Add support for configuring the hash algorithm used to sign CSRF tokens - #700
phinjensen wants to merge 7 commits into
Conversation
| Also set to ``False`` if you want to use WTForms's | ||
| built-in messages directly, see more info `here`_. | ||
| Default is ``True``. | ||
| ``WTF_CSRF_SIGNER_DIGEST_METHOD`` Set to an algorithm from the `hashlib`_ library to |
There was a problem hiding this comment.
:mod:`hashlib` to reference a module
| __all__ = ("generate_csrf", "validate_csrf", "csrf_meta_tag", "CSRFProtect") | ||
| logger = logging.getLogger(__name__) | ||
|
|
||
| DEFAULT_CSRF_SIGNER_DIGEST_METHOD = hashlib.sha1 |
| salt="wtf-csrf-token", | ||
| signer_kwargs={ | ||
| "digest_method": current_app.config.get( | ||
| "WTF_CSRF_SIGNER_DIGEST_METHOD", DEFAULT_CSRF_SIGNER_DIGEST_METHOD |
There was a problem hiding this comment.
This should not pass at all (still use itsdangerous default) unless it's set.
| salt="wtf-csrf-token", | ||
| signer_kwargs={ | ||
| "digest_method": current_app.config.get( | ||
| "WTF_CSRF_SIGNER_DIGEST_METHOD", DEFAULT_CSRF_SIGNER_DIGEST_METHOD |
There was a problem hiding this comment.
This should not pass at all (still use itsdangerous default) unless it's set.
| app.config.setdefault("WTF_CSRF_TIME_LIMIT", 3600) | ||
| app.config.setdefault("WTF_CSRF_SSL_STRICT", True) | ||
| app.config.setdefault( | ||
| "WTF_CSRF_SIGNER_DIGEST_METHOD", DEFAULT_CSRF_SIGNER_DIGEST_METHOD |
|
I think I'd prefer a way to override the signer in general, rather than adding specific configs for specific (potentially nested) arguments. |
I considered doing that, but the signer is passed as a type + properties and gets built by |
|
@davidism I just pushed some commits that address all of your concerns, including making the Signer as a whole configurable. let me know what you think. |
|
@davidism Any thoughts on this? |
This fixes the issue described in #699 by adding a configuration option that allows the user to set what hash algorithm is used by the
itsdangerousSigner object, allowing users on FIPS-enabled systems (or those wanting a better algorithm than sha1 for any reason) to choose which hash algorithm is used.Checklist:
docs/changes.rstsummarizing the change and linking to the issue. Add.. versionchanged::entries in any relevant code docs.