All state-changing POST routes (app create/delete/deploy, env var add/delete, etc.) lack CSRF token validation. The CORS middleware allows X-CSRF-Token header but no middleware generates or validates tokens.
Impact
An attacker could craft a malicious page that submits forms to the upaas instance while the victim is logged in, performing actions like deleting apps or triggering deployments.
Fix
Add gorilla/csrf middleware to the protected route group. Pass CSRF token to templates via template data. Include hidden CSRF field in all forms.
Location
internal/server/routes.go — protected route group internal/middleware/middleware.go — add CSRF middleware
## Summary
All state-changing POST routes (app create/delete/deploy, env var add/delete, etc.) lack CSRF token validation. The CORS middleware allows `X-CSRF-Token` header but no middleware generates or validates tokens.
## Impact
An attacker could craft a malicious page that submits forms to the upaas instance while the victim is logged in, performing actions like deleting apps or triggering deployments.
## Fix
Add `gorilla/csrf` middleware to the protected route group. Pass CSRF token to templates via template data. Include hidden CSRF field in all forms.
## Location
`internal/server/routes.go` — protected route group
`internal/middleware/middleware.go` — add CSRF middleware
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
All state-changing POST routes (app create/delete/deploy, env var add/delete, etc.) lack CSRF token validation. The CORS middleware allows
X-CSRF-Tokenheader but no middleware generates or validates tokens.Impact
An attacker could craft a malicious page that submits forms to the upaas instance while the victim is logged in, performing actions like deleting apps or triggering deployments.
Fix
Add
gorilla/csrfmiddleware to the protected route group. Pass CSRF token to templates via template data. Include hidden CSRF field in all forms.Location
internal/server/routes.go— protected route groupinternal/middleware/middleware.go— add CSRF middleware