Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

False positive: "Missing cross-site request forgery token validation" should not apply to Web API Controller Actions sharing a project with Browser-based actions

Aberta
#22,215 1 comentário 0 reações 0 responsáveis Ver no GitHub

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
4/5
Tempo estimado
3-5 dias
Facilidade para iniciantes
48/100
Tipo de issue
Bug
Clareza
Razoavelmente clara
Status de atividade
Pouca atividade
Stack de tecnologia
csharp

Direção de pesquisa

Comece lendo csharp/ql/src/Security Features/CWE-352/MissingAntiForgeryTokenValidation.ql, especialmente a verificação de CSRF em todo o projeto descrita perto da linha 74. Rastreie como as ações dos controladores e seus esquemas de autenticação são modelados e, em seguida, examine a cobertura existente da consulta. O trabalho deve ser considerado concluído quando as ações autenticadas pelo navegador continuarem sendo verificadas, enquanto as ações de API autenticadas por bearer no mesmo projeto não forem reportadas apenas porque outra ação usa validação de CSRF.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

false-positive

Description of the false positive

  • ASP.NET (and ASP.NET Core) projects can have two sets of endpoint handlers (controller actions) which separately handle...
  1. Requests originating from web-browsers, which are authenticated using browser cookies or browser-managed HTTP Basic/Digest authentication; including XHR/fetch-based requests, as well as ordinary document navigation. These are the kinds of requests that are vulnerable to CSRF attacks and so should use a CSRF validation token or other approach.
  2. Requests originating from non-browser-based clients (e.g. daemon processes; cron jobs running curl, etc); these are authenticated using HTTP Authorization header (e.g. Bearer tokens). It is not possible for a CSRF attack to succeed in this case (see https://security.stackexchange.com/questions/170388/do-i-need-csrf-token-if-im-using-bearer-jwt ).

Assuming that this code is the actual CodeQL analysis rule for this alert (CWE-352/MissingAntiForgeryTokenValidation.ql), then the problem is...

  1. The rule is only activated if the project uses CSRF at least once, anywhere (see the comment where it says "Verify that validate anti forgery token attributes are used somewhere within this project").
  2. So it assumes that if at least one controller-action in a project uses CSRF, then all controller-actions in the same project should also use CSRF...
    • This assumption is incorrect: as mentioned above, it's possible for a project to serve both browser-based requests and non-browser requests - with entirely different authentication schemes and policies such that non-browser-based endpoint-actions cannot be invoked in a browser-based CSRF scenario.

Code samples or links to source code

If the two controller-classes are built in a single project, then the fact BrowserAjaxController uses [ValidateAntiForgeryToken] will cause MissingAntiForgeryTokenValidation.q to think that WebServiceController should also use [ValidateAntiForgeryToken] even though it doesn't use browser-cookies based authentication (due to the different Scheme value).

class BrowserAjaxController : Controller
{
    [HttpPost("/ajax/exec-rm-rf-root" )]
    [Authorize( AuthenticationSchemes = MySchemeNames.BrowserCookiesScheme,  Policy = "SomePolicy1" )]
    [ValidateAntiForgeryToken]
    public IActionResult DoTheThing()
    {
        return this.Ok();
    }
}

class WebServiceController : Controller
{
    [HttpPost("/api/arbitrary-operation" )]
    [Authorize( AuthenticationSchemes = MySchemeNames.BearerTokenScheme,  Policy = "SomePolicy2" )]
    public IActionResult DoTheOtherThing()
    {
        return this.Ok();
    }
}
Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 16h
PRs com merge (30d)
143

Guia de contribuição

Abrir o guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de github/codeql

Todas as issues de github/codeql

Issues semelhantes

Mais issues de Security

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.