google / google/gae-secure-scaffold-python3

Document how to use CSRF with SPAs

オープン
#20 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

主要言語
Python
スター
35
フォーク
19
PR マージ指標
30日以内にマージされた PR はありません

説明

Please document how to use this secure scaffold with single page applications, e.g. Angular and React SPAs. These would typically serve the static HTML directly from AppEngine (not through Python templating), which makes it impossible to inject the CSRF token. To make things more complicated, the CSRF token can also not be read from client-side JavaScript, because the secure scaffold defaults set the cookie to HttpOnly.

As far as I can tell, setting the cookie to HttpOnly does not add to the protection in a major way - e.g. see https://docs.djangoproject.com/en/3.0/ref/settings/#csrf-cookie-httponly.

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

まず、secure scaffold が AppEngine から提供される静的 HTML、Python テンプレートのページ、クライアント側 JavaScript に対して CSRF をどのように設定しているかを確認します。HttpOnly cookie の動作をリンク先の Django ガイダンスと比較し、Angular および React の SPA で実用的に CSRF を使用する方法を、トークンを注入または読み取れない場合にユーザーが何を想定すべきかも含めて文書化します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
angular, python, react
領域
documentation, security
issue の種類
ドキュメント
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。