RTL/server/utils/csrf.ts

46 lines
2.1 KiB
TypeScript
Raw Normal View History

Replace deprecated csurf with csrf-csrf csurf has been deprecated since 2022 and pins an old cookie release with a known advisory; npm's only fix is a downgrade (issue #1634, item 2). csrf-csrf v4 implements the same double-submit-cookie pattern with an HMAC-signed, session-bound token keyed on the existing boot secret (common.secret_key). The frontend contract is unchanged: the token still arrives via the XSRF-TOKEN cookie/header and is echoed as x-xsrf-token (all token sources csurf accepted are still read), the signed cookie keeps the _csrf name (now httpOnly, secure:false to match the session cookie on plain-HTTP deployments), doubleCsrfProtection attaches req.csrfToken so app.ts keeps working, and the error code is EBADCSRFTOKEN - already handled in app.ts. The websocket upgrade check in authCheck.ts now routes through the shared middleware; upgrade requests are GETs, so its pass-through semantics are unchanged. One fix this surfaced: app.ts called req.csrfToken() twice (cookie and header). Under csurf every token validated against a stable secret; under csrf-csrf each first-visit call mints a new token, desyncing the XSRF-TOKEN cookie from the _csrf cookie it must equal. The token is now generated once per request. Tokens are session-bound, so a token stolen from one session no longer validates in another - a check csurf's cookie mode did not perform. Production npm audit drops from 6 low findings to 4, all in the crypto-browserify/elliptic chain tracked in #1634. Verified against the docker regtest fixture: both API suites (43 checks across LND, CLN and Eclair) plus a dedicated CSRF battery - valid-token auth, missing token 403, garbage token 403, cross-session replay 403, token stability across requests, the XSRF-TOKEN response header for Quickpay, and the websocket handshake. Lint and build are clean.
2026-07-19 17:03:53 -07:00
import { doubleCsrf } from 'csrf-csrf';
2021-12-29 18:08:41 -05:00
import { Application } from 'express';
import { Logger, LoggerService } from './logger.js';
import { Common, CommonService } from './common.js';
2021-12-29 18:08:41 -05:00
class CSRF {
public logger: LoggerService = Logger;
public common: CommonService = Common;
2021-12-29 18:08:41 -05:00
Replace deprecated csurf with csrf-csrf csurf has been deprecated since 2022 and pins an old cookie release with a known advisory; npm's only fix is a downgrade (issue #1634, item 2). csrf-csrf v4 implements the same double-submit-cookie pattern with an HMAC-signed, session-bound token keyed on the existing boot secret (common.secret_key). The frontend contract is unchanged: the token still arrives via the XSRF-TOKEN cookie/header and is echoed as x-xsrf-token (all token sources csurf accepted are still read), the signed cookie keeps the _csrf name (now httpOnly, secure:false to match the session cookie on plain-HTTP deployments), doubleCsrfProtection attaches req.csrfToken so app.ts keeps working, and the error code is EBADCSRFTOKEN - already handled in app.ts. The websocket upgrade check in authCheck.ts now routes through the shared middleware; upgrade requests are GETs, so its pass-through semantics are unchanged. One fix this surfaced: app.ts called req.csrfToken() twice (cookie and header). Under csurf every token validated against a stable secret; under csrf-csrf each first-visit call mints a new token, desyncing the XSRF-TOKEN cookie from the _csrf cookie it must equal. The token is now generated once per request. Tokens are session-bound, so a token stolen from one session no longer validates in another - a check csurf's cookie mode did not perform. Production npm audit drops from 6 low findings to 4, all in the crypto-browserify/elliptic chain tracked in #1634. Verified against the docker regtest fixture: both API suites (43 checks across LND, CLN and Eclair) plus a dedicated CSRF battery - valid-token auth, missing token 403, garbage token 403, cross-session replay 403, token stability across requests, the XSRF-TOKEN response header for Quickpay, and the websocket handshake. Lint and build are clean.
2026-07-19 17:03:53 -07:00
// Signed double-submit-cookie protection (replaces the deprecated csurf).
