mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-01 20:42:50 +08:00
no-referrer downgraded the Origin header to the literal "null" on same-origin non-GET requests (per the WHATWG Fetch "Append a request Origin header" algorithm), which the /api/* csrfOriginCheck then rejected with 403 "bad origin" — silently breaking QR login, cookie save, and every other WebUI POST/PUT/DELETE/PATCH (playback, bot management, user admin). /api/session/* was unaffected because it mounts before the CSRF gate, which is why WebUI login still worked. same-origin keeps the real Origin on same-origin requests (CSRF passes) while still sending no Referer cross-origin, so B站/NetEase/QQ CDN cover thumbnails keep loading. Adds referrer-policy.test.ts pinning the policy and a csrf.test.ts case for the Origin: "null" rejection. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
27 lines
1.4 KiB
HTML
27 lines
1.4 KiB
HTML
<!DOCTYPE html>
|
|
<html lang="zh-CN">
|
|
<head>
|
|
<meta charset="UTF-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
<!-- Bilibili / NetEase / QQ image CDNs reject requests whose Referer is not on
|
|
their whitelist, so we must not leak a Referer cross-origin. "same-origin"
|
|
does exactly that: full Referer for our own requests, none for cross-origin
|
|
ones — so cover thumbnails (<img> AND CSS background-image) still load.
|
|
Do NOT switch this back to "no-referrer": per the WHATWG Fetch spec
|
|
("Append a request Origin header") no-referrer downgrades the Origin header
|
|
to the literal string "null" on same-origin non-GET requests. The /api/*
|
|
CSRF guard (src/web/middleware/csrf.ts) then can't parse a host from it and
|
|
responds 403 "bad origin", silently breaking EVERY POST/PUT/DELETE — QR
|
|
login, cookie save, playback controls, bot management, user admin, etc.
|
|
"same-origin" keeps the real Origin on same-origin requests, so CSRF passes. -->
|
|
<meta name="referrer" content="same-origin">
|
|
<title>TSMusicBot</title>
|
|
<link rel="preconnect" href="https://fonts.googleapis.com">
|
|
<link href="https://fonts.googleapis.com/css2?family=Barlow:wght@400;500;600;700;800&display=swap" rel="stylesheet">
|
|
</head>
|
|
<body>
|
|
<div id="app"></div>
|
|
<script type="module" src="/src/main.ts"></script>
|
|
</body>
|
|
</html>
|