Problem
CSRF relies on the fact that browsers automatically send cookies. If someone is logged into the WaveHouse dashboard at wavehouse.com, the browser has a session cookie for that domain. If that person accidentally visit some malicious site in another tab, that site can include a hidden form that sends a POST request to wavehouse.com/api/pipes/delete. Because it's the same browser making the request, it attaches the login cookie, and WaveHouse thinks that person authorized the deletion.
Proposed Solution
The most common approach to solve this is bearer tokens. Don't use cookies at all. The frontend can store the JWT in localStorage or sessionStorage and sends it via the Authorization header: Authorization: Bearer <jwt_token>
Browsers do not automatically attach headers to cross-site requests. Malicious sites can trick the browser into sending a cookie, but it has no way to "reach into" the browser's memory, grab the JWT, and put it in a custom header.
Note: Dependencies struct already includes api.JWTAuthMiddleware, so we are likely already using this approach? Just make sure cookies aren't storing that JWT
Alternatives Considered
Synchronizer Token Pattern with handshake.
Additional Context
Check CORS middleware
Problem
CSRF relies on the fact that browsers automatically send cookies. If someone is logged into the WaveHouse dashboard at wavehouse.com, the browser has a session cookie for that domain. If that person accidentally visit some malicious site in another tab, that site can include a hidden form that sends a POST request to wavehouse.com/api/pipes/delete. Because it's the same browser making the request, it attaches the login cookie, and WaveHouse thinks that person authorized the deletion.
Proposed Solution
The most common approach to solve this is bearer tokens. Don't use cookies at all. The frontend can store the JWT in localStorage or sessionStorage and sends it via the Authorization header: Authorization: Bearer <jwt_token>
Browsers do not automatically attach headers to cross-site requests. Malicious sites can trick the browser into sending a cookie, but it has no way to "reach into" the browser's memory, grab the JWT, and put it in a custom header.
Note: Dependencies struct already includes api.JWTAuthMiddleware, so we are likely already using this approach? Just make sure cookies aren't storing that JWT
Alternatives Considered
Synchronizer Token Pattern with handshake.
Additional Context
Check CORS middleware