diff options
| author | grm <grm@eyesin.space> | 2026-09-18 13:48:27 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-18 13:48:27 +0300 |
| commit | 526a8742688ed58ae40ba1f254c2e7f1f7bbd866 (patch) | |
| tree | adbcd6e77ee36259e8df5fb53c8762b4cbe6fc81 /internal/web/templates/partials/dashnav.html | |
| parent | d71a01f4fcc4bb5ca040889694c94a07e52fa50e (diff) | |
| download | blogspace-526a8742688ed58ae40ba1f254c2e7f1f7bbd866.tar.gz blogspace-526a8742688ed58ae40ba1f254c2e7f1f7bbd866.tar.bz2 blogspace-526a8742688ed58ae40ba1f254c2e7f1f7bbd866.zip | |
Security: Check the CSRF token on logout
/logout was the one management POST without the token. A blog lives on
a subdomain of the root domain, which is same-site, so SameSite=Lax
does not keep the cookie off a form a blog page submits: any blogger's
custom HTML could log the superadmin out at will. The logout form
already carried _csrf; the handler now checks it through guardPOST.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/templates/partials/dashnav.html')
0 files changed, 0 insertions, 0 deletions
