Skip to content

Protect topic attribute actions from CSRF - #4

Merged
kaileymsnay merged 1 commit into
kaileymsnay:masterfrom
StudioMaX:fix/csrf-attribute-actions
Aug 29, 2026
Merged

kaileymsnay merged 1 commit into
kaileymsnay:masterfrom
StudioMaX:fix/csrf-attribute-actions

Conversation

@StudioMaX

@StudioMaX StudioMaX commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • keep the original one-click AJAX attribute links and protect them with phpBB link hashes
  • require POST and a form key for MCP bulk attribute changes
  • add a regression test that verifies a forged GET without a valid hash is ignored

Reproduction

An authorised topic author could change an attribute by visiting viewtopic.php?t=62&attr_id=1; no form key, link hash, or confirmation was required. A page on another origin successfully top-level-navigated an authenticated browser to that URL and changed the topic attribute.

Verification

  • PHP and JavaScript syntax checks passed
  • a forged GET with an invalid hash left the topic unchanged
  • the rendered hashed link retained the original anchor markup and data-ajax callback
  • the generated hashed AJAX GET returned the normal QTE JSON response and changed the attribute
  • MCP attribute changes remain protected POST submissions

@StudioMaX StudioMaX closed this Aug 28, 2026
@StudioMaX StudioMaX reopened this Aug 28, 2026
@StudioMaX
StudioMaX marked this pull request as draft August 28, 2026 20:42
@StudioMaX
StudioMaX force-pushed the fix/csrf-attribute-actions branch from 497a0ea to 1890ca6 Compare August 29, 2026 08:06
@StudioMaX
StudioMaX marked this pull request as ready for review August 29, 2026 08:09
@kaileymsnay

Copy link
Copy Markdown
Owner

Thank you for the contribution.

A note on tests - this extension doesn't fully implement functional tests, so the one included in you pull request would never run (see https://github.com/kaileymsnay/qte/blob/master/.github/workflows/tests.yml#L53-L66). This is something I never utilized, but looking to at some point.

@kaileymsnay
kaileymsnay merged commit 24eebdd into kaileymsnay:master Aug 29, 2026
1 check passed
@StudioMaX
StudioMaX deleted the fix/csrf-attribute-actions branch August 30, 2026 09:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants