead, matching the live fix. Updates the characterisation test and a stale comment in cms-proxy.js accordingly.
Both containers are local integration-test fixtures (not deployed), and already documented why they deliberately run as root: Dockerfile.nginx needs the master process bound to root to listen on port 80 and drop worker privileges per nginx.conf's own 'user nginx;' directive; Dockerfile.mock listens on the privileged port 443 to answer the hardcoded App Insights hostname. Added #checkov:skip=CKV_DOCKER_3 annotations with those reasons, matching the skip convention already used elsewhere in this repo's Terraform files, rather than adding a USER directive that would break either container.
kramduny-cps
approved these changes
Sep 17, 2026
|
auto-merge was automatically disabled
September 17, 2026 10:40
Merge commits are not allowed on this repository
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Problem
DDEI calls to the CMS proxy
/internal-implementation/{corsham,farnborough}/CMS(thecms-modern-token/ auth-refresh flow) were failing in UAT with:CmsException: Could not extract CMS version ID from home route redirect response->InvalidOperationException: Sequence contains no matching elementi.e. the upstream returned no
Locationheader (no redirect).Root cause
Commit
83bacc65(RMAT-242, "Fix for proxy on Prod") changedcmsenv.jsenv detection fromcookie.includes("mod")tocookie.includes("-cmo-lb"). Real UAT sessions carry aC-CMO-LBsessioncookie, so detection now returns envcmo- but there is nocmoupstream configured (nginx.conf js_vars and app settings define onlydefault/cpt/cin2/cin4/cin5).proxyDestinationCorshamInternaltherefore buildshttps://undefined, theproxy_passfails, and no/CMS.<version>redirect is returned.Before RMAT-242,
C-CMO-LBsessioncookiecontained nomodsubstring and fell through todefault- and in UAT the default upstream iscmo.cps.gov.uk, so it worked.Fix
Route CMO sessions to the
defaultenv. CMO has no dedicated upstream, and in UAT the default upstream iscmo.cps.gov.uk, so this restores the pre-RMAT-242 behaviour. Prod/dev/qa are unaffected (their defaults arecms/cin3, and CMO cookies do not legitimately occur there).Scope / notes
cmsenv.js(FORCE_REFRESH_CONFIGmd5 will pick it up on apply).proxy/config/.../cms-detection.js) still detectscmofrom themodtoken and carries the same latent "cmo has no upstream" quirk (documented in its QUIRKS.md). It is not deployed, so it is left as a follow-up rather than widening this PR.