Skip to content

fix(csrf): CSRF cookie was HttpOnly, breaking the double-submit pattern - #21

Merged
magi8101 merged 1 commit into
mainfrom
fix/csrf-cookie-httponly-blocks-double-submit
Sep 6, 2026
Merged

magi8101 merged 1 commit into
mainfrom
fix/csrf-cookie-httponly-blocks-double-submit

Conversation

@magi8101

@magi8101 magi8101 commented Sep 6, 2026

Copy link
Copy Markdown
Member

The double-submit pattern relies on client-side JS reading the CSRF cookie and echoing it back in a request header — that round-trip is what proves same-origin, since a cross-site attacker can't read the cookie's value. _set_csrf_cookie() set HttpOnly on it, making that impossible for any real browser client: every state-changing request would 403 until someone noticed. Found reading the source while building a session-cookie app; no existing test caught it.

Removed HttpOnly, added a regression test. 261/261 tests, mypy clean, ruff clean.

…bmit pattern

The double-submit cookie pattern relies on client-side JavaScript reading
the CSRF cookie and echoing its value back in a request header
(header_name, e.g. X-CSRF-Token) -- that round-trip is what proves the
request came from same-origin script, since a cross-site attacker can
trigger a cookie-carrying request but can't read the cookie's value to
set the matching header.

_set_csrf_cookie() set HttpOnly on that cookie, which makes it invisible
to JavaScript entirely. Every real browser client would be structurally
unable to complete the round-trip: every state-changing request would
403 with "CSRF token missing" until an app author noticed and manually
worked around the framework. Found reading the source while building a
session-cookie app; not caught by any existing test.

Removed HttpOnly. Added a regression test. 261/261 tests, mypy clean,
ruff clean.
Copilot AI lite review requested due to automatic review settings September 6, 2026 17:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@magi8101
magi8101 merged commit d05db33 into main Sep 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants