Uploaded image for project: 'translate5'
  1. translate5
  2. TRANSLATE-3273

Security fixes against hacking translate5 for CSRF (Cross-site request forgery)

    XMLWordPrintable

Details

    • Critical
    • Hide
      CSRF protection was unintentionally blocking some live communication between browser and translate5 server. In detail: session re-sync endpoint needed for re-sync to MessageBus socket server after network reconnect.
      An exception for that endpoint was added.
      Show
      CSRF protection was unintentionally blocking some live communication between browser and translate5 server. In detail: session re-sync endpoint needed for re-sync to MessageBus socket server after network reconnect. An exception for that endpoint was added.

    Description

      problem

      session resync endpoint needed for resync to frontendmessagebus after network reconnect is not working due CSRF protection.

      Attachments

        Activity

          People

            axelbecher Axel Becher
            axelbecher Axel Becher
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: