From abc1898daebae33405688618caffa01cece3b850 Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:48:50 +0300 Subject: Security: Refuse form posts a browser marks as coming from another origin Every blog is a subdomain of the root domain, which makes a blog page "same-site" to the dashboard: SameSite=Lax sends the session cookie with a form a blog's custom HTML submits to example.com. The HMAC token already stops those, but the login form had nothing (login CSRF), and a second, independent check costs one header lookup. A POST whose Sec-Fetch-Site is cross-site or same-site is now refused in guardPOST and on login; old browsers without the header keep working under the token alone. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- AGENTS.md | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) (limited to 'AGENTS.md') diff --git a/AGENTS.md b/AGENTS.md index 4640647..9764661 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -126,8 +126,11 @@ internal/web/ server.go (host router, middleware, render helpers) if disabled or version mismatch. Password change / reset / disable bump `token_version`. Every management POST must include ``; the check runs in - `guardPOST`, which first caps the body at the limit it is given + 1 MB - and parses the form. `requireLogin` only redirects anonymous users; + `guardPOST`, which first refuses a POST whose `Sec-Fetch-Site` is + `cross-site` or `same-site` (`crossSiteForm`: a blog subdomain is + same-site, only the dashboard origin may post; the login form checks it + too against login-CSRF), then caps the body at the limit it is given + + 1 MB and parses the form. `requireLogin` only redirects anonymous users; `requireAuth` = login + `guardPOST(0)` (dashboard, password, admin: no uploads); `withBlog` = login → `resolveBlog` → owner-or-superadmin → `guardPOST(blog.UploadLimit(cfg))`, and `withBlogFiles(n, …)` allows n -- cgit v1.2.3