aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/server.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/web/server.go')
-rw-r--r--internal/web/server.go17
1 files changed, 17 insertions, 0 deletions
diff --git a/internal/web/server.go b/internal/web/server.go
index f768ebd..5a6ac4e 100644
--- a/internal/web/server.go
+++ b/internal/web/server.go
@@ -214,6 +214,10 @@ func (s *Server) guardPOST(w http.ResponseWriter, r *http.Request, limit int64)
if r.Method != http.MethodPost {
return true
}
+ if crossSiteForm(r) {
+ s.fail(w, r, http.StatusForbidden, s.tr(r, "Form expired or invalid. Go back, reload the page and try again."))
+ return false
+ }
u := currentUser(r)
// Cap the request body before any form parsing (uploads included).
r.Body = http.MaxBytesReader(w, r.Body, limit+1<<20)
@@ -233,6 +237,19 @@ func (s *Server) guardPOST(w http.ResponseWriter, r *http.Request, limit int64)
return true
}
+// crossSiteForm says a browser sent the POST from another origin. Blogs are
+// subdomains of the root domain, so a blog page is "same-site" to the
+// dashboard and SameSite=Lax would send the cookie along; only the dashboard
+// itself ("same-origin") or a typed address ("none") may post. Browsers too
+// old to send the header pass, and the CSRF token still covers them.
+func crossSiteForm(r *http.Request) bool {
+ switch r.Header.Get("Sec-Fetch-Site") {
+ case "cross-site", "same-site":
+ return true
+ }
+ return false
+}
+
// requireAuth is for management pages outside a blog (dashboard, password,
// admin): logged in, small forms only.
func (s *Server) requireAuth(next http.HandlerFunc) http.HandlerFunc {