diff options
Diffstat (limited to 'AGENTS.md')
| -rw-r--r-- | AGENTS.md | 7 |
1 files changed, 5 insertions, 2 deletions
@@ -126,8 +126,11 @@ internal/web/ server.go (host router, middleware, render helpers) if disabled or version mismatch. Password change / reset / disable bump `token_version`. Every management POST must include `<input type="hidden" name="_csrf" value="{{.CSRF}}">`; the check runs in - `guardPOST`, which first caps the body at the limit it is given + 1 MB - and parses the form. `requireLogin` only redirects anonymous users; + `guardPOST`, which first refuses a POST whose `Sec-Fetch-Site` is + `cross-site` or `same-site` (`crossSiteForm`: a blog subdomain is + same-site, only the dashboard origin may post; the login form checks it + too against login-CSRF), then caps the body at the limit it is given + + 1 MB and parses the form. `requireLogin` only redirects anonymous users; `requireAuth` = login + `guardPOST(0)` (dashboard, password, admin: no uploads); `withBlog` = login → `resolveBlog` → owner-or-superadmin → `guardPOST(blog.UploadLimit(cfg))`, and `withBlogFiles(n, …)` allows n |