// The signed token lives in the httpOnly '_csrf' cookie; the client echoes
// the same token (read from the XSRF-TOKEN cookie set in app.ts) in a
// header. The cookie is not secure-only because RTL commonly serves plain
// HTTP (matching the session cookie); token sources match what csurf
// accepted. The error code EBADCSRFTOKEN is handled in app.ts.
private doubleCsrfUtilities = doubleCsrf({
getSecret: () => this.common.secret_key,
getSessionIdentifier: (req: any) => (req.session ? req.session.id : ''),
cookieName: '_csrf',
cookieOptions: { sameSite: 'strict', path: '/', secure: false, httpOnly: true },
getCsrfTokenFromRequest: (req: any) => (req.body && req.body._csrf) || (req.query && req.query._csrf) ||
req.headers['csrf-token'] || req.headers['xsrf-token'] ||
req.headers['x-csrf-token'] || req.headers['x-xsrf-token']
});
public csrfProtection = this.doubleCsrfUtilities.doubleCsrfProtection;
Address review: fix logout -> re-login under session-bound CSRF tokens Session-bound tokens broke re-login after logout: logoutUser destroys the session, but the SPA navigated to the login page without a document reload, so the surviving _csrf/XSRF-TOKEN cookies stayed bound to the destroyed session id and the next login POST failed with 403 until a manual refresh. Hit both manual logout and the idle-timer auto-logout. Two coordinated fixes: 1. Frontend: the logout effect now performs a full document navigation to the login page (after the server logout completes, so the request is not aborted by the reload), which re-runs the handshake and mints a token bound to the fresh session. The logout reason previously travelled on the NgRx action stream, which cannot survive a reload - it is now handed over via sessionStorage (set after clearAll) and picked up and cleared by the login component. The SSO branch is unchanged (it already left the document). 2. Backend: the EBADCSRFTOKEN error path now re-mints the token for the current session before responding 403, so any client holding a stale token (e.g. after a server restart rotates the boot secret) self-heals on retry instead of looping on 403. Verified on the fixture: reviewer's repro now shows login 200 -> logout 200 -> stale-token login 403 (binding intact) with re-minted cookies on the 403 -> retry 200; and the reload path (fresh GET / after logout, what the full navigation does) logs in on the first attempt. Both API suites, the CSRF battery, rtl.effects specs and the full frontend suite pass; frontend and backend artifacts rebuilt.
2026-07-19 17:41:25 -07:00
// Force-mints a fresh token for the current session, discarding any token
// cookie bound to a previous session or boot secret (used by the
// EBADCSRFTOKEN error path in app.ts so a client retry succeeds).
public reMintToken = (req, res) => this.doubleCsrfUtilities.generateCsrfToken(req, res, { overwrite: true });
2021-12-29 18:08:41 -05:00
public mount(app: Application): Application {
Release 0.15.1 (#1406) * rm .DS_Store * Add watchfrontenddev command for npm * Fix toggle issues in sidenav (pinning and on page refresh) * Add copy-to-clipboard fallback if navigator.clipboard is not available (#1336) * add copy-to-clipboard fallback if navigator.clipboard is not available * amend copy fallback * clipboard copy lint fixes and frontend build * fix: add missing boltz state `transaction.lockupFailed` (#1349) * fix: boltzd docs link (#1354) * exit gracefully (#1356) * allow for eclair updated relayed audit format (#1363) * feat: add boltz service to cln (#1352) * lint fix * Request Params Cleanup * cln: Boltz auto-send (#1366) * Bug-fix (CLN Boltz): Hide claim tx id and routing fee for non-zero conf reverse swap * cln: Boltz auto-send - Added auto send option for Swap In - Checking compatiblity with v2.0.0 and above * Test import fixes * Update help.component.ts (#1379) Fixed broken link under "Help" -> "Node Settings" * Backend config fix (#1382) * Updating Common Application Configuration * Fixed get RTL Conf * Update Application Settings * application and settings case change * Unified config models * Default node update * 2FA and Password reset * Final application settings update * Config Settings and Authentication case fixed * Node Setting Fix * Fiat currency Symbol fix * CLN: Fiat symbol fix * All: Fiat symbol fix * Update node settings * Services UI fix * CLN: Removed child node settings * All: Removed child node settings * Test fixes * mempool links for onchain information (#1383) * Tests fix Tests fix * UI for Block Explorer Configuration (#1385) * Bump fee with mempool information (#1386) * Mempool openchannel minfee (#1388) Open channel model block if min fee is higher * Show error on login screen if rune is incorrect and getinfo throws error (#1391) * cln: Removed channel lookup call for update policy (#1392) * ECL: On-chain Transactions, Invoice and Payments pagination (#1393) Done most of the UI changes to accommodate pagination on transactions, payments and invoices tables but true pagination cannot be implemented till total