plone / plone/plone.restapi

Disable plone.protect for all API calls

Open
#155 7 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

05 type: question
Dominant language
Python
Stars
109
Forks
107
Avg merge
2d 3h
Merged PRs (30d)
4

Description

There is a way to disable it always for all restapi calls? Or it is required to disable it manually always?

        # Disable CSRF protection
        if 'IDisableCSRFProtection' in dir(plone.protect.interfaces):
            alsoProvides(self.request,
                         plone.protect.interfaces.IDisableCSRFProtection)

If so, maybe we can provide a convenience decorator for that...

@tisto @lukasgraf @buchi any insights?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the manual plone.protect usage shown in the issue and the associated discussion. The work is complete when the project has agreed on and documented a supported way to disable CSRF protection for REST API calls, with the relevant behavior covered by tests if the discussion identifies them.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
api
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.