Skip to content

CSRF cookie is set on every GET, including public pages that promise no cookies #31

Description

@thorwhalen

What happens

`CSRFMiddleware` gives a fresh `enlace_csrf` cookie to every safe-method request (GET/HEAD/OPTIONS) that arrives without one, on any path (`enlace_auth/auth/middleware.py`, `_send_with_csrf_cookie`). That includes the pages and assets of `public` apps that have no forms and never talk to the auth endpoints.

Why it matters now

i2mint/enlace#55 adds privacy-first analytics to enlace for apps that must not set cookies, starting with a site used by children. Those pages promise that nothing is stored on the visitor's device. On a platform that also runs this plugin, the first page load still sets `enlace_csrf`, so the promise is broken by the platform and not by the app. Under the CNIL's rules a cookie is exempt from consent only when it is strictly necessary to a service the user asked for. A CSRF token on a public page with no state-changing request is hard to defend as necessary.

Direction (to decide, not decided)

Set the CSRF cookie only where a state-changing request can follow:

  • on `/auth/*` (including `/auth/csrf`, which frontends already call);
  • on the pages of `protected:*` apps and `/_admin`.

The double-submit check itself stays as it is. The token has to exist before any POST, so the design question is which flows currently rely on getting it from an arbitrary first GET. That needs checking before anything changes, because narrowing it could break a login form served from a public landing page.

Acceptance

  • A `public` app's page served through a platform with this plugin sets no cookie. This can be checked with the headless-browser test pattern in enlace's `tests/test_analytics_browser.py`.
  • Login, registration and admin flows keep working. The existing CSRF tests still pass, plus one test per flow that obtains its token first.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions