mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-06 15:25:08 +00:00
fix(web): don't echo the refused Origin/Referer back in the 403 body
The claimed origin is attacker-chosen, so the refusal reason in the response names only which header failed; the values are logged instead. Clears Codacy's directly-returned-format-string finding. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -51,7 +51,9 @@ def test_a_cross_site_origin_is_refused_for_every_changing_method(probe, method)
|
||||
body = resp.get_json()
|
||||
assert body['status'] == 'error'
|
||||
assert body['error_code'] == 'CROSS_SITE_REQUEST'
|
||||
assert 'evil.example' in body['details']
|
||||
assert body['details'].startswith('Origin ')
|
||||
# The attacker-chosen origin is logged, never echoed back in the body.
|
||||
assert 'evil.example' not in resp.get_data(as_text=True)
|
||||
|
||||
|
||||
@pytest.mark.parametrize('origin', [
|
||||
|
||||
@@ -116,7 +116,9 @@ def check_request_origin():
|
||||
if claimed is None:
|
||||
return f'{header} header is not a valid http(s) URL'
|
||||
if claimed != _request_host_port():
|
||||
return f'{header} {value!r} is not this interface ({request.host!r})'
|
||||
# The claimed value is attacker-chosen: the hook logs it, but the
|
||||
# reason (echoed in the 403 body) never repeats it.
|
||||
return header + ' names a different host than this interface'
|
||||
return None
|
||||
|
||||
|
||||
@@ -128,8 +130,10 @@ def init_app(app: Flask) -> None:
|
||||
reason = check_request_origin()
|
||||
if reason is None:
|
||||
return None
|
||||
logger.warning("Refused cross-site %s %s: %s",
|
||||
request.method, request.path, reason)
|
||||
logger.warning("Refused cross-site %s %s: %s (Origin=%r, Referer=%r)",
|
||||
request.method, request.path, reason,
|
||||
request.headers.get('Origin'),
|
||||
request.headers.get('Referer'))
|
||||
return jsonify({
|
||||
'status': 'error',
|
||||
'error_code': 'CROSS_SITE_REQUEST',
|
||||
|
||||
Reference in New Issue
Block a user