Skip to content

fix(middleware): reject CSRF TokenLookup that produces no extractors (v4) - #3149

Open
orinnz wants to merge 1 commit into
labstack:v4from
orinnz:fix/v4-csrf-empty-extractors
Open

orinnz wants to merge 1 commit into
labstack:v4from
orinnz:fix/v4-csrf-empty-extractors

Conversation

@orinnz

@orinnz orinnz commented Oct 3, 2026

Copy link
Copy Markdown

Backport of #3067 to v4.

If every source in TokenLookup is unknown (for example nope:nope), CreateExtractors returns an empty list without an error. The middleware is then created with nothing to check, so unsafe requests go through with no token validation. ToMiddleware now returns an error in that case, so the misconfiguration shows up at startup instead of silently turning CSRF protection off.

Added a case to TestCSRF_tokenExtractors. It fails before the change and passes after. go test ./... passes.

…in v4

A TokenLookup whose sources are all unknown (for example "nope:nope")
parsed without error but yielded zero extractors. With nothing to
check, unsafe requests were let through without any token validation.
Fail middleware creation instead, so the misconfiguration surfaces at
startup.

Backport of labstack#3067.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant