FeatureFuel
0

Only check OCS-APIREQUEST header in case of an apptoken

Source: nextcloud/server#26942 · opened by @LukasReschke
Only check OCS-APIREQUEST header in case of an apptoken: We should only check the OCS-APIREQUEST header in case of an apptoken. Otherwise we should always require the presence of a CSRF token. (in the past there have been bugs that would allow an attacker to set arbitrary headers potentially cross-origin)

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests