aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/web_test.go
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:48:50 +0300
committergrm <grm@eyesin.space>2026-09-18 13:48:50 +0300
commitabc1898daebae33405688618caffa01cece3b850 (patch)
treeaab73282a999647ec196c29bb3312ef8491c725c /internal/web/web_test.go
parent526a8742688ed58ae40ba1f254c2e7f1f7bbd866 (diff)
downloadblogspace-abc1898daebae33405688618caffa01cece3b850.tar.gz
blogspace-abc1898daebae33405688618caffa01cece3b850.tar.bz2
blogspace-abc1898daebae33405688618caffa01cece3b850.zip
Security: Refuse form posts a browser marks as coming from another origin
Every blog is a subdomain of the root domain, which makes a blog page "same-site" to the dashboard: SameSite=Lax sends the session cookie with a form a blog's custom HTML submits to example.com. The HMAC token already stops those, but the login form had nothing (login CSRF), and a second, independent check costs one header lookup. A POST whose Sec-Fetch-Site is cross-site or same-site is now refused in guardPOST and on login; old browsers without the header keep working under the token alone. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/web_test.go')
-rw-r--r--internal/web/web_test.go23
1 files changed, 23 insertions, 0 deletions
diff --git a/internal/web/web_test.go b/internal/web/web_test.go
index 74c0fb7..b1609cd 100644
--- a/internal/web/web_test.go
+++ b/internal/web/web_test.go
@@ -1026,3 +1026,26 @@ func TestLogoutAnonymous(t *testing.T) {
t.Errorf("got %d → %q", rec.Code, rec.Header().Get("Location"))
}
}
+
+// A POST a browser marks as coming from another origin is refused, blog subdomains included; old browsers send no header.
+func TestCrossSiteForm(t *testing.T) {
+ for site, want := range map[string]bool{"": false, "none": false, "same-origin": false, "same-site": true, "cross-site": true} {
+ req := httptest.NewRequest("POST", "/", nil)
+ if site != "" {
+ req.Header.Set("Sec-Fetch-Site", site)
+ }
+ if got := crossSiteForm(req); got != want {
+ t.Errorf("Sec-Fetch-Site %q: %v", site, got)
+ }
+ }
+ s := NewServer(&config.Config{BaseDomain: "example.com", JWTSecret: []byte("x")}, nil)
+ rec := httptest.NewRecorder()
+ req := httptest.NewRequest("POST", "/webadmin", strings.NewReader("username=a&password=b"))
+ req.Host = "example.com"
+ req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
+ req.Header.Set("Sec-Fetch-Site", "same-site")
+ s.ServeHTTP(rec, req)
+ if rec.Code != http.StatusForbidden {
+ t.Errorf("cross-site login: got %d, want 403", rec.Code)
+ }
+}