opendevstack / opendevstack/ods-quickstarters
Flask quickstarter is not protected from CSRF by default
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 39
- Forks
- 50
- PR merge metrics
- No merged PRs in 30d
Description
A newly provisioned Flask quickstarter is immediately flagged by SonarQube:
Make sure disabling CSRF protection is safe here.
The recommended action is to change:
app = Flask(__name__)
to:
app = Flask(__name__)
csrf = CSRFProtect()
csrf.init_app(app)
@gerardcl @henrjk @buegelbeatz Do you see any issues doing that change?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Locate the Flask quickstarter entry point and inspect how the application and its dependencies are initialized. Compare the current setup with the CSRFProtect configuration shown in the issue, then run the quickstarter's existing checks and confirm the SonarQube warning is addressed without breaking startup.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- flask, python
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100