ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
csrf.h File Reference

Stateless HMAC-signed CSRF token (PROTOCORE_ENABLE_CSRF). More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

Stateless HMAC-signed CSRF token (PROTOCORE_ENABLE_CSRF).

A token is <nonce_hex>.<sig_hex> where sig is the first CSRF_SIG_BYTES of HMAC-SHA256(secret, nonce). The secret is seeded once from the platform's randomness; the nonce is a per-issue counter and need not be secret, because the security is the HMAC. A verify recomputes the HMAC over the embedded nonce and compares the signature in constant time, so no server-side session state is kept.

The token is sized to fit a single MAX_VAL_LEN header value and a csrf= cookie. Nothing here touches a platform, so it runs on the host with PROTOCORE_ENABLE_CSRF set and a fixed secret.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file csrf.h.