•  
      request #10181 Domain name equivalence is not verified properly in the CSRF protection of the REST API
    Infos
    #10181
    Thomas Gerbet (tgerbet)
    2017-05-04 16:38
    2017-04-24 21:28
    10450
    Details
    Domain name equivalence is not verified properly in the CSRF protection of the REST API
    The equivalence of domain name is not done properly in in the CSRF protection of the REST API leading to the rejection of valid request.

    For example, if you set the parameter sys_https_host to EXAMPLE.COM and access your instance through https://example.com, your requests are going to be rejected. Internationalized domain names are also not managed at all.
    API
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2017-05-04
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2017-05-04 16:36
    • Status changed from Closed to Reopen
    • Connected artifacts cleared
    • Close date cleared