security: harden JWT auth with session binding, CSP headers, and sessionStorage

- Reduce access_token_ttl from 900s to 300s (5 min) to shrink XSS exploit window
- Add session_id claim to JWT tokens tied to browser session (X-Session-Id header)
- Flask middleware validates session_id matches header on every request
- CSP headers: default-src/script-src 'self', no unsafe-inline/eval, frame-ancestors none
- X-Content-Type-Options: nosniff on all responses
- Move refresh token from localStorage to sessionStorage (tab-scoped, cleared on close)
- Timing-safe password verification (dummy Argon2id for unknown users)
- WebSocket auth also validates session_id header
- Add 5 session_id tests and 3 CSP header tests
This commit is contained in:
2026-07-24 02:51:54 +00:00
parent 56b200d233
commit a365059976
13 changed files with 317 additions and 96 deletions
-4
View File
@@ -38,9 +38,6 @@ def main() -> None:
from lib.auth_users import ALL_SUBSYSTEMS, create_user
# Generate JWT secret
secret = os.urandom(32).hex()
# Write config
config_dir = project_dir / "config" / "auth"
config_dir.mkdir(parents=True, exist_ok=True)
@@ -51,7 +48,6 @@ def main() -> None:
"access_token_ttl": 900,
"refresh_token_ttl": 604800,
"algorithm": "HS256",
"secret": secret,
},
"webauthn": {
"rp_name": "Vacuum Wall",