fix: add missing csrf protection to metainfo saves - #6615
Merged
Conversation
The metainfo handlers stored posted metafields without validating a csrf token: - The sidebar on the content page posts `save=1&savemeta=1` without `function` and therefore bypassed the csrf check of the content page. This affected the article name as well as all article metafields. - The category and clang handlers saved on every POST to the structure resp. language page, no matter whether the csrf check of that page had passed. The sidebar is a form of metainfo itself, so it gets its own csrf token. Category and clang metafields are rendered into a form of another package, which already carries a csrf token of its own -- a second token field cannot be added there, as both would use the same request param and overwrite each other. Instead those metafields are now only saved via the `CAT_ADDED`/`CAT_UPDATED` resp. `CLANG_ADDED`/`CLANG_UPDATED` extension points, which are only reached through the csrf protected save of the category resp. clang itself. The media handler already worked that way.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The metainfo handlers stored posted metafields without validating a csrf token.
functionand therefore bypassed the csrf check of the content page. This affected the article name as well as all article metafields.The sidebar is a form of metainfo itself, so it gets its own csrf token. Category and clang metafields are rendered into a form of another package, which already carries a csrf token of its own — a second token field cannot be added there, as both would use the same request param and overwrite each other. Instead those metafields are now only saved via the
CAT_ADDED/CAT_UPDATEDresp.CLANG_ADDED/CLANG_UPDATEDextension points, which are only reached through the csrf protected save of the category resp. clang itself. The media handler already worked that way.Manually tested in the backend: saving article name/metafields via the sidebar, category metafields on add and edit, clang metafields on add and edit.