Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
Security 1.1.16
-
None
Description
As discussed in https://issues.apache.org/jira/browse/SLING-9043?focusedCommentId=17031442&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-17031442 the origin header should be used to implement some CSRF protection. See also https://owasp.org/www-project-cheat-sheets/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#verifying-origin-with-standard-headers, https://seclab.stanford.edu/websec/csrf/csrf.pdf and https://www.sjoerdlangkemper.nl/2019/02/27/prevent-csrf-with-the-origin-http-request-header/
Attachments
Issue Links
- is duplicated by
-
SLING-11871 Referrer Filter - Enable Bypass for Requests with Origin Header
- Closed
- is related to
-
SLING-11871 Referrer Filter - Enable Bypass for Requests with Origin Header
- Closed
- relates to
-
SLING-9043 COPY/MOVE should be in the referer filter's default list of protected HTTP methods
- Closed
- links to