Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-4337

Document the fact that X-Requested-By HTTP header needs to be passed for non-GET API calls

    XMLWordPrintableJSON

Details

    • Task
    • Status: Resolved
    • Major
    • Resolution: Done
    • 1.4.2
    • None
    • documentation
    • None

    Description

      Ambari 1.4.2 added CSRF prevention by default.
      This means that non-GET calls now require the "X-Requested-By" header. The API reference doc should be updated to reflect this change.
      Also, we should mention that this behavior can be turned off (at the risk of allowing CSRF) by modifying /etc/ambari/conf/ambari.properties and setting api.csrfPrevention.enabled=false.

      Attachments

        Activity

          People

            Unassigned Unassigned
            u39kun Yusaku Sako
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: