Protect against XSFR attacks
Open
@laeti-tia is already working on this.
Since Jul 12, 2017.
- Dominant language
- JavaScript
- Stars
- 37
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
Our current forms, i.e. configuration changes forms, are not well protected against XSFR attacks. We should use one-time tokens or other functionalities to make sure POST request are originating from real users.
From GN4-SA2T1 report 2.2.21.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.