aboutsummaryrefslogtreecommitdiffstats
path: root/AGENTS.md
diff options
context:
space:
mode:
Diffstat (limited to 'AGENTS.md')
-rw-r--r--AGENTS.md7
1 files changed, 5 insertions, 2 deletions
diff --git a/AGENTS.md b/AGENTS.md
index 4640647..9764661 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -126,8 +126,11 @@ internal/web/ server.go (host router, middleware, render helpers)
if disabled or version mismatch. Password change / reset / disable bump
`token_version`. Every management POST must include
`<input type="hidden" name="_csrf" value="{{.CSRF}}">`; the check runs in
- `guardPOST`, which first caps the body at the limit it is given + 1 MB
- and parses the form. `requireLogin` only redirects anonymous users;
+ `guardPOST`, which first refuses a POST whose `Sec-Fetch-Site` is
+ `cross-site` or `same-site` (`crossSiteForm`: a blog subdomain is
+ same-site, only the dashboard origin may post; the login form checks it
+ too against login-CSRF), then caps the body at the limit it is given +
+ 1 MB and parses the form. `requireLogin` only redirects anonymous users;
`requireAuth` = login + `guardPOST(0)` (dashboard, password, admin: no
uploads); `withBlog` = login → `resolveBlog` → owner-or-superadmin →
`guardPOST(blog.UploadLimit(cfg))`, and `withBlogFiles(n, …)` allows n