Skip to content

gateway: protect against CSRF #14546

@emersion

Description

@emersion

Description and goal

The Sec-Fetch-Site HTTP header field is set by modern Web browsers and allows servers to easily protect against CSRF.

editoast doesn't have a lot of state-changing simple requests, so the risk isn't very high. At worst, CSRF could be used to change a rolling stock's image, or to send a STDCM railway manager request. Still, we may introduce more simple requests in the future, and better be safe than sorry.

See https://words.filippo.io/csrf/

Acceptance criteria

.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions