github / github/codeql

False positive: "Missing cross-site request forgery token validation" in C# API for endpoint with no cookie/session tokens

Abierto
#21,665 0 comentarios 1 reacción 0 asignados Ver en GitHub
false-positive
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the false positive**

We are using a .NET 10 Api and since commit https://github.com/github/codeql/commit/5bb31afc834f53d5ea719d782744ff9c7ab70fc2 we get a false positive on a server -> server endpoint where we have a ApiKey in the header with no tokens or cookies.

Is it possible to extend the check to look if cookie/token authentication is used instead of a ApiKey?

**Code samples or links to source code**

```
public class Controller()
{

[HttpPost()]
public string Execute()
{
return "test";
}

```

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start by reviewing commit 5bb31afc834f53d5ea719d782744ff9c7ab70fc0 and the C# API example in this issue to understand why the finding applies. Locate the query entry point and its existing tests, then verify that API-key-only server-to-server endpoints are not flagged while endpoints using cookie or token authentication still are.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
csharp
Área
api, security
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Tranquilo
Claridad
Bastante claro
Aptitud para principiantes
45/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.