-
Notifications
You must be signed in to change notification settings - Fork 4
/
index.js
65 lines (62 loc) · 2.07 KB
/
index.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
const { randomUUID } = require("crypto");
const { encryptCookie, verifyCsrf } = require("./encryption");
const cookieParams = {
httpOnly: true,
sameSite: "strict",
signed: true,
maxAge: 300000
};
const csurf = (secret, forbiddenMethods, excludedUrls, excludedReferers) => {
if (secret.length != 32)
throw new Error("Your secret is not the required 32 characters long");
if (!forbiddenMethods) forbiddenMethods = ["POST", "PUT", "PATCH"];
if (!excludedReferers) excludedReferers = [];
else if (!Array.isArray(excludedReferers))
throw new Error(
`Invalid argument passed for excludedReferers (fourth arg): ${excludedReferers}`
);
return (req, res, next) => {
if (!req.cookies || !res.cookie || !req.signedCookies)
throw new Error("No Cookie middleware is installed");
if (
// if any excludedUrl matches as either string or regexp
excludedUrls?.filter(
(x) => x == req.originalUrl || (x.test && x.test(req.originalUrl))
).length > 0
) {
req.csrfToken = () => {
if (excludedReferers.includes(req.headers.referer)) return null;
else {
const csrfToken = randomUUID();
res.cookie(
"csrfToken",
encryptCookie(csrfToken, secret),
cookieParams
);
return csrfToken;
}
};
return next();
} else if (forbiddenMethods.includes(req.method)) {
const { csrfToken } = req.signedCookies;
if (
csrfToken != undefined &&
verifyCsrf(req.body?._csrf, csrfToken, secret)
) {
res.cookie("csrfToken", null, cookieParams);
} else {
throw new Error(
`Did not get a valid CSRF token for '${req.method} ${req.originalUrl}': ${req.body?._csrf} v. ${csrfToken}`
);
}
}
req.csrfToken = () => {
if (excludedReferers.includes(req.headers.referer)) return null;
const csrfToken = randomUUID();
res.cookie("csrfToken", encryptCookie(csrfToken, secret), cookieParams);
return csrfToken;
};
return next();
};
};
module.exports = csurf;