aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--AGENTS.md7
-rw-r--r--internal/web/handlers_auth.go4
-rw-r--r--internal/web/server.go17
-rw-r--r--internal/web/web_test.go23
4 files changed, 49 insertions, 2 deletions
diff --git a/AGENTS.md b/AGENTS.md
index 4640647..9764661 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -126,8 +126,11 @@ internal/web/ server.go (host router, middleware, render helpers)
if disabled or version mismatch. Password change / reset / disable bump
`token_version`. Every management POST must include
`<input type="hidden" name="_csrf" value="{{.CSRF}}">`; the check runs in
- `guardPOST`, which first caps the body at the limit it is given + 1 MB
- and parses the form. `requireLogin` only redirects anonymous users;
+ `guardPOST`, which first refuses a POST whose `Sec-Fetch-Site` is
+ `cross-site` or `same-site` (`crossSiteForm`: a blog subdomain is
+ same-site, only the dashboard origin may post; the login form checks it
+ too against login-CSRF), then caps the body at the limit it is given +
+ 1 MB and parses the form. `requireLogin` only redirects anonymous users;
`requireAuth` = login + `guardPOST(0)` (dashboard, password, admin: no
uploads); `withBlog` = login → `resolveBlog` → owner-or-superadmin →
`guardPOST(blog.UploadLimit(cfg))`, and `withBlogFiles(n, …)` allows n
diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go
index 5c57254..1cb83ba 100644
--- a/internal/web/handlers_auth.go
+++ b/internal/web/handlers_auth.go
@@ -49,6 +49,10 @@ func (s *Server) handleWebadminRedirect(w http.ResponseWriter, r *http.Request)
const maxLoginBody = 64 << 10
func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
+ if crossSiteForm(r) { // login CSRF: another site logging the visitor into an account it knows
+ s.plainError(w, http.StatusForbidden, s.tr(r, "Form expired or invalid. Go back, reload the page and try again."))
+ return
+ }
r.Body = http.MaxBytesReader(w, r.Body, maxLoginBody)
if err := r.ParseForm(); err != nil {
s.plainError(w, http.StatusBadRequest, s.tr(r, "Could not read the form."))
diff --git a/internal/web/server.go b/internal/web/server.go
index f768ebd..5a6ac4e 100644
--- a/internal/web/server.go
+++ b/internal/web/server.go
@@ -214,6 +214,10 @@ func (s *Server) guardPOST(w http.ResponseWriter, r *http.Request, limit int64)
if r.Method != http.MethodPost {
return true
}
+ if crossSiteForm(r) {
+ s.fail(w, r, http.StatusForbidden, s.tr(r, "Form expired or invalid. Go back, reload the page and try again."))
+ return false
+ }
u := currentUser(r)
// Cap the request body before any form parsing (uploads included).
r.Body = http.MaxBytesReader(w, r.Body, limit+1<<20)
@@ -233,6 +237,19 @@ func (s *Server) guardPOST(w http.ResponseWriter, r *http.Request, limit int64)
return true
}
+// crossSiteForm says a browser sent the POST from another origin. Blogs are
+// subdomains of the root domain, so a blog page is "same-site" to the
+// dashboard and SameSite=Lax would send the cookie along; only the dashboard
+// itself ("same-origin") or a typed address ("none") may post. Browsers too
+// old to send the header pass, and the CSRF token still covers them.
+func crossSiteForm(r *http.Request) bool {
+ switch r.Header.Get("Sec-Fetch-Site") {
+ case "cross-site", "same-site":
+ return true
+ }
+ return false
+}
+
// requireAuth is for management pages outside a blog (dashboard, password,
// admin): logged in, small forms only.
func (s *Server) requireAuth(next http.HandlerFunc) http.HandlerFunc {
diff --git a/internal/web/web_test.go b/internal/web/web_test.go
index 74c0fb7..b1609cd 100644
--- a/internal/web/web_test.go
+++ b/internal/web/web_test.go
@@ -1026,3 +1026,26 @@ func TestLogoutAnonymous(t *testing.T) {
t.Errorf("got %d → %q", rec.Code, rec.Header().Get("Location"))
}
}
+
+// A POST a browser marks as coming from another origin is refused, blog subdomains included; old browsers send no header.
+func TestCrossSiteForm(t *testing.T) {
+ for site, want := range map[string]bool{"": false, "none": false, "same-origin": false, "same-site": true, "cross-site": true} {
+ req := httptest.NewRequest("POST", "/", nil)
+ if site != "" {
+ req.Header.Set("Sec-Fetch-Site", site)
+ }
+ if got := crossSiteForm(req); got != want {
+ t.Errorf("Sec-Fetch-Site %q: %v", site, got)
+ }
+ }
+ s := NewServer(&config.Config{BaseDomain: "example.com", JWTSecret: []byte("x")}, nil)
+ rec := httptest.NewRecorder()
+ req := httptest.NewRequest("POST", "/webadmin", strings.NewReader("username=a&password=b"))
+ req.Host = "example.com"
+ req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
+ req.Header.Set("Sec-Fetch-Site", "same-site")
+ s.ServeHTTP(rec, req)
+ if rec.Code != http.StatusForbidden {
+ t.Errorf("cross-site login: got %d, want 403", rec.Code)
+ }
+}