fix(audit-2026-06-11/C-1): drop cookie auth on /api/v1/admin/*
Same-origin CSRF: the platform co-hosts user-route HTML on the same origin as /api/v1/admin/*; SameSite=Lax did not block a same-origin POST from a malicious script at /<route>, riding the admin's picloud_session cookie. The dashboard already uses Bearer (dashboard/src/lib/auth.ts + api.ts:495), so cookie auth was dead weight on the admin side and exploitable. Cuts the cookie path entirely: - auth_middleware::extract_token is Bearer-only; cookie branch removed. - auth_api::login no longer sets Set-Cookie. - auth_api::logout no longer clears the cookie (the bearer token is still revoked by deleting the session row). - extract_token_for_logout matches. - SESSION_COOKIE const + PICLOUD_COOKIE_SECURE env var deleted. Audit ref: security_audit/07_http_cors_csrf_xss.md#c07-01. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -133,7 +133,7 @@ pub use auth_bootstrap::{
|
||||
#[allow(deprecated)]
|
||||
pub use auth_middleware::{
|
||||
attach_principal_if_present, require_admin, require_authenticated, AuthState, AuthedAdmin,
|
||||
API_KEY_PREFIX, API_KEY_PREFIX_LEN, SESSION_COOKIE,
|
||||
API_KEY_PREFIX, API_KEY_PREFIX_LEN,
|
||||
};
|
||||
pub use authz::{can, require, AuthzDenied, AuthzError, AuthzRepo, Capability, Decision};
|
||||
pub use cron_scheduler::spawn_cron_scheduler;
|
||||
|
||||
Reference in New Issue
Block a user