con2 / con2/kompassi

Require a CSRF token when GraphQL API is authenticated by anything else than Bearer/Basic

Open
#358 0 comments 0 reactions 0 assignees View on GitHub
security
Dominant language
Python
Stars
29
Forks
33
Avg merge
1d 22h
Merged PRs (30d)
19

Description

As of 2024-01-12, there is a CSRF possibility in cookie authentication to the GraphQL API. Currently the risk is low as there are very few authenticated resources in the API and they provide very little information. However, we should require a CSRF token when the GraphQL API is authenticated via a cookie, and monkey patch GraphiQL to include the token.

https://outline.con2.fi/doc/graphql-ZKn04xpcvm#h-graphql-playground-session-based-authentication

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.