Add CSRF protection to API v1 routes by requiring X-Requested-With header on all state-changing requests (POST, PUT, DELETE). Browsers will not send custom headers in cross-origin simple requests, blocking CSRF attacks.
Add APICSRFProtection() middleware requiring X-Requested-With header on non-GET/HEAD/OPTIONS requests
Apply middleware to /api/v1 route group
Add X-Requested-With to CORS allowed headers
Add unit tests (csrf_test.go) and integration tests
Update existing API tests to include the required header
## Summary
Add CSRF protection to API v1 routes by requiring `X-Requested-With` header on all state-changing requests (POST, PUT, DELETE). Browsers will not send custom headers in cross-origin simple requests, blocking CSRF attacks.
Closes #112
## Changes
- Add `APICSRFProtection()` middleware requiring `X-Requested-With` header on non-GET/HEAD/OPTIONS requests
- Apply middleware to `/api/v1` route group
- Add `X-Requested-With` to CORS allowed headers
- Add unit tests (`csrf_test.go`) and integration tests
- Update existing API tests to include the required header
sneak
was assigned by clawbot2026-02-20 14:34:35 +01:00
Add APICSRFProtection middleware that requires X-Requested-With header
on all state-changing (non-GET/HEAD/OPTIONS) API requests. This prevents
CSRF attacks since browsers won't send custom headers in cross-origin
simple requests (form posts, navigations).
Changes:
- Add APICSRFProtection() middleware in internal/middleware/middleware.go
- Apply middleware to /api/v1 route group in routes.go
- Add X-Requested-With to CORS allowed headers
- Add unit tests for the middleware (csrf_test.go)
- Add integration tests for CSRF rejection/allowance (api_test.go)
- Update existing API tests to include the required header
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Add CSRF protection to API v1 routes by requiring
X-Requested-Withheader on all state-changing requests (POST, PUT, DELETE). Browsers will not send custom headers in cross-origin simple requests, blocking CSRF attacks.Closes #112
Changes
APICSRFProtection()middleware requiringX-Requested-Withheader on non-GET/HEAD/OPTIONS requests/api/v1route groupX-Requested-Withto CORS allowed headerscsrf_test.go) and integration testsmake checkoutputPull request closed