Ensure only logged in users can see /webauthn/register

There are no links to the `webauthn_begin_register` route - you are only
taken there if you are logged in and have clicked to register a key.
However, we have seen this route being crawled by bots making a GET
request which gives a `500` status code error because there isn't a
logged in current_user. For consistency, this also adds teh decorator to
the POST route.
This commit is contained in:
Katie Smith
2021-10-05 09:11:02 +01:00
parent 1fde4b99d9
commit 5885110360

View File

@@ -13,9 +13,11 @@ from app.utils.login import (
log_in_user,
redirect_to_sign_in,
)
from app.utils.user import user_is_logged_in
@main.route('/webauthn/register')
@user_is_logged_in
def webauthn_begin_register():
if not current_user.can_use_webauthn:
abort(403)
@@ -38,6 +40,7 @@ def webauthn_begin_register():
@main.route('/webauthn/register', methods=['POST'])
@user_is_logged_in
def webauthn_complete_register():
if 'webauthn_registration_state' not in session:
return cbor.encode("No registration in progress"), 400