fix: harden auth with refresh token session binding, logging, and router state

- Add session_id to refresh tokens and enforce it during validation,
  preventing stolen refresh tokens from being usable without the
  originating browser session
- Set router.isAuthenticated via auth:login event after successful
  login (previously only set at page load)
- Add console.warn logging to WS message parse/handler errors
- Improve _refreshPromise error handling in token refresh flow
- Document rate limiter in-memory limitation and CSP connect-src
  same-origin requirement
- Add 3 tests for session-bound refresh token validation
This commit is contained in:
2026-08-12 15:53:17 +00:00
parent 76300e281f
commit 6404508519
8 changed files with 95 additions and 38 deletions
+3
View File
@@ -259,6 +259,9 @@ def _log_request_finish(response):
)
# Content Security Policy — prevent inline script execution and XSS
# NOTE: connect-src 'self' is safe because all XHR/fetch/WS calls go through
# nginx on the same origin. If WS or API routing ever changes to use a
# different host/port directly, the CSP must be updated accordingly.
if "Content-Security-Policy" not in response.headers:
response.headers["Content-Security-Policy"] = (
"default-src 'self'; "