diff options
| author | grm <grm@eyesin.space> | 2026-09-18 13:48:50 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-18 13:48:50 +0300 |
| commit | abc1898daebae33405688618caffa01cece3b850 (patch) | |
| tree | aab73282a999647ec196c29bb3312ef8491c725c /internal/web/templates/dashboard | |
| parent | 526a8742688ed58ae40ba1f254c2e7f1f7bbd866 (diff) | |
| download | blogspace-abc1898daebae33405688618caffa01cece3b850.tar.gz blogspace-abc1898daebae33405688618caffa01cece3b850.tar.bz2 blogspace-abc1898daebae33405688618caffa01cece3b850.zip | |
Security: Refuse form posts a browser marks as coming from another origin
Every blog is a subdomain of the root domain, which makes a blog page
"same-site" to the dashboard: SameSite=Lax sends the session cookie
with a form a blog's custom HTML submits to example.com. The HMAC token
already stops those, but the login form had nothing (login CSRF), and
a second, independent check costs one header lookup. A POST whose
Sec-Fetch-Site is cross-site or same-site is now refused in guardPOST
and on login; old browsers without the header keep working under the
token alone.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/templates/dashboard')
0 files changed, 0 insertions, 0 deletions
