aboutsummaryrefslogtreecommitdiffstats
path: root/AGENTS.md
diff options
context:
space:
mode:
Diffstat (limited to 'AGENTS.md')
-rw-r--r--AGENTS.md5
1 files changed, 4 insertions, 1 deletions
diff --git a/AGENTS.md b/AGENTS.md
index 4f5e893..4640647 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -133,7 +133,10 @@ internal/web/ server.go (host router, middleware, render helpers)
`guardPOST(blog.UploadLimit(cfg))`, and `withBlogFiles(n, …)` allows n
limits for the Files page's multi-upload (`maxUploadFiles` = 10). Errors
from `guardPOST` go through `s.fail`, which answers JSON when the request
- has `Accept: application/json` (the upload scripts).
+ has `Accept: application/json` (the upload scripts). `POST /logout` runs
+ `guardPOST` too when a user is logged in (blogs are same-site with the
+ root domain, so `SameSite=Lax` alone would let a blog page log a
+ superadmin out).
- **Hardening** (`web/ratelimit.go`): a per-key token bucket throttles the
anonymous endpoints worth abusing — `loginLimit` on `POST /webadmin`, keyed
by client address *and* by lowercased username (10 at once, then 10 a