None of the 12+ POST forms have CSRF tokens. An attacker can craft a page that submits forms on behalf of an authenticated user.
Suggested fix: Add CSRF middleware (e.g. gorilla/csrf or custom token-in-form approach). All state-changing POST handlers need token verification.
## From Security Audit ([#33 comment](https://git.eeqj.de/sneak/webhooker/issues/33#issuecomment-10915))
**Severity: BLOCKER**
None of the 12+ POST forms have CSRF tokens. An attacker can craft a page that submits forms on behalf of an authenticated user.
**Suggested fix:** Add CSRF middleware (e.g. `gorilla/csrf` or custom token-in-form approach). All state-changing POST handlers need token verification.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
From Security Audit (#33 comment)
Severity: BLOCKER
None of the 12+ POST forms have CSRF tokens. An attacker can craft a page that submits forms on behalf of an authenticated user.
Suggested fix: Add CSRF middleware (e.g.
gorilla/csrfor custom token-in-form approach). All state-changing POST handlers need token verification.