[E05-S03] CSRF protection #74

Open
opened 2026-08-27 00:00:40 +00:00 by kpcto · 0 comments
Owner

Parent epic: [E05] Administrator security (#33)

Intent

Cookie-authenticated state changes are protected against CSRF and the protection has automated test coverage.

Acceptance criteria

  • All cookie-authenticated state-changing routes require CSRF protection
  • Requests without a valid CSRF token are rejected
  • CSRF protection is backed by automated test coverage

Explicitly out of scope

  • Session token storage, hashing and revocation (E05-S02)
  • Administrator bootstrap password handling (E05-S01)

Test plan

  • Automated test submits a state change without a CSRF token and expects rejection

Rollback note

  • Disable the CSRF middleware via configuration and redeploy the previous build

Owning stream

platform

Risk quadrant

agent-full

> Parent epic: [E05] Administrator security (#33) ## Intent Cookie-authenticated state changes are protected against CSRF and the protection has automated test coverage. ## Acceptance criteria - All cookie-authenticated state-changing routes require CSRF protection - Requests without a valid CSRF token are rejected - CSRF protection is backed by automated test coverage ## Explicitly out of scope - Session token storage, hashing and revocation (E05-S02) - Administrator bootstrap password handling (E05-S01) ## Test plan - Automated test submits a state change without a CSRF token and expects rejection ## Rollback note - Disable the CSRF middleware via configuration and redeploy the previous build ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 1 milestone 2026-08-27 00:00:40 +00:00
kpcto added the
status
proposed
kind
story
labels 2026-08-27 00:00:40 +00:00
Sign in to join this conversation.