feat(security): HttpOnly cookies + CSP headers + CSRF double-submit protection

- Migrate auth tokens from localStorage to HttpOnly SameSite=Lax cookies
- Add cookie_auth.rs: helpers for setting/clearing auth + CSRF cookies
- Update auth middleware: 3-method auth (Bearer → Basic → Cookie)
- Add 5 security headers: CSP, X-Content-Type-Options, X-Frame-Options,
  Referrer-Policy, Permissions-Policy
- Implement CSRF double-submit cookie pattern (csrf.rs middleware)
- Set CSRF cookie on login/refresh/oidc-exchange, clear on logout
- CookieAuthenticated marker skips CSRF for Bearer/Basic clients
- Frontend: strip all localStorage token refs from 14 JS files
- Frontend: csrf.js utility + all 52 mutating fetch/XHR calls protected
- 121 tests passing, 0 warnings
This commit is contained in:
Dionisio
2026-03-03 01:10:50 +01:00
parent 7b2a8577a9
commit d2c08d31ba
27 changed files with 579 additions and 455 deletions
+1 -3
View File
@@ -1,8 +1,7 @@
const API = '/api';
const token = localStorage.getItem('oxicloud_token') || localStorage.getItem('token') || localStorage.getItem('access_token');
function headers() {
return { 'Authorization': 'Bearer ' + token, 'Content-Type': 'application/json' };
return { 'Content-Type': 'application/json', ...getCsrfHeaders() };
}
function formatBytes(bytes) {
@@ -25,7 +24,6 @@ function timeAgo(dateStr) {
}
async function init() {
if (!token) { showError(); return; }
try {
const resp = await fetch(API + '/auth/me', { headers: headers() });
if (!resp.ok) { showError(); return; }