mirror of
https://github.com/Buriburizaem0n/nezha_domains.git
synced 2026-09-19 09:40:12 +00:00
- Set GinJWTMiddleware.SigningAlgorithm to "HS256" explicitly so a future library default change (or an alg:none confusion attempt) cannot weaken token validation. This matches the current gin-jwt default, so behaviour is unchanged. - Set CookieSameSite to Lax: same as the modern-browser default, but pinned so server-side intent is clear and CSRF on cross-site POST is blocked while top-level GET (OAuth callback) still works. - Move the nz-o2s OAuth2 state cookie into writeOauth2StateCookie and set HttpOnly=true. The frontend does not read this cookie, so HttpOnly is strictly an XSS-hardening win with no behaviour change. JWT Cookie HttpOnly/Secure are intentionally left default for now: the frontend reads \`!!document.cookie\` to display login state and many deployments terminate TLS at an upstream proxy — flipping those would require a coordinated frontend change. Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>