Bittersweet Symfony: Devs accidentally turn off CSRF protection in PHP framework
portswigger.net
portswigger.net
In fact, every time somebody choose flask over Django, I ask what they are going to do about CSRF, only to get a blank stare. Same with manual PHP or using most nodejs web libs.
There are so many websites that are vulnerable to this, and it's something we know well, and have solutions for. Imagine what we don't know about. The internet is really made of swiss cheese.
Django provides so much security out of the box.
That's before we even talk about features.
It just feels free because you already paid with your time to learn the conventions. :)
2. WTForms is not the only way to do CSRF tokens with Flask
My point is that it’s not plausible to infer with certainty that some large part of Flask users would not have CSRF tokens just because Flask has more downloads than Flask-WTF
[0]: https://github.com/nickjj/build-a-saas-app-with-flask/blob/1...
If you are professional you know what kind of potential problems might happen and you know what are reasonable possible approaches to handle it.
If security of your piece of software relies on default values of some settings I would reasonably expect you to have automated tests to verify that these settings have correct values.
Next time you hire an electrician who causes damage to your house because he did not follow procedure to wire it correctly, will you be still calling him "professional" because he quickly removed the short?
But if you are calling somebody or something "professional" what you are saying is they act as if they were doing it in a certain way. If they don't follow the practices it does not matter if they are doing it for free.
It is like saying a kid is doing something professionally (even if he is not) and argumenting that it is because he isn't paid for it.
I mean I fail to understand what are you trying to say, someone stops being a professional as soon as it hasn't covered a test case?
Or are they kids just for having slipped a bug? Despite their work powers a lot of companies software (including the ones I work for)
Are you just trolling?
I don't know if they are or are not professionals.
It is just my opinion that being nice and prompt about removing cause of the damage after they have caused damage through recklessly ignoring industry standards cannot be reason to call their entire set of actions around this particular issue as "professional".
So they didn't say their "entire set of actions" was "professional" just that it was disclosed and resolved professionally.
If you consider that kind of behavior recklessly unprofessional I'd be amazed to see the kind of tests you write for your code.
Yes -- it is important how you rectify those mistakes.
But being quick at rectifying mistakes does not yet make your actions professional.
Source: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Se...
But I would say yes you still need it for defence in depth.
For instance in RFC6749 (OAuth 2.0) it says clients MUST implement CSRF for the redirection step.
So many PRs people ask, why should we add protective measure X, when we already have protective measure Y? Defense in depth, my friends.
I took a job at a subcontracting about 9 years ago, where I was mostly doing Node.js work, but there were some projects using Symfony, and even after using it on/off for a month, I have to say I never really "got" it. I could tell there's something there that's fairly cool, but I never really was able to wrap my head around all the folders.
I've become a way better programmer since then, so I have thought about trying it out again, but nothing in my day job uses PHP anymore, and I've moved away from web since then.
Laravel is the other big MVC framework for PHP.
Quite nice to see they're all going.
The frameworks around before, Zend & CodeIgniter, were flawed in my opinion and Symfony was a breath of fresh air. More recently though, it feels like Laravel is doing a better job at letting people just get on with building a website.
No doubt about it though, some very talented people contributed to that project and I imagine they still do. Symfony was one of the lights in the dark if you ask me; PHP could be a very ugly thing at the time, but it proved that you could do great things with it by applying good practices and being diligent about reviewing and improving designs.
One of the things that blew me away (I was pretty green at the time) was when they made all of Symfony modular, and other frameworks began consuming their components. The portability of all of it was so impressing and inspiring to me back then.
Anyway, plenty of ways to criticize PHP and Symfony, but I think they did a stellar job. I built my career on that stuff. I haven't actually looked at it in quite a while, though.
https://github.com/Qbix/Platform
It takes the best ideas from CodeIgniter, Symfony, Kohana, Drupal and Doctrine…
Modern Symfony changed a lot about directory structures, and no longer recommends to use bundles. Most things now are autowired.
Oh, wait, it's PHP... Nevermind.
A random package author removes a package from npm breaking thousands of apps, never mind its Nodejs.
A random package typo squats a famous package name making many apps vulnerable, never mind its python.
A random logging library grants access to shell, never mind its Java.
I could go on.
As a demo, here is a link to an 1100 line file full of such tests for the Rails framework: https://github.com/rails/rails/blob/main/actionpack/test/con...