From abc1898daebae33405688618caffa01cece3b850 Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:48:50 +0300 Subject: Security: Refuse form posts a browser marks as coming from another origin Every blog is a subdomain of the root domain, which makes a blog page "same-site" to the dashboard: SameSite=Lax sends the session cookie with a form a blog's custom HTML submits to example.com. The HMAC token already stops those, but the login form had nothing (login CSRF), and a second, independent check costs one header lookup. A POST whose Sec-Fetch-Site is cross-site or same-site is now refused in guardPOST and on login; old browsers without the header keep working under the token alone. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- AGENTS.md | 7 +++++-- internal/web/handlers_auth.go | 4 ++++ internal/web/server.go | 17 +++++++++++++++++ internal/web/web_test.go | 23 +++++++++++++++++++++++ 4 files changed, 49 insertions(+), 2 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 4640647..9764661 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -126,8 +126,11 @@ internal/web/ server.go (host router, middleware, render helpers) if disabled or version mismatch. Password change / reset / disable bump `token_version`. Every management POST must include ``; the check runs in - `guardPOST`, which first caps the body at the limit it is given + 1 MB - and parses the form. `requireLogin` only redirects anonymous users; + `guardPOST`, which first refuses a POST whose `Sec-Fetch-Site` is + `cross-site` or `same-site` (`crossSiteForm`: a blog subdomain is + same-site, only the dashboard origin may post; the login form checks it + too against login-CSRF), then caps the body at the limit it is given + + 1 MB and parses the form. `requireLogin` only redirects anonymous users; `requireAuth` = login + `guardPOST(0)` (dashboard, password, admin: no uploads); `withBlog` = login → `resolveBlog` → owner-or-superadmin → `guardPOST(blog.UploadLimit(cfg))`, and `withBlogFiles(n, …)` allows n diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go index 5c57254..1cb83ba 100644 --- a/internal/web/handlers_auth.go +++ b/internal/web/handlers_auth.go @@ -49,6 +49,10 @@ func (s *Server) handleWebadminRedirect(w http.ResponseWriter, r *http.Request) const maxLoginBody = 64 << 10 func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { + if crossSiteForm(r) { // login CSRF: another site logging the visitor into an account it knows + s.plainError(w, http.StatusForbidden, s.tr(r, "Form expired or invalid. Go back, reload the page and try again.")) + return + } r.Body = http.MaxBytesReader(w, r.Body, maxLoginBody) if err := r.ParseForm(); err != nil { s.plainError(w, http.StatusBadRequest, s.tr(r, "Could not read the form.")) diff --git a/internal/web/server.go b/internal/web/server.go index f768ebd..5a6ac4e 100644 --- a/internal/web/server.go +++ b/internal/web/server.go @@ -214,6 +214,10 @@ func (s *Server) guardPOST(w http.ResponseWriter, r *http.Request, limit int64) if r.Method != http.MethodPost { return true } + if crossSiteForm(r) { + s.fail(w, r, http.StatusForbidden, s.tr(r, "Form expired or invalid. Go back, reload the page and try again.")) + return false + } u := currentUser(r) // Cap the request body before any form parsing (uploads included). r.Body = http.MaxBytesReader(w, r.Body, limit+1<<20) @@ -233,6 +237,19 @@ func (s *Server) guardPOST(w http.ResponseWriter, r *http.Request, limit int64) return true } +// crossSiteForm says a browser sent the POST from another origin. Blogs are +// subdomains of the root domain, so a blog page is "same-site" to the +// dashboard and SameSite=Lax would send the cookie along; only the dashboard +// itself ("same-origin") or a typed address ("none") may post. Browsers too +// old to send the header pass, and the CSRF token still covers them. +func crossSiteForm(r *http.Request) bool { + switch r.Header.Get("Sec-Fetch-Site") { + case "cross-site", "same-site": + return true + } + return false +} + // requireAuth is for management pages outside a blog (dashboard, password, // admin): logged in, small forms only. func (s *Server) requireAuth(next http.HandlerFunc) http.HandlerFunc { diff --git a/internal/web/web_test.go b/internal/web/web_test.go index 74c0fb7..b1609cd 100644 --- a/internal/web/web_test.go +++ b/internal/web/web_test.go @@ -1026,3 +1026,26 @@ func TestLogoutAnonymous(t *testing.T) { t.Errorf("got %d → %q", rec.Code, rec.Header().Get("Location")) } } + +// A POST a browser marks as coming from another origin is refused, blog subdomains included; old browsers send no header. +func TestCrossSiteForm(t *testing.T) { + for site, want := range map[string]bool{"": false, "none": false, "same-origin": false, "same-site": true, "cross-site": true} { + req := httptest.NewRequest("POST", "/", nil) + if site != "" { + req.Header.Set("Sec-Fetch-Site", site) + } + if got := crossSiteForm(req); got != want { + t.Errorf("Sec-Fetch-Site %q: %v", site, got) + } + } + s := NewServer(&config.Config{BaseDomain: "example.com", JWTSecret: []byte("x")}, nil) + rec := httptest.NewRecorder() + req := httptest.NewRequest("POST", "/webadmin", strings.NewReader("username=a&password=b")) + req.Host = "example.com" + req.Header.Set("Content-Type", "application/x-www-form-urlencoded") + req.Header.Set("Sec-Fetch-Site", "same-site") + s.ServeHTTP(rec, req) + if rec.Code != http.StatusForbidden { + t.Errorf("cross-site login: got %d, want 403", rec.Code) + } +} -- cgit v1.2.3