Using Ory/Kratos login/registration API flows

Viewed 937

In the documentation, there is a large, bright red warning:

Never use API flows to implement Browser applications!

Using API flows in Single-Page-Apps as well as server-side apps opens up several potential attack vectors, including Login and other CSRF attacks.

The documentation does not elaborate on what these attacks are. If I properly secure my application by storing session data on the server, by allowing only the server to access this API, and by implementing my own csrf protection, am I safe? If not, what attacks am I opening myself up to and what additional measures should I take?

Certainly, there must be a way to secure my application without tearing down the running javascript vm then sequentially being redirected three times just to view a login/registration page. For modern apps, I think users may expect this discontinuous transition for successful authentication, but I don't think it's necessarily expected for just viewing the login/registration page.

2 Answers

There are two ways to use Kratos.

From a WebApp (browser)
From a Native app (iOS, Android...)

The first way is using browser redirects and they set csrf tokens.

The second way does not set csrf tokens since there is no browser involved.

That's why there is a warning stating that any sort of "browser" related application should never use the methodology from the native app flows and vice versa!

For example here is how you initialise the login flow for API clients (native apps)

https://www.ory.sh/kratos/docs/reference/api#initialize-login-flow-for-api-clients

And here is an example of how you initialise the login flow for Browser clients

https://www.ory.sh/kratos/docs/reference/api#initialize-login-flow-for-browsers

The selfservice configurations are for your browser redirect flows (so Browser clients).

All credit for this answer goes to https://github.com/Benehiko.

For more details about the warning, please visit the kratos channel.

Related