Rework CSRF: deterministic token from session + self-healing cookie (no more stale 403s)

This commit is contained in:
Kühn
2026-08-31 11:26:00 +02:00
parent a05133f39d
commit ec2ed91621
3 changed files with 57 additions and 15 deletions

View File

@@ -5,22 +5,22 @@ export const FILE_BASE = import.meta.env.VITE_API_BASE
? import.meta.env.VITE_API_BASE.replace(/\/api$/, '')
: '';
// P5: CSRF token kept in memory only (not localStorage - not sensitive, but avoids stale tokens)
let csrfToken = null;
// Helper: Read CSRF token from cookie (fallback after page reload)
// P5: CSRF token — the server derives it deterministically from the session and
// self-heals the cookie on every GET. The frontend simply reads the cookie fresh
// on every request, so memory/cookie can never drift apart (no more 403s).
function getCSRFTokenFromCookie() {
const match = document.cookie.match(/workflow_csrf=([^;]+)/);
return match ? match[1] : null;
}
export function setCSRFToken(token) {
csrfToken = token;
// Kept for API compatibility; the cookie is the single source of truth now.
// No-op: token is always read fresh from the cookie.
}
export function getCSRFToken() {
// Return memory token, or fallback to cookie (after page reload)
return csrfToken || getCSRFTokenFromCookie();
// Always read fresh from the cookie (server keeps it in sync on every GET)
return getCSRFTokenFromCookie();
}
// P5: Auth relies on HttpOnly cookie only - no token in localStorage