2 ms·
Yeah, implementing a Vault client in the browser is just asking for trouble. Currently, I am copy-pasting into the browser, which has two obvious vulnerabilitie
by devrandomguy 9y ago
Yeah, implementing a Vault client in the browser is just asking for trouble. Currently, I am copy-pasting into the browser, which has two obvious vulnerabilities: the clipboard, which is accessible to everything, and the login page, which could be running an XSS exploit.
Perhaps we could eliminate both problems, by handling authentication outside of the browser, and then injecting an auth cookie into a new browser tab?
1. `curl site.com/login` to get the login form as HTML
2. Extract the form submission URL and the name of the user/pass fields
3. Pipe a key from Vault, to a URL encoded HTTPS POST request (curl again)
4. Receive the resulting session cookie and the login-success URL from the login response
5. Insert or replace this cookie into Firefox's jar
6. Open a new browser tab to the login-success URL
This way, the browser never sees the password, and the clipboard never holds it. The session cookie is still just as vulnerable as ever, but is of a lower value, assuming that it alone does not grant the ability to change the user's password or PW recovery email address. The entire sequence could be scripted into an `authenticate my-user@site.com` command, which would depend on a connected Vault client (or some other backend scheme). I have no idea if this would work on mobile operating systems, it might not be possible to write to the FF cookie jar from another app.