Skip to content

fix(security): default CSRF origin validation to block mode - #266

Merged
2witstudios merged 1 commit into
masterfrom
high-csrf-origin-validation-must-default-to-block-not-warn
Jan 27, 2026
Merged

2witstudios merged 1 commit into
masterfrom
high-csrf-origin-validation-must-default-to-block-not-warn

Conversation

@2witstudios

Copy link
Copy Markdown
Owner

Summary

  • Flipped default ORIGIN_VALIDATION_MODE from warn to block — misconfigured or missing config no longer silently degrades CSRF protection
  • Warn mode is now opt-in via explicit ORIGIN_VALIDATION_MODE=warn (for debugging only)
  • Bearer token requests unaffected — requests without an Origin header (curl, MCP, mobile apps) are still allowed through, as they are not browser-initiated CSRF vectors

Test plan

  • All 53 origin-validation tests pass with updated expectations
  • All 22 csrf-validation tests pass (unchanged)
  • All 37 auth-middleware tests pass (unchanged)
  • Verify production .env already has ORIGIN_VALIDATION_MODE=block (no-op change)
  • Verify dev environments explicitly set ORIGIN_VALIDATION_MODE=warn if needed

🤖 Generated with Claude Code

Origin validation previously defaulted to "warn" mode, silently allowing
requests from misconfigured or malicious origins. This is a configuration
vulnerability—missing ORIGIN_VALIDATION_MODE should not degrade security.

Now defaults to "block" in all environments. Warn mode is opt-in via
ORIGIN_VALIDATION_MODE=warn for debugging only.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@2witstudios

Copy link
Copy Markdown
Owner Author

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

Reviewed: logic changes in getOriginValidationMode(), test updates (53 origin-validation tests), documentation updates, and .env.example defaults. Verified against git history that the warn-to-block default change completes the phased security rollout originally planned in PR #151.

🤖 Generated with Claude Code

- If this code review was useful, please react with 👍. Otherwise, react with 👎.

@2witstudios
2witstudios merged commit aefe9a5 into master Jan 27, 2026
9 checks passed
@2witstudios
2witstudios deleted the high-csrf-origin-validation-must-default-to-block-not-warn branch January 29, 2026 02:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant