Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
/nadaPublic

CSRF routes exclusion#100

Obyka started this conversation inGeneral
Nov 6, 2023· 0 comments
Discussion options

Hello,
While configuring NADA, I saw that several routes are excluded from the anti-CSRF token generation (see snippet below)
In my understanding, some of these routes likeadmin/catalog/update could benefit from CSRF protection.
Is there a technical reason why these path are excluded ? If not, what is the most correct and recent way to include the CSRF token in NADA ?

$config['csrf_protection'] =FALSE;$config['csrf_token_name'] ='ncsrf';$config['csrf_cookie_name'] ='ccsrf';$config['csrf_expire'] =7200;$config['csrf_regenerate'] =FALSE;$config['csrf_exclude_uris'] =array('auth/.*+','admin/citations/find_duplicates','admin/citations/find_surveys','api/.*+','catalog/.*+','admin/catalog/update','admin/pdf_generator/.*+','admin/survey_alias/.*+','admin/catalog_tags/.*+','admin/catalog/set_featured_study/.*+','admin/catalog/update_doi.*+','admin/catalog_notes.*+');
You must be logged in to vote

Replies: 0 comments

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Category
General
Labels
None yet
1 participant
@Obyka

[8]ページ先頭

©2009-2025 Movatter.jp