This commit implements CSRF token support for all session-based API requests to fix the "CSRF token missing" and "CSRF token mismatch" errors introduced after CSRF protection was added in commit 62c4cc84. Changes: - Created csrfService.ts utility for fetching and caching CSRF tokens - Added getPostHeadersWithCsrf() helper to authUtils for async token injection - Updated all service files (*Service.ts) to include CSRF tokens in POST/PUT/PATCH/DELETE requests - Updated components with inline fetch calls to use getCsrfToken() - Fixed CSRF middleware to use single lusca instance instead of creating new instances per request - Improved generateToken() to use req.csrfToken() when available - Added CalDAV path exemption to CSRF protection Technical details: - CSRF tokens are fetched from /api/csrf-token endpoint - Tokens are cached and reused across requests to avoid unnecessary fetches - Tokens are included in x-csrf-token header for state-changing requests - Public endpoints (login, register) remain exempt from CSRF protection - Bearer token authentication remains exempt from CSRF protection Files modified: - Backend: app.js, middleware/csrf.js - Frontend: 13 service files, 8 component files - New file: frontend/utils/csrfService.ts This ensures all session-based requests properly include CSRF tokens while maintaining support for API token authentication.
37 lines
730 B
JavaScript
37 lines
730 B
JavaScript
const lusca = require('lusca');
|
|
|
|
const csrfMiddleware = lusca.csrf({
|
|
header: 'x-csrf-token',
|
|
cookie: false,
|
|
});
|
|
|
|
const csrfProtection = (req, res, next) => {
|
|
if (
|
|
process.env.NODE_ENV === 'test' ||
|
|
req.user ||
|
|
req.headers.authorization?.startsWith('Bearer ')
|
|
) {
|
|
return next();
|
|
}
|
|
|
|
return lusca.csrf({
|
|
header: 'x-csrf-token',
|
|
cookie: false,
|
|
})(req, res, next);
|
|
};
|
|
|
|
const generateToken = (req, res) => {
|
|
if (typeof req.csrfToken === 'function') {
|
|
return req.csrfToken();
|
|
}
|
|
if (res.locals._csrf) {
|
|
return res.locals._csrf;
|
|
}
|
|
return '';
|
|
};
|
|
|
|
module.exports = {
|
|
csrfProtection,
|
|
csrfMiddleware,
|
|
generateToken,
|
|
};
|