diff options
Diffstat (limited to 'internal/web/server.go')
| -rw-r--r-- | internal/web/server.go | 17 |
1 files changed, 17 insertions, 0 deletions
diff --git a/internal/web/server.go b/internal/web/server.go index f768ebd..5a6ac4e 100644 --- a/internal/web/server.go +++ b/internal/web/server.go @@ -214,6 +214,10 @@ func (s *Server) guardPOST(w http.ResponseWriter, r *http.Request, limit int64) if r.Method != http.MethodPost { return true } + if crossSiteForm(r) { + s.fail(w, r, http.StatusForbidden, s.tr(r, "Form expired or invalid. Go back, reload the page and try again.")) + return false + } u := currentUser(r) // Cap the request body before any form parsing (uploads included). r.Body = http.MaxBytesReader(w, r.Body, limit+1<<20) @@ -233,6 +237,19 @@ func (s *Server) guardPOST(w http.ResponseWriter, r *http.Request, limit int64) return true } +// crossSiteForm says a browser sent the POST from another origin. Blogs are +// subdomains of the root domain, so a blog page is "same-site" to the +// dashboard and SameSite=Lax would send the cookie along; only the dashboard +// itself ("same-origin") or a typed address ("none") may post. Browsers too +// old to send the header pass, and the CSRF token still covers them. +func crossSiteForm(r *http.Request) bool { + switch r.Header.Get("Sec-Fetch-Site") { + case "cross-site", "same-site": + return true + } + return false +} + // requireAuth is for management pages outside a blog (dashboard, password, // admin): logged in, small forms only. func (s *Server) requireAuth(next http.HandlerFunc) http.HandlerFunc { |
