fix(csrf): CSRF cookie was HttpOnly, breaking the double-submit pattern - #21
Merged
Merged
Conversation
…bmit pattern The double-submit cookie pattern relies on client-side JavaScript reading the CSRF cookie and echoing its value back in a request header (header_name, e.g. X-CSRF-Token) -- that round-trip is what proves the request came from same-origin script, since a cross-site attacker can trigger a cookie-carrying request but can't read the cookie's value to set the matching header. _set_csrf_cookie() set HttpOnly on that cookie, which makes it invisible to JavaScript entirely. Every real browser client would be structurally unable to complete the round-trip: every state-changing request would 403 with "CSRF token missing" until an app author noticed and manually worked around the framework. Found reading the source while building a session-cookie app; not caught by any existing test. Removed HttpOnly. Added a regression test. 261/261 tests, mypy clean, ruff clean.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The double-submit pattern relies on client-side JS reading the CSRF cookie and echoing it back in a request header — that round-trip is what proves same-origin, since a cross-site attacker can't read the cookie's value. _set_csrf_cookie() set HttpOnly on it, making that impossible for any real browser client: every state-changing request would 403 until someone noticed. Found reading the source while building a session-cookie app; no existing test caught it.
Removed HttpOnly, added a regression test. 261/261 tests, mypy clean, ruff clean.