number of records are missing from the API response. Once the issue https://github.com/ACINQ/eclair/issues/2855 is fixed, I will uncomment pagination changes in the frontend. * lnd: Onchain CPFP (#1394) - UTXO label bug fix - Warning on utxo label for "sweep" in text. * Bug fixes after testing * Testing bug fixes (#1401) * Bug fix 2: lnd: Link channel point to explorer and show fee on close channel too * lnd: explorer link on pending channels * Node lookup link on view channel peer pubkey * Testing bug fixes (#1402) * Bug fix 2: lnd: Link channel point to explorer and show fee on close channel too * lnd: explorer link on pending channels * Node lookup link on view channel peer pubkey * test fixes * ng update to v18.0.x * Updating install with --legacy-peer-deps --------- Co-authored-by: Grzegorz Kućmierz <gkucmierz@gmail.com> Co-authored-by: lacksfish <lacksfish@gmail.com> Co-authored-by: jackstar12 <62219658+jackstar12@users.noreply.github.com> Co-authored-by: Kilian <19181985+kilrau@users.noreply.github.com> Co-authored-by: Taylor King <taylorbradleyking@gmail.com> Co-authored-by: Fishcake <128653975+fishcakeday@users.noreply.github.com> Co-authored-by: Ant <72945059+2140data@users.noreply.github.com>
2024-06-10 12:40:37 -07:00
this.logger.log({ selectedNode: this.common.selectedNode, level: 'INFO', fileName: 'CSRF', msg: 'Setting up CSRF..' });
2021-12-29 18:08:41 -05:00
if (process.env.NODE_ENV !== 'development') {
app.use((req, res, next) => this.csrfProtection(req, res, next));
}
Release 0.15.1 (#1406) * rm .DS_Store * Add watchfrontenddev command for npm * Fix toggle issues in sidenav (pinning and on page refresh) * Add copy-to-clipboard fallback if navigator.clipboard is not available (#1336) * add copy-to-clipboard fallback if navigator.clipboard is not available * amend copy fallback * clipboard copy lint fixes and frontend build * fix: add missing boltz state `transaction.lockupFailed` (#1349) * fix: boltzd docs link (#1354) * exit gracefully (#1356) * allow for eclair updated relayed audit format (#1363) * feat: add boltz service to cln (#1352) * lint fix * Request Params Cleanup * cln: Boltz auto-send (#1366) * Bug-fix (CLN Boltz): Hide claim tx id and routing fee for non-zero conf reverse swap * cln: Boltz auto-send - Added auto send option for Swap In - Checking compatiblity with v2.0.0 and above * Test import fixes * Update help.component.ts (#1379) Fixed broken link under "Help" -> "Node Settings" * Backend config fix (#1382) * Updating Common Application Configuration * Fixed get RTL Conf * Update Application Settings * application and settings case change * Unified config models * Default node update * 2FA and Password reset * Final application settings update * Config Settings and Authentication case fixed * Node Setting Fix * Fiat currency Symbol fix * CLN: Fiat symbol fix * All: Fiat symbol fix * Update node settings * Services UI fix * CLN: Removed child node settings * All: Removed child node settings * Test fixes * mempool links for onchain information (#1383) * Tests fix Tests fix * UI for Block Explorer Configuration (#1385) * Bump fee with mempool information (#1386) * Mempool openchannel minfee (#1388) Open channel model block if min fee is higher * Show error on login screen if rune is incorrect and getinfo throws error (#1391) * cln: Removed channel lookup call for update policy (#1392) * ECL: On-chain Transactions, Invoice and Payments pagination (#1393) Done most of the UI changes to accommodate pagination on transactions, payments and invoices tables but true pagination cannot be implemented till total number of records are missing from the API response. Once the issue https://github.com/ACINQ/eclair/issues/2855 is fixed, I will uncomment pagination changes in the frontend. * lnd: Onchain CPFP (#1394) - UTXO label bug fix - Warning on utxo label for "sweep" in text. * Bug fixes after testing * Testing bug fixes (#1401) * Bug fix 2: lnd: Link channel point to explorer and show fee on close channel too * lnd: explorer link on pending channels * Node lookup link on view channel peer pubkey * Testing bug fixes (#1402) * Bug fix 2: lnd: Link channel point to explorer and show fee on close channel too * lnd: explorer link on pending channels * Node lookup link on view channel peer pubkey * test fixes * ng update to v18.0.x * Updating install with --legacy-peer-deps --------- Co-authored-by: Grzegorz Kućmierz <gkucmierz@gmail.com> Co-authored-by: lacksfish <lacksfish@gmail.com> Co-authored-by: jackstar12 <62219658+jackstar12@users.noreply.github.com> Co-authored-by: Kilian <19181985+kilrau@users.noreply.github.com> Co-authored-by: Taylor King <taylorbradleyking@gmail.com> Co-authored-by: Fishcake <128653975+fishcakeday@users.noreply.github.com> Co-authored-by: Ant <72945059+2140data@users.noreply.github.com>
2024-06-10 12:40:37 -07:00
this.logger.log({ selectedNode: this.common.selectedNode, level: 'INFO', fileName: 'CSRF', msg: 'CSRF Set' });
2021-12-29 18:08:41 -05:00
return app;
};
}
export default new CSRF;