Skip to content

fix: add missing csrf protection to metainfo saves - #6615

Merged
gharlan merged 1 commit into
5.xfrom
metainfo-csrf
Aug 3, 2026
Merged

fix: add missing csrf protection to metainfo saves#6615
gharlan merged 1 commit into
5.xfrom
metainfo-csrf

Conversation

@gharlan

@gharlan gharlan commented Aug 3, 2026

Copy link
Copy Markdown
Member

The metainfo handlers stored posted metafields without validating a csrf token.

  • The sidebar on the content page posts without function and therefore bypassed the csrf check of the content page. This affected the article name as well as all article metafields.
  • The category and clang handlers saved on every POST to the structure resp. language page, no matter whether the csrf check of that page had passed.

The sidebar is a form of metainfo itself, so it gets its own csrf token. Category and clang metafields are rendered into a form of another package, which already carries a csrf token of its own — a second token field cannot be added there, as both would use the same request param and overwrite each other. Instead those metafields are now only saved via the CAT_ADDED/CAT_UPDATED resp. CLANG_ADDED/CLANG_UPDATED extension points, which are only reached through the csrf protected save of the category resp. clang itself. The media handler already worked that way.

Manually tested in the backend: saving article name/metafields via the sidebar, category metafields on add and edit, clang metafields on add and edit.

The metainfo handlers stored posted metafields without validating a csrf token:

- The sidebar on the content page posts `save=1&savemeta=1` without `function`
  and therefore bypassed the csrf check of the content page. This affected the
  article name as well as all article metafields.
- The category and clang handlers saved on every POST to the structure resp.
  language page, no matter whether the csrf check of that page had passed.

The sidebar is a form of metainfo itself, so it gets its own csrf token.
Category and clang metafields are rendered into a form of another package,
which already carries a csrf token of its own -- a second token field cannot be
added there, as both would use the same request param and overwrite each other.
Instead those metafields are now only saved via the `CAT_ADDED`/`CAT_UPDATED`
resp. `CLANG_ADDED`/`CLANG_UPDATED` extension points, which are only reached
through the csrf protected save of the category resp. clang itself. The media
handler already worked that way.
@rex-bot rex-bot added the bug label Aug 3, 2026
@gharlan gharlan added this to the REDAXO 5.21.4 milestone Aug 3, 2026
@gharlan
gharlan merged commit 52e4f99 into 5.x Aug 3, 2026
18 checks passed
@gharlan
gharlan deleted the metainfo-csrf branch August 3, 2026 13:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

2 participants