mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 04:52:50 +08:00
fix(web): referrer-policy same-origin so same-origin POSTs keep a real Origin
no-referrer downgraded the Origin header to the literal "null" on same-origin non-GET requests (per the WHATWG Fetch "Append a request Origin header" algorithm), which the /api/* csrfOriginCheck then rejected with 403 "bad origin" — silently breaking QR login, cookie save, and every other WebUI POST/PUT/DELETE/PATCH (playback, bot management, user admin). /api/session/* was unaffected because it mounts before the CSRF gate, which is why WebUI login still worked. same-origin keeps the real Origin on same-origin requests (CSRF passes) while still sending no Referer cross-origin, so B站/NetEase/QQ CDN cover thumbnails keep loading. Adds referrer-policy.test.ts pinning the policy and a csrf.test.ts case for the Origin: "null" rejection. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
3abb468cca
commit
f720da49d6
3 files changed
+73
-4
No files matched your search
+12
-4
@@ -3,10 +3,18 @@
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<!-- Bilibili / NetEase / QQ image CDNs reject requests whose Referer is not on their whitelist.
|
||||
Setting no-referrer at the document level covers <img> tags AND CSS background-image fetches.
|
||||
Our own /api/* CSRF check uses Origin (not Referer), so this doesn't break auth. -->
|
||||
<meta name="referrer" content="no-referrer">
|
||||
<!-- Bilibili / NetEase / QQ image CDNs reject requests whose Referer is not on
|
||||
their whitelist, so we must not leak a Referer cross-origin. "same-origin"
|
||||
does exactly that: full Referer for our own requests, none for cross-origin
|
||||
ones — so cover thumbnails (<img> AND CSS background-image) still load.
|
||||
Do NOT switch this back to "no-referrer": per the WHATWG Fetch spec
|
||||
("Append a request Origin header") no-referrer downgrades the Origin header
|
||||
to the literal string "null" on same-origin non-GET requests. The /api/*
|
||||
CSRF guard (src/web/middleware/csrf.ts) then can't parse a host from it and
|
||||
responds 403 "bad origin", silently breaking EVERY POST/PUT/DELETE — QR
|
||||
login, cookie save, playback controls, bot management, user admin, etc.
|
||||
"same-origin" keeps the real Origin on same-origin requests, so CSRF passes. -->
|
||||
<meta name="referrer" content="same-origin">
|
||||
<title>TSMusicBot</title>
|
||||
<link rel="preconnect" href="https://fonts.googleapis.com">
|
||||
<link href="https://fonts.googleapis.com/css2?family=Barlow:wght@400;500;600;700;800&display=swap" rel="stylesheet">
|
||||
|
||||
Reference in new issue
Block a user