|
import secrets |
|
from flask import request, session, abort |
|
import os |
|
import time |
|
from functools import wraps |
|
import logging |
|
|
|
|
|
logger = logging.getLogger(__name__) |
|
|
|
def generate_csrf_token(): |
|
"""Generate a new CSRF token""" |
|
if 'csrf_token' not in session: |
|
session['csrf_token'] = secrets.token_hex(32) |
|
|
|
session['csrf_token_time'] = time.time() |
|
return session['csrf_token'] |
|
|
|
def validate_csrf_token(token): |
|
"""Validate the CSRF token""" |
|
|
|
session_token = session.get('csrf_token') |
|
|
|
if not token: |
|
logger.warning("CSRF validation failed: No token provided") |
|
return False |
|
|
|
if token != session_token: |
|
logger.warning(f"CSRF validation failed: Tokens don't match. Request token: {token[:10]}..., Session token: {session_token[:10]}..." if session_token else "None") |
|
return False |
|
|
|
return True |
|
|
|
def csrf_protect(func): |
|
"""Decorator to check CSRF token""" |
|
@wraps(func) |
|
def decorated_function(*args, **kwargs): |
|
|
|
if request.method in ['POST', 'PUT', 'DELETE']: |
|
|
|
header_token = request.headers.get('X-CSRF-Token') |
|
form_token = request.form.get('csrf_token') |
|
token = header_token or form_token |
|
|
|
logger.debug(f"CSRF check: Header token present: {header_token is not None}, Form token present: {form_token is not None}") |
|
|
|
if not validate_csrf_token(token): |
|
logger.warning(f"CSRF validation failed for {request.method} {request.path}") |
|
abort(403) |
|
return func(*args, **kwargs) |
|
return decorated_function |
|
|
|
def set_security_headers(response): |
|
"""Set security headers for all responses""" |
|
|
|
pocketbase_url = os.getenv('POCKETBASE_URL', '') |
|
|
|
|
|
csp_directives = [ |
|
"default-src 'self'", |
|
|
|
"script-src 'self' 'unsafe-inline' https://unpkg.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com", |
|
|
|
"style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com", |
|
|
|
"font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com", |
|
|
|
"img-src 'self' data:", |
|
|
|
f"connect-src 'self' {pocketbase_url}" if pocketbase_url else "connect-src 'self'" |
|
] |
|
|
|
|
|
csp_header = "; ".join(csp_directives) |
|
|
|
|
|
response.headers['Content-Security-Policy'] = csp_header |
|
response.headers['X-Content-Type-Options'] = 'nosniff' |
|
response.headers['X-Frame-Options'] = 'SAMEORIGIN' |
|
response.headers['X-XSS-Protection'] = '1; mode=block' |
|
response.headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains' |
|
|
|
|
|
if 'csrf_token' not in session: |
|
session['csrf_token'] = secrets.token_hex(32) |
|
session['csrf_token_time'] = time.time() |
|
|
|
return response |
|
|