Remove POST /apps, DELETE /apps/{id}, and POST /apps/{id}/deploy from
the API v1 route group. These endpoints used cookie-based session auth
without CSRF protection, creating a CSRF vulnerability.
Read-only endpoints (GET /apps, GET /apps/{id}, GET /apps/{id}/deployments),
login, and whoami are retained.
Removed handlers: HandleAPICreateApp, HandleAPIDeleteApp,
HandleAPITriggerDeploy, along with apiCreateRequest struct and
validateCreateRequest function.
Updated tests to use service layer directly for app creation in
remaining read-only endpoint tests.
clawbot
requested review from sneak 2026-02-20 14:33:24 +01:00
sneak
was assigned by clawbot2026-02-20 14:33:25 +01:00
sneak
merged commit ab526fc93d into main2026-02-20 14:35:13 +01:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Remove API v1 write methods (POST /apps, DELETE /apps/{id}, POST /apps/{id}/deploy) that used cookie-based session auth without CSRF protection.
Read-only endpoints, login, and whoami are retained.
Closes #112
make check output
Remove POST /apps, DELETE /apps/{id}, and POST /apps/{id}/deploy from the API v1 route group. These endpoints used cookie-based session auth without CSRF protection, creating a CSRF vulnerability. Read-only endpoints (GET /apps, GET /apps/{id}, GET /apps/{id}/deployments), login, and whoami are retained. Removed handlers: HandleAPICreateApp, HandleAPIDeleteApp, HandleAPITriggerDeploy, along with apiCreateRequest struct and validateCreateRequest function. Updated tests to use service layer directly for app creation in remaining read-only endpoint tests.Code Review: PR #115 — Disable API v1 Write Methods
Result: ✅ LGTM — Ready for merge
Checklist
POST /apps,DELETE /apps/{id},POST /apps/{id}/deployHandleAPICreateApp,HandleAPIDeleteApp,HandleAPITriggerDeploy,validateCreateRequest,apiCreateRequestinternal/server/routes.gocontext,appservice in api.go)apiRequesthelper narrowed toapiGet— clean simplificationmake checkpasses cleanly (all tests pass, build succeeds, lint clean)Clean, focused removal of CSRF-vulnerable write endpoints. No regressions.