Skip to content

Protect CSRF (Cross-Site Request Forgery) #30

Description

@taitelee

Problem

CSRF relies on the fact that browsers automatically send cookies. If someone is logged into the WaveHouse dashboard at wavehouse.com, the browser has a session cookie for that domain. If that person accidentally visit some malicious site in another tab, that site can include a hidden form that sends a POST request to wavehouse.com/api/pipes/delete. Because it's the same browser making the request, it attaches the login cookie, and WaveHouse thinks that person authorized the deletion.

Proposed Solution

The most common approach to solve this is bearer tokens. Don't use cookies at all. The frontend can store the JWT in localStorage or sessionStorage and sends it via the Authorization header: Authorization: Bearer <jwt_token>

Browsers do not automatically attach headers to cross-site requests. Malicious sites can trick the browser into sending a cookie, but it has no way to "reach into" the browser's memory, grab the JWT, and put it in a custom header.

Note: Dependencies struct already includes api.JWTAuthMiddleware, so we are likely already using this approach? Just make sure cookies aren't storing that JWT

Alternatives Considered

Synchronizer Token Pattern with handshake.

Additional Context

Check CORS middleware

Activity

  1. added theissue type on Apr 16, 2026
  2. changed the title [-][feature] Protect CSRF (Cross-Site Request Forgery)[/-] [+]Protect CSRF (Cross-Site Request Forgery)[/+] on Apr 16, 2026
  3. self-assigned this
    on Apr 16, 2026
  4. moved this from Backlog to In progress in WaveHouse Task Boardon Apr 27, 2026
  5. moved this from In progress to Backlog in WaveHouse Task Boardon Apr 27, 2026
  6. moved this from Backlog to Ready in WaveHouse Task Boardon May 12, 2026
  7. moved this from Ready to In progress in WaveHouse Task Boardon May 12, 2026
  8. moved this from In progress to In review in WaveHouse Task Boardon May 13, 2026
  9. added a commit that references this issue on May 13, 2026
    b8fc829
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions