mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-06 15:25:08 +00:00
fix(web): don't echo the refused Origin/Referer back in the 403 body
The claimed origin is attacker-chosen, so the refusal reason in the response names only which header failed; the values are logged instead. Clears Codacy's directly-returned-format-string finding. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -51,7 +51,9 @@ def test_a_cross_site_origin_is_refused_for_every_changing_method(probe, method)
|
|||||||
body = resp.get_json()
|
body = resp.get_json()
|
||||||
assert body['status'] == 'error'
|
assert body['status'] == 'error'
|
||||||
assert body['error_code'] == 'CROSS_SITE_REQUEST'
|
assert body['error_code'] == 'CROSS_SITE_REQUEST'
|
||||||
assert 'evil.example' in body['details']
|
assert body['details'].startswith('Origin ')
|
||||||
|
# The attacker-chosen origin is logged, never echoed back in the body.
|
||||||
|
assert 'evil.example' not in resp.get_data(as_text=True)
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.parametrize('origin', [
|
@pytest.mark.parametrize('origin', [
|
||||||
|
|||||||
@@ -116,7 +116,9 @@ def check_request_origin():
|
|||||||
if claimed is None:
|
if claimed is None:
|
||||||
return f'{header} header is not a valid http(s) URL'
|
return f'{header} header is not a valid http(s) URL'
|
||||||
if claimed != _request_host_port():
|
if claimed != _request_host_port():
|
||||||
return f'{header} {value!r} is not this interface ({request.host!r})'
|
# The claimed value is attacker-chosen: the hook logs it, but the
|
||||||
|
# reason (echoed in the 403 body) never repeats it.
|
||||||
|
return header + ' names a different host than this interface'
|
||||||
return None
|
return None
|
||||||
|
|
||||||
|
|
||||||
@@ -128,8 +130,10 @@ def init_app(app: Flask) -> None:
|
|||||||
reason = check_request_origin()
|
reason = check_request_origin()
|
||||||
if reason is None:
|
if reason is None:
|
||||||
return None
|
return None
|
||||||
logger.warning("Refused cross-site %s %s: %s",
|
logger.warning("Refused cross-site %s %s: %s (Origin=%r, Referer=%r)",
|
||||||
request.method, request.path, reason)
|
request.method, request.path, reason,
|
||||||
|
request.headers.get('Origin'),
|
||||||
|
request.headers.get('Referer'))
|
||||||
return jsonify({
|
return jsonify({
|
||||||
'status': 'error',
|
'status': 'error',
|
||||||
'error_code': 'CROSS_SITE_REQUEST',
|
'error_code': 'CROSS_SITE_REQUEST',
|
||||||
|
|||||||
Reference in New Issue
Block a user