# Cross-Site Request Forgery (CSRF) (CWE-352) The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. **Stack:** Go - Prevalence: 中 3 言語をカバー - Impact: ハイ 3 件の重大度ハイのルール - Prevention: 文書化済み 3 件の修正例 **OWASP:** Broken Access Control (A01:2021-Broken Access Control) - #1 ## Description When a web server is designed to receive a request from a client without any mechanism for verifying that it was intentionally sent, then it might be possible for an attacker to trick a client into making an unintentional request to the web server which will be treated as an authentic request. ## Prevention 1 件の Shoulder 検出ルールに基づく Cross-Site Request Forgery の予防策。 ### Go Add CSRF middleware to protect state-changing endpoints ## Warning Signs - [HIGH] State-changing endpoints lack CSRF protection ## Consequences - アプリケーションデータの変更 - 権限の取得 - 未承認コードの実行 ## Mitigations - 状態を変更するすべてのリクエストで CSRF 対策トークンを使用する - Referer ヘッダーを確認する - Cookie に SameSite 属性を設定する ## Detection - Total rules: 3 - Languages: javascript, typescript, python, go ## Rules by Language ### Go (1 rules) - **Missing CSRF Protection (Gin)** [HIGH]: State-changing endpoints lack CSRF token protection. - Remediation: Add CSRF middleware using gin-csrf. ```go import "github.com/utrack/gin-csrf" r := gin.Default() r.Use(csrf.Middleware(csrf.Options{ Secret: os.Getenv("CSRF_SECRET"), })) r.POST("/transfer", transferHandler) ``` Learn more: https://shoulder.dev/learn/go/cwe-352/csrf-protection