#29802: Allow skipping CSRF check for Referer header
-------------------------------------+-------------------------------------
     Reporter:  Aaron1011            |                    Owner:  nobody
         Type:  New feature          |                   Status:  new
    Component:  CSRF                 |                  Version:  2.1
     Severity:  Normal               |               Resolution:
     Keywords:                       |             Triage Stage:
  csrf,https,hsts,referer            |  Unreviewed
    Has patch:  0                    |      Needs documentation:  0
  Needs tests:  0                    |  Patch needs improvement:  0
Easy pickings:  0                    |                    UI/UX:  0
-------------------------------------+-------------------------------------
Description changed by Aaron1011:

Old description:

> Currently, Django's CSRF middleware will reject any 'non-safe' HTTPS
> request that lacks a Referer header:
> https://github.com/django/django/blob/22e8ab02863819093832de9f771bf40a62a6bd4a/django/middleware/csrf.py#L242
>
> However, some users may prevent their browsers from sending the Referer
> header, due to privacy concerns. These users are unable to submit 'non-
> safe' requests (e.g. POST requests) on HTTPS-enabled Django-powered
> website that uses CSRF protection.
>
> For some websites, checking the Referer header may provide no added
> security benefit. For example, an HSTS-preloaded website which controls
> all of its subdomains has nothing to gain from this check - there are no
> untrusted subdomains which can mount an attack, and HSTS prevents an HTTP
> MITM attack.
>
> To allow these websites to provide more flexibility to their users,
> Django should support disabling this CSRF Referer check. This could be
> done through a new setting, e.g. ' CSRF_REFERER_CHECK' (defaulting to
> 'True' to avoid breaking existing sites).

New description:

 Currently, Django's CSRF middleware will reject any 'non-safe' HTTPS
 request that lacks a Referer header:
 
https://github.com/django/django/blob/22e8ab02863819093832de9f771bf40a62a6bd4a/django/middleware/csrf.py#L242

 However, some users may prevent their browsers from sending the Referer
 header, due to privacy concerns. These users are unable to submit 'non-
 safe' requests (e.g. POST requests) on HTTPS-enabled Django-powered
 website that use CSRF protection.

 For some websites, checking the Referer header may provide no added
 security benefit. For example, an HSTS-preloaded website which controls
 all of its subdomains has nothing to gain from this check - there are no
 untrusted subdomains which can mount an attack, and HSTS prevents an HTTP
 MITM attack.

 To allow these websites to provide more flexibility to their users, Django
 should support disabling this CSRF Referer check. This could be done
 through a new setting, e.g. ' CSRF_REFERER_CHECK' (defaulting to 'True' to
 avoid breaking existing sites).

--

-- 
Ticket URL: <https://code.djangoproject.com/ticket/29802#comment:1>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/067.79778958d1b270f175a253049f2e2f28%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to