Skip to content

feat(flow): expose received cookies to templates for CSRF - #61

Merged
moosebay merged 1 commit into
mainfrom
feat/template-cookies
Oct 7, 2026
Merged

moosebay merged 1 commit into
mainfrom
feat/template-cookies

Conversation

@moosebay

@moosebay moosebay commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Double-submit CSRF protection (Django csrftoken, Laravel and Angular XSRF-TOKEN, many Express apps) has the client copy a cookie into a header. Flows already kept cookie sessions through the client's jar, but couldn't read a cookie's value, so such requests always got 403.

  • httpclient.New uses a recording jar that also keeps the latest value of every cookie it receives, URL-decoded the way client code reads them. httpclient.Cookies returns them.
  • Request and GraphQL nodes expose them as the cookies variable: {{ cookies.csrftoken }} / {{ cookies["XSRF-TOKEN"] }}. A flow variable named cookies takes precedence.
  • Version plan: cli: minor.

Verified

  • Unit tests for the jar and WithCookies.
  • A built CLI against a double-submit CSRF server: login, cookie session, then POST with X-CSRF-Token: {{ cookies.csrftoken }}. 4/4 steps pass, in both template forms. It got 403 before.
  • server:lint, cli:lint, root:lint:format, client:lint, server:test green.
  • cli:test: only the known TestFlowRun_WebSocket flake failed. Measured over 20 runs each, it fails 4/20 on this branch and 5/20 on main.

🤖 Generated with Claude Code

https://claude.ai/code/session_01DTfHLHkkg1TPGQgj6P6grg

Double-submit CSRF protection has the client copy a cookie into a header
(X-CSRFToken, X-XSRF-TOKEN). A flow could keep a cookie session (the client
has a jar) but had no way to read a cookie's value, so such requests always
failed with 403.

- httpclient.New uses a recording jar that also keeps the latest value of
  every cookie it receives, URL-decoded; httpclient.Cookies reads them.
- Request and GraphQL nodes add them as the `cookies` variable:
  {{ cookies.csrftoken }} / {{ cookies["XSRF-TOKEN"] }}. A flow variable
  named cookies wins.

Claude-Session: https://claude.ai/code/session_01DTfHLHkkg1TPGQgj6P6grg
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

📊 Performance Comparison

Generated on 2026-10-07 16:07:13 UTC

Detailed Results

Benchmark Old Ops/sec New Ops/sec Change Memory Change Status
CreateMockFlow_Large 84368 85131 +0.9% +0.0% ⚠️
CreateMockFlow_Medium 245086 248606 +1.4% +0.0% ⚠️
CreateMockFlow_Small 560415 557829 -0.5% +0.0% ⚠️
FlowExecution_Large 46 46 +0.0% +0.0% ⚠️
FlowExecution_Medium 135 135 +0.0% +0.1% ⚠️
FlowExecution_Small 369 369 +0.0% +0.0% ⚠️

📈 Summary Statistics

  • Total benchmarks compared: 6
  • Regressions: 0 🚨
  • Improvements: 0 ✅
  • Neutral: 6 ⚠️

✅ Stable Performance: All benchmarks within acceptable range

@moosebay
moosebay merged commit c65e79a into main Oct 7, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant