Skip to content

ASa#349

Open
prathamesh-aws wants to merge 6 commits intoOWASP:masterfrom
prathamesh-aws:master
Open

ASa#349
prathamesh-aws wants to merge 6 commits intoOWASP:masterfrom
prathamesh-aws:master

Conversation

@prathamesh-aws
Copy link
Copy Markdown

No description provided.

iampava pushed a commit to Initech-cantina/NodeGoat that referenced this pull request Mar 18, 2026
Uncomment csurf middleware and CSRF token generation in server.js.
This enforces server-side CSRF token validation on all state-changing
POST routes including /signup, /login, /profile, and /contributions.
The signup form already includes a _csrf hidden field that will now
be validated server-side.

Fixes: Signup CSRF enables attacker-controlled account creation + forced login
Alert: Clarion OWASP#349

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant