github / github/codeql

False positive: "Missing cross-site request forgery token validation" in C# API for endpoint with no cookie/session tokens

Open
#21,665 0 comments 1 reaction 0 assignees View on GitHub
false-positive
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

**Description of the false positive**

We are using a .NET 10 Api and since commit https://github.com/github/codeql/commit/5bb31afc834f53d5ea719d782744ff9c7ab70fc2 we get a false positive on a server -> server endpoint where we have a ApiKey in the header with no tokens or cookies.

Is it possible to extend the check to look if cookie/token authentication is used instead of a ApiKey?

**Code samples or links to source code**

```
public class Controller()
{

[HttpPost()]
public string Execute()
{
return "test";
}

```

Contributor guide

Open the contributing guide

Research direction

Start by reviewing commit 5bb31afc834f53d5ea719d782744ff9c7ab70fc0 and the C# API example in this issue to understand why the finding applies. Locate the query entry point and its existing tests, then verify that API-key-only server-to-server endpoints are not flagged while endpoints using cookie or token authentication still are.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
api, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.