Merged
Conversation
Contributor
|
Needs to be clean rebased on top of latest dev.l, no merge. |
e3c5481 to
c9fd71a
Compare
Contributor
Author
|
- fixes CSRF mismatches on /api/shellCommand.php, /api/previewCamera.php, and /api/capture.php - adds /api/csrf.php endpoint to fetch the current session CSRF token - replaces static frontend token usage with token refresh + single retry on 403 - migrates affected requests to ajaxWithCsrf (including applyEffects/applyVideoEffects) - improves 403 handling: reload only for explicit Invalid CSRF token responses - moves PHP session storage outside the web root and cleans up legacy public session path - reduces token drift after session changes and prevents session file exposure
- Use getTranslation('csrf_session_reloading') instead of hardcoded English.
- Log CSRF mismatch with ERROR prefix consistent with tools.js.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prerequisites checklist
What is the purpose of this pull request? (put an "x" next to an item)
Fixes intermittent 403 / Invalid CSRF token on POST APIs that already use CSRF (
shellCommand,capture,previewCamera,applyEffects,applyVideoEffects) by syncing the token after session drift and hardening session storage.What changes did you make? (Give an overview)
api/csrf.php: JSON endpoint to read the current session CSRF token (GET, no-store).assets/js/tools.js:ajaxWithCsrf(attach token, one retry aftercsrf.phprefresh), explicit CSRF-403 detection,getRequest403 handling; user message viacsrf_session_reloadinginen.json.core.js,preview.js,admin/index.js: affected calls useajaxWithCsrfinstead of stale global token / raw$.ajaxwhere needed.lib/boot.php: session save path outside document root (with fallback), GC ini tweaks, cleanup of legacyvar/sessions.dev(resolveadmin/index.jsheader:photoboothTools+eslint-env browser).Is there anything you'd like reviewers to focus on?
/var/www/sessionsor temp fallback).var/sessions(users re-login).AI used to create this Pull Request?
Yes, in part: implementation and wording were assisted; changes were reviewed and eslint-checked locally.