Files
nezha_domains/cmd/dashboard
naibaandcloudcode a4f4cb1f34 fix(fm): switch create FM session to POST to defeat CSRF
GET /api/v1/file?id=<server> created an FM stream on the agent stream
and committed real state change (TaskTypeFM dispatched). With JWT
cookie SameSite=Lax a victim's browser would still send the cookie on
a top-level cross-site GET, so an attacker could trick a logged-in
user into opening an FM session on any of their own servers, consuming
resources and triggering the agent's FM machinery without consent.

Mirror the GHSA-8qhj-4f8c-j8qg fix: move the route to POST. SameSite=
Lax cookies are not sent on cross-site POST. Frontend (admin-frontend)
adjusted in a follow-up commit.

Co-authored-by: cloudcode <cloudcode@users.noreply.github.com>
2026-05-26 04:07:49 +00:00
..
2024-11-29 21:31:39 +08:00
2026-05-25 10:17:34 +00:00
2024-11-29 21:31:39 +08:00