rpc: prevent cross-origin calls with cached credentials #36464

pull l0rinc wants to merge 2 commits into bitcoin:master from l0rinc:l0rinc/rpc-reject-origin changing 2 files +21 −0
  1. l0rinc commented at 5:51 AM on October 8, 2026: contributor

    Problem: If a browser has cached Bitcoin Core RPC credentials, another page permitted to reach RPC may be able to invoke methods using them. The calls can execute even when the page cannot read the response.

    Browser RPC examples I found: Block Clock, transaction broadcasting.

    Fix: Reject browser-origin RPC requests before authentication.

    Note that this rejects every Origin value, including same-origin requests, null, and empty values. Browser or reverse-proxy integrations that add this header will need to adapt.

  2. test: characterize cross-origin RPC requests
    Record that `getblockcount` succeeds with an Origin header and valid credentials, while unauthenticated requests receive a login challenge.
    The following fix will reject these requests before authentication.
    f8592b75b9
  3. rpc: reject browser cross-origin requests
    After a browser authenticates to RPC, another page permitted to reach the endpoint may cause calls to execute using cached credentials, even when it cannot read the response.
    Reject RPC requests carrying an Origin header before authentication.
    
    Browser RPC examples:
    https://github.com/voltagecloud/block-clock#connecting-to-bitcoin-core-rpc-locally
    https://github.com/bitcoin/bitcoin/pull/12040#issuecomment-363307306
    cbe4698cb5
  4. DrahtBot added the label RPC/REST/ZMQ on Oct 8, 2026
  5. DrahtBot commented at 5:52 AM on October 8, 2026: contributor

    <!--e57a25ab6845829454e8d69fc972939a-->

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    <!--006a51241073e994b41acfe9ec718e94-->

    External sites

    <!--021abf342d371248e50ceaed478a90ca-->

    Reviews

    See the guideline and AI policy for information on the review process.

    Type Reviewers
    Concept ACK pinheadmz

    If your review is incorrectly listed, please copy-paste <code>&lt;!--meta-tag:bot-skip--&gt;</code> into the comment that the bot should ignore.

    <!--5faf32d7da4f0f540f40219e4f7537a3-->

    LLM Linter (✨ experimental)

    Possible places where comparison-specific test macros should replace generic comparisons:

    • test/functional/interface_http.py: assert response.getheader('WWW-Authenticate') is None → Prefer assert_equal(response.getheader('WWW-Authenticate'), None).

    <sup>2026-10-08 05:52:10</sup>

  6. pinheadmz commented at 9:33 AM on October 8, 2026: member

    concept ACK


github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-10-11 08:51 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me