Open source · Security & Privacy

CSRF Fixture Tester

Compare recorded CSRF middleware decisions with local request fixtures and declared policy; it sends no requests.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Offline, read-only comparison of abstract CSRF request fixtures against recorded local middleware decisions. It consumes no live target URL, executes no middleware, creates no exploit page, and sends no request. The caller's unit harness records observedDecision; this checker tests whether those recorded decisions match a declared origin/token policy. Node.js 22+, zero dependencies. src/index.mjs exports evaluateCsrfFixtures(fixtures, policy, {now, deadline}) and TOOLID.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

node bin/csrf-fixture-tester.mjs --root examples --policy policy.json --fixtures passing-fixtures.json
node bin/csrf-fixture-tester.mjs --root examples --policy policy.json --fixtures failing-fixtures.json

Read the result

The synthetic examples exit 0 and 1. --help prints usage to stderr; normal runs print a bounded human summary to stderr. Stdout contains only the v1 JSON report.

Where this check stops

This local walkthrough does not establish the state of a live production system or replace the limits documented in the repository.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.