Summary
Trinity's WebSocket endpoint accepts a JWT via `?token=` URL query parameter. While this fixes the original unauthenticated access finding, the approach introduces Cross-Site WebSocket Hijacking (CSWSH) and leaks the JWT in browser history, proxy logs, and server access logs. This was flagged as Partially Fixed in the April 2026 UnderDefense remediation pentest (finding 3.2.1, residual CVSS ~2.1).
Context
The original finding required adding authentication to `/ws`. The fix added `?token=` in the URL. The remediation pentest flagged the remaining risk:
- CSWSH: A malicious page can initiate a WebSocket connection to Trinity using the victim's browser session (cookies/credentials sent automatically for same-origin).
- Token leakage: JWT appears in nginx access logs, browser history, and any intermediate proxy logs — a 7-day token exposed in logs is high-value.
The standard fix is a short-lived one-time WS ticket:
- Authenticated client calls `POST /api/ws/ticket` → backend returns a random opaque token (e.g., 32-byte urlsafe, 30s TTL in Redis)
- Client connects to `/ws?ticket=<opaque_token>`
- Backend exchanges ticket → user session; ticket is single-use and deleted on first use
This breaks CSWSH (ticket can't be forged cross-site) and eliminates JWT exposure in logs.
Acceptance Criteria
Technical Notes
- Current WS auth: `src/backend/main.py` — `/ws` endpoint reads `?token=` query param
- Frontend WS client: `src/frontend/src/utils/websocket.js`
- Redis already available for ticket storage (same pattern as OAuth state)
- Ticket TTL of 30s is sufficient — client fetches ticket immediately before connecting
- Also applies to `/ws/events` (MCP events WebSocket) if it has the same pattern
Summary
Trinity's WebSocket endpoint accepts a JWT via `?token=` URL query parameter. While this fixes the original unauthenticated access finding, the approach introduces Cross-Site WebSocket Hijacking (CSWSH) and leaks the JWT in browser history, proxy logs, and server access logs. This was flagged as Partially Fixed in the April 2026 UnderDefense remediation pentest (finding 3.2.1, residual CVSS ~2.1).
Context
The original finding required adding authentication to `/ws`. The fix added `?token=` in the URL. The remediation pentest flagged the remaining risk:
The standard fix is a short-lived one-time WS ticket:
This breaks CSWSH (ticket can't be forged cross-site) and eliminates JWT exposure in logs.
Acceptance Criteria
Technical Notes