aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/handlers_auth.go
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:48:50 +0300
committergrm <grm@eyesin.space>2026-09-18 13:48:50 +0300
commitabc1898daebae33405688618caffa01cece3b850 (patch)
treeaab73282a999647ec196c29bb3312ef8491c725c /internal/web/handlers_auth.go
parent526a8742688ed58ae40ba1f254c2e7f1f7bbd866 (diff)
downloadblogspace-abc1898daebae33405688618caffa01cece3b850.tar.gz
blogspace-abc1898daebae33405688618caffa01cece3b850.tar.bz2
blogspace-abc1898daebae33405688618caffa01cece3b850.zip
Security: Refuse form posts a browser marks as coming from another origin
Every blog is a subdomain of the root domain, which makes a blog page "same-site" to the dashboard: SameSite=Lax sends the session cookie with a form a blog's custom HTML submits to example.com. The HMAC token already stops those, but the login form had nothing (login CSRF), and a second, independent check costs one header lookup. A POST whose Sec-Fetch-Site is cross-site or same-site is now refused in guardPOST and on login; old browsers without the header keep working under the token alone. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/handlers_auth.go')
-rw-r--r--internal/web/handlers_auth.go4
1 files changed, 4 insertions, 0 deletions
diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go
index 5c57254..1cb83ba 100644
--- a/internal/web/handlers_auth.go
+++ b/internal/web/handlers_auth.go
@@ -49,6 +49,10 @@ func (s *Server) handleWebadminRedirect(w http.ResponseWriter, r *http.Request)
const maxLoginBody = 64 << 10
func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
+ if crossSiteForm(r) { // login CSRF: another site logging the visitor into an account it knows
+ s.plainError(w, http.StatusForbidden, s.tr(r, "Form expired or invalid. Go back, reload the page and try again."))
+ return
+ }
r.Body = http.MaxBytesReader(w, r.Body, maxLoginBody)
if err := r.ParseForm(); err != nil {
s.plainError(w, http.StatusBadRequest, s.tr(r, "Could not read the form."))