tududi/backend/middleware/csrf.js
Chris 6c9902b584
fix: add CSRF token support to frontend requests (#1025)
This commit implements CSRF token support for all session-based API
requests to fix the "CSRF token missing" and "CSRF token mismatch" errors
introduced after CSRF protection was added in commit 62c4cc84.

Changes:
- Created csrfService.ts utility for fetching and caching CSRF tokens
- Added getPostHeadersWithCsrf() helper to authUtils for async token injection
- Updated all service files (*Service.ts) to include CSRF tokens in POST/PUT/PATCH/DELETE requests
- Updated components with inline fetch calls to use getCsrfToken()
- Fixed CSRF middleware to use single lusca instance instead of creating new instances per request
- Improved generateToken() to use req.csrfToken() when available
- Added CalDAV path exemption to CSRF protection

Technical details:
- CSRF tokens are fetched from /api/csrf-token endpoint
- Tokens are cached and reused across requests to avoid unnecessary fetches
- Tokens are included in x-csrf-token header for state-changing requests
- Public endpoints (login, register) remain exempt from CSRF protection
- Bearer token authentication remains exempt from CSRF protection

Files modified:
- Backend: app.js, middleware/csrf.js
- Frontend: 13 service files, 8 component files
- New file: frontend/utils/csrfService.ts

This ensures all session-based requests properly include CSRF tokens while
maintaining support for API token authentication.
2026-04-14 15:06:56 +03:00

37 lines
730 B
JavaScript

const lusca = require('lusca');
const csrfMiddleware = lusca.csrf({
header: 'x-csrf-token',
cookie: false,
});
const csrfProtection = (req, res, next) => {
if (
process.env.NODE_ENV === 'test' ||
req.user ||
req.headers.authorization?.startsWith('Bearer ')
) {
return next();
}
return lusca.csrf({
header: 'x-csrf-token',
cookie: false,
})(req, res, next);
};
const generateToken = (req, res) => {
if (typeof req.csrfToken === 'function') {
return req.csrfToken();
}
if (res.locals._csrf) {
return res.locals._csrf;
}
return '';
};
module.exports = {
csrfProtection,
csrfMiddleware,
generateToken,
};