Where: src/websocket.rs, src/dispatch.rs (run_rsgi_websocket).
There is no built-in check of the Origin header on WebSocket upgrade. Browsers don't enforce CORS/SOP for WebSocket connections, so if a deployment authenticates WebSocket connections via a cookie (rather than a token passed explicitly in a message), any origin can open a cross-site WebSocket and ride the victim's session — classic CSWSH (Cross-Site WebSocket Hijacking).
Fix direction: provide an opt-in (or documented pattern) for validating Origin on the WebSocket handshake before accept(), e.g. an allowlist parameter on @app.websocket(path, allowed_origins=[...]) or documented guidance to check ws.scope.headers.get("origin") manually when cookie-based auth is used.
Where:
src/websocket.rs,src/dispatch.rs(run_rsgi_websocket).There is no built-in check of the
Originheader on WebSocket upgrade. Browsers don't enforce CORS/SOP for WebSocket connections, so if a deployment authenticates WebSocket connections via a cookie (rather than a token passed explicitly in a message), any origin can open a cross-site WebSocket and ride the victim's session — classic CSWSH (Cross-Site WebSocket Hijacking).Fix direction: provide an opt-in (or documented pattern) for validating
Originon the WebSocket handshake beforeaccept(), e.g. an allowlist parameter on@app.websocket(path, allowed_origins=[...])or documented guidance to checkws.scope.headers.get("origin")manually when cookie-based auth is used.