#41 FTX-41: CSRF + Action Web session + OTP in Redis

closed high Created 2026-07-23 15:08 · Updated 2026-07-23 15:31

Description

Edit
Signed HttpOnly session cookie on review GET + double-submit CSRF on all Action Web POSTs (UB-AW-6, UB-TOK-5, UN-SEC-2); OTP moves to Redis (hashed code, TTL, atomic attempts max 5, single-use); step-up decided by policy snapshot not client form field (current require_otp param is a bypass). Phase 1.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...