Proteger le logout et aligner les flux CSRF d'authentification #9
Labels
No labels
area: auth
area: deps
area: frontend
area: gameplay
area: import
area: infra
area: product
area: tests
priority: P0
priority: P1
priority: P2
priority: P3
type: bug
type: chore
type: feature
type: infrastructure
type: performance
type: security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: thibaud-lclr/ltbxd-actorle#9
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
1. Le souci
Le logout est actuellement expose via un simple lien GET. Cela facilite les deconnexions forcees par un site tiers et rend le flux moins coherent que le reste des actions sensibles proteges par CSRF.
2. Proposition de solution
Passer le logout sur un POST protege par CSRF et harmoniser les conventions des flux auth sensibles.
3. Proposition d'implementation