False positive: "Missing cross-site request forgery token validation" in C# API for endpoint with no cookie/session tokens
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the false positive**
We are using a .NET 10 Api and since commit https://github.com/github/codeql/commit/5bb31afc834f53d5ea719d782744ff9c7ab70fc2 we get a false positive on a server -> server endpoint where we have a ApiKey in the header with no tokens or cookies.
Is it possible to extend the check to look if cookie/token authentication is used instead of a ApiKey?
**Code samples or links to source code**
```
public class Controller()
{
[HttpPost()]
public string Execute()
{
return "test";
}
```
貢獻指南
研究方向
先檢視 commit 5bb31afc834f53d5ea719d782744ff9c7ab70fc0 和此 issue 中的 C# API 範例,以了解為什麼此發現適用。找到查詢入口及其現有測試,然後確認僅使用 API key 的 server-to-server 端點不會被標記,而使用 cookie 或 token 驗證的端點仍會被標記。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- csharp
- 領域
- api, security
- Issue 類型
- 缺陷
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 活躍度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 45/100