What happens
`CSRFMiddleware` gives a fresh `enlace_csrf` cookie to every safe-method request (GET/HEAD/OPTIONS) that arrives without one, on any path (`enlace_auth/auth/middleware.py`, `_send_with_csrf_cookie`). That includes the pages and assets of `public` apps that have no forms and never talk to the auth endpoints.
Why it matters now
i2mint/enlace#55 adds privacy-first analytics to enlace for apps that must not set cookies, starting with a site used by children. Those pages promise that nothing is stored on the visitor's device. On a platform that also runs this plugin, the first page load still sets `enlace_csrf`, so the promise is broken by the platform and not by the app. Under the CNIL's rules a cookie is exempt from consent only when it is strictly necessary to a service the user asked for. A CSRF token on a public page with no state-changing request is hard to defend as necessary.
Direction (to decide, not decided)
Set the CSRF cookie only where a state-changing request can follow:
- on `/auth/*` (including `/auth/csrf`, which frontends already call);
- on the pages of `protected:*` apps and `/_admin`.
The double-submit check itself stays as it is. The token has to exist before any POST, so the design question is which flows currently rely on getting it from an arbitrary first GET. That needs checking before anything changes, because narrowing it could break a login form served from a public landing page.
Acceptance
- A `public` app's page served through a platform with this plugin sets no cookie. This can be checked with the headless-browser test pattern in enlace's `tests/test_analytics_browser.py`.
- Login, registration and admin flows keep working. The existing CSRF tests still pass, plus one test per flow that obtains its token first.
What happens
`CSRFMiddleware` gives a fresh `enlace_csrf` cookie to every safe-method request (GET/HEAD/OPTIONS) that arrives without one, on any path (`enlace_auth/auth/middleware.py`, `_send_with_csrf_cookie`). That includes the pages and assets of `public` apps that have no forms and never talk to the auth endpoints.
Why it matters now
i2mint/enlace#55 adds privacy-first analytics to enlace for apps that must not set cookies, starting with a site used by children. Those pages promise that nothing is stored on the visitor's device. On a platform that also runs this plugin, the first page load still sets `enlace_csrf`, so the promise is broken by the platform and not by the app. Under the CNIL's rules a cookie is exempt from consent only when it is strictly necessary to a service the user asked for. A CSRF token on a public page with no state-changing request is hard to defend as necessary.
Direction (to decide, not decided)
Set the CSRF cookie only where a state-changing request can follow:
The double-submit check itself stays as it is. The token has to exist before any POST, so the design question is which flows currently rely on getting it from an arbitrary first GET. That needs checking before anything changes, because narrowing it could break a login form served from a public landing page.
Acceptance