Uploaded image for project: 'JSPWiki'
  1. JSPWiki
  2. JSPWIKI-1075

Add CSRF protection

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 2.11.3
    • None
    • None

    Description

      As far as I can tell, JSPWIKI currently lacks protection agains Cross-Site Request Forgery (CSRF). Are there plans (or previous work) to add for example some additional session token to prevent CSRF?

      I'm willing to contribute here, but some general discussion about how and where to implement this would be helpful. 

      More info about CSRF here: https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet

      Attachments

        Activity

          People

            Unassigned Unassigned
            astriffler Albrecht Striffler
            Votes:
            1 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: