Tuleap Community Edition development and releases are no longer public. You have until September 30th to download packages and sources in Tuleap project. You can contact the team if you need further assistance.

    •  
      request #42977 Harden CSRF protection by blocking all cross-site state modifying queries to the Web UI
    Infos
    #42977
    Thomas Gerbet (tgerbet)
    2025-11-18 22:03
    2025-05-09 15:49
    44725
    Details
    Harden CSRF protection by blocking all cross-site state modifying queries to the Web UI

    By blocking all non-GET/HEAD requests with a Sec-Fetch-Site header set to something else than none or same-origin we could harden our CSRF protection.

    For reference Tuleap already do something equivalent for the REST endpoints.

    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-05-28
    Attachments
    Empty
    References
    Referenced by request #42977

    Follow-ups