fix(security): verify transfer-token HMAC and sign CSRF double-submit cookie

- consumeTransferToken now recomputes and constant-time compares the
  entry's HMAC-SHA256; previously the signature was minted but never
  checked, so the documented "防篡改" guarantee was hollow and security
  rested solely on the sync.Map key's randomness.
- CSRF switches from a raw-random double-submit cookie to a signed token
  (nonce.HMAC-SHA256 keyed by JWTSecretKey). The middleware now also
  validates the signature, defeating sibling-subdomain cookie tossing
  where a naive header==cookie pair would otherwise pass.

Co-authored-by: cloudcode <cloudcode@users.noreply.github.com>
This commit is contained in:
naiba
2026-05-31 05:48:50 +00:00
co-authored by cloudcode
parent d4837dfc7a
commit 05e14981b5
6 changed files with 280 additions and 20 deletions
@@ -12,6 +12,7 @@ import (
// it so OAuth-only sessions can satisfy the double-submit CSRF gate.
func TestSetCSRFCookieIssuesReadableToken(t *testing.T) {
gin.SetMode(gin.TestMode)
withCSRFSecret(t, "test-jwt-secret")
w := httptest.NewRecorder()
c, _ := gin.CreateTestContext(w)
c.Request = httptest.NewRequest("GET", "/", nil)