Skip to content

Fix CSRF vulnerability in session-based authentication - #53

Merged
szeka9 merged 3 commits into
mainfrom
development
Aug 30, 2026
Merged

szeka9 merged 3 commits into
mainfrom
development

Conversation

@szeka9

@szeka9 szeka9 commented Aug 30, 2026

Copy link
Copy Markdown
Owner

Require valid CSRF tokens for HTTP sessions. Currently,
CSRF tokens are only required for HTTP Basic Authentication.
However, session cookies are equally vulnerable to CSRF
attacks as they are sent automatically by the browser.

Add new regression tests to ensure that session cookies
can only authenticate when a valid CSRF token and cookie
is sent by the client.

szeka9 added 3 commits August 30, 2026 12:12
Require valid CSRF tokens for HTTP sessions. Currently,
CSRF tokens are only required for HTTP Basic Authentication.
However, session cookies are equally vulnerable to CSRF
attacks as they are sent automatically by the browser.

Add new regression tests to ensure that session cookies
can only authenticate when a valid CSRF token and cookie
is sent by the client.
Update load testing results related to authentication
and session management for the security fix
delivered in 7dde64e.
Include CSRF security fix and
documentation updates in the v0.9.0 release.
@szeka9
szeka9 merged commit 352e91c into main Aug 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant