0
Only check OCS-APIREQUEST header in case of an apptoken
Source: nextcloud/server#26942 · opened by @LukasReschke
Only check OCS-APIREQUEST header in case of an apptoken: We should only check the OCS-APIREQUEST header in case of an apptoken. Otherwise we should always require the presence of a CSRF token. (in the past there have been bugs that would allow an attacker to set arbitrary headers potentially cross-origin)
No pledges yet. Be the first to back this.
Comments
Similar requests
Support the forwarded header that superceedes X-Forwarded-For
0 votes · 0 comments
[WebDAV] Add "Accept-Ranges: bytes" header
2 votes · 0 comments
Pick vCard version by url parameters
1 vote · 0 comments
[Bug]: Setup check for `X-Robot-Tag` expects exact match, resulting in a warning
9 votes · 0 comments
Code integrity check
3 votes · 0 comments
No comments yet.