test(security): prove cross-origin form POSTs are rejected #280
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!280
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "test/csrf-origin-check"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
POST.security.checkOrigin: trueset explicitly inastro.config.mjs.Accept-Languagedetection (Refs #177).Why
Astro's origin check is the only CSRF protection on the state-changing routes, and nothing failed if it went away. The README claimed detection that does not exist.
How tested
src/test/csrf-origin.test.tsstartsdist/server/entry.mjson a free port. It finds routes by scanningsrc/pagesforexport const POST, so new routes are covered. Per route: cross-originapplication/x-www-form-urlencoded,multipart/form-dataandtext/plainexpect 403. Same-origin control expects not 403.Negative control: with
checkOrigin: falsethe test fails (30 failed, 11 passed). Withtrue: 41 passed.It runs in CI under the existing
pnpm teststep, afterBuild. The CI does not run Playwright, so e2e was not an option. Locally the file skips ifdist/is missing. UnderCIit fails instead.Findings
Astro only checks form content types (urlencoded, multipart, text/plain) and requests with no content type. A cross-origin request with another content type (for example
application/json) passes the check./api/captcha/redeemreads JSON. It uses no session and no cookie, so CSRF does not apply.request.formData(), which fails on a JSON body.No route is exposed today. A future JSON route that uses the session cookie would be. Cross-origin JSON with a cookie needs a CORS preflight, which is not granted. The session cookie is SameSite=Lax, a second layer.
Open questions
Visa kommandoradsinstruktioner
Checka ut
Checka ut en ny gren från din projektkatalog och testa ändringarna.