diff options
Diffstat (limited to 'internal/web/handlers_auth.go')
| -rw-r--r-- | internal/web/handlers_auth.go | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go index 5c57254..1cb83ba 100644 --- a/internal/web/handlers_auth.go +++ b/internal/web/handlers_auth.go @@ -49,6 +49,10 @@ func (s *Server) handleWebadminRedirect(w http.ResponseWriter, r *http.Request) const maxLoginBody = 64 << 10 func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { + if crossSiteForm(r) { // login CSRF: another site logging the visitor into an account it knows + s.plainError(w, http.StatusForbidden, s.tr(r, "Form expired or invalid. Go back, reload the page and try again.")) + return + } r.Body = http.MaxBytesReader(w, r.Body, maxLoginBody) if err := r.ParseForm(); err != nil { s.plainError(w, http.StatusBadRequest, s.tr(r, "Could not read the form.")) |
