Description
Cross-site request forgery (CSRF) abuses authentication information sent automatically by the browser to perform an unintended state-changing request. If the HTTP method changes after CSRF validation, a request excluded from validation may later reach a state-changing operation. Whether this bypass is possible depends on the permitted original methods and override configuration.
Potential impact
- Data or settings may be changed without permission using the victim's authenticated authority.
- CSRF does not itself steal the session secret, but it can abuse the victim's browser to send authenticated requests.
Remediation
- Apply method-override middleware before CSRF validation.
- Restrict the original methods eligible for overriding, and validate CSRF tokens for state-changing requests using the final method.
- The current
method-overridemiddleware permits originalPOSTrequests by default. Review the security implications before extending this toGETor other methods.
Examples
These historical excerpts compare middleware order in Express 3, which is no longer supported. Body parsing, cookie and session setup, and token issuance are omitted. Use supported Express and CSRF implementations for new code.
Before
javascript
const express = require('express');
const app = express();
app.use(express.csrf()); // CSRF middleware runs first
app.use(express.methodOverride());
app.post('/update', function(req, res) {
// Application data-handling logic
res.send('done');
});
After
javascript
const express = require('express');
const app = express();
app.use(express.methodOverride()); // Run methodOverride first
app.use(express.csrf()); // Then apply CSRF middleware
app.post('/update', function(req, res) {
// Application data-handling logic
res.send('done');
});
Explanation:
- Before: CSRF validation sees the request before its method is overridden. Depending on the override configuration, a request excluded from validation may reach a state-changing handler.
- After: Method overriding runs first, so the CSRF middleware evaluates the final method. Correct token validation and session configuration are still required.