Disable plone.protect for all API calls
Open
Nobody has claimed this yet.
05 type: question
- Dominant language
- Python
- Stars
- 109
- Forks
- 107
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 4
Description
There is a way to disable it always for all restapi calls? Or it is required to disable it manually always?
# Disable CSRF protection
if 'IDisableCSRFProtection' in dir(plone.protect.interfaces):
alsoProvides(self.request,
plone.protect.interfaces.IDisableCSRFProtection)
If so, maybe we can provide a convenience decorator for that...
@tisto @lukasgraf @buchi any insights?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the manual plone.protect usage shown in the issue and the associated discussion. The work is complete when the project has agreed on and documented a supported way to disable CSRF protection for REST API calls, with the relevant behavior covered by tests if the discussion identifies them.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- api
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100