A08 — Software & Data Integrity Failures
CSRFTokenManager issues and validates anti-CSRF tokens; HTTPClient wraps fetch with CSRF attachment, an async tokenProvider, interceptors, and origin-aware credential handling.
Core API (@owasp-webshield/core)
js
import { CSRFTokenManager, DATA_INTEGRITY_TYPES, HTTPClient, SSRFGuard } from "@owasp-webshield/core";
const csrf = new CSRFTokenManager();
csrf.rotateToken();
csrf.attach({});
csrf.validate(csrf.getToken());
const client = new HTTPClient({
baseUrl: "https://api.example.com",
csrfManager: csrf,
tokenProvider: async () => "access-token",
outboundRequestPolicy: new SSRFGuard()
});
client.addRequestInterceptor(async (config) => ({
...config,
headers: { ...config.headers, "X-Request-Id": "req-1" }
}));
const response = await client.request("/profile", { method: "GET" });
console.log(response.ok, response.data, DATA_INTEGRITY_TYPES);HTTPClientaccepts atokenProviderfunction that may return a string,null, or a promise for either value. The client always awaits it before sending the request.Authorization/X-CSRF-Tokenheaders are only attached to requests whose target matchesbaseUrl's origin, or an origin explicitly listed inallowedOrigins— otherwise aCREDENTIAL_LEAK_BLOCKEDSecurityErroris thrown. This closes a cross-origin credential leak; see CHANGELOG for the 1.0.3 fix.- Passing an
outboundRequestPolicy(typically aSSRFGuard) composes transport hardening with SSRF defense in one client.
React Adapter (@owasp-webshield/react)
jsx
import React from "react";
import { useSecureHttpClient, withSecurityHeaders } from "@owasp-webshield/react";
export function ProfileLoader({ tokenManager }) {
const client = useSecureHttpClient({
baseUrl: "https://api.example.com",
tokenProvider: async () => tokenManager.getAccessToken()
});
async function loadProfile() {
const response = await client.request(
"/profile",
withSecurityHeaders({
method: "GET",
headers: { "X-Feature": "profile-view" }
})
);
console.log(response.data);
}
return <button onClick={loadProfile}>Load profile</button>;
}useSecureHttpClient()creates oneCSRFTokenManagerper hook instance and rotates a token during initialization.withSecurityHeaders()adds OWL defaults and preserves caller-supplied headers.