Skip to content

Make it possible to disable CSRF check for the specified list of paths. - #13904

Merged
azasypkin merged 4 commits into
elastic:masterfrom
azasypkin:issue-xxx-xsrf-whitelist
Jan 17, 2018
Merged

azasypkin merged 4 commits into
elastic:masterfrom
azasypkin:issue-xxx-xsrf-whitelist

Conversation

@azasypkin

@azasypkin azasypkin commented Sep 8, 2017 •

Copy link
Copy Markdown
Contributor

This PR adds simple white-list for the paths that should not apply CSRF check.

Comment thread src/server/http/xsrf.js Outdated

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems to be the most restrictive way, like people should be very specific about particular URL that is supposed to be white-listed.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

++ agreed, I like this approach — I think it needs to be this specific. It's definitely better to have people list multiple urls in the config than to try to be smart here, if possible.

@azasypkin
azasypkin force-pushed the issue-xxx-xsrf-whitelist branch from d1ddb6f to 11794f8 Compare October 26, 2017 08:16
@azasypkin

Copy link
Copy Markdown
Contributor Author

jenkins, test this

@azasypkin
azasypkin force-pushed the issue-xxx-xsrf-whitelist branch from 11794f8 to 34afb7e Compare November 2, 2017 10:42
@azasypkin azasypkin removed the WIP Work in progress label Nov 2, 2017
@azasypkin
azasypkin force-pushed the issue-xxx-xsrf-whitelist branch from 34afb7e to 6ddcbfd Compare November 3, 2017 11:46
@azasypkin

Copy link
Copy Markdown
Contributor Author

We should probably only merge this PR once ES SAML support and https://github.com/elastic/x-pack-kibana/pull/1752 are merged into master, but it's ready for review nevertheless @kjbekkelund

@azasypkin
azasypkin requested a review from kimjoar November 3, 2017 12:59
@azasypkin azasypkin added review and removed v6.1.0 labels Nov 3, 2017
@azasypkin
azasypkin force-pushed the issue-xxx-xsrf-whitelist branch from 6ddcbfd to 8d41d90 Compare November 23, 2017 12:16
@azasypkin

Copy link
Copy Markdown
Contributor Author

jenkins, test this

@kimjoar kimjoar added Team:Core Platform Core services: plugins, logging, config, saved objects, http, ES client, i18n, etc t// v7.0.0 v6.2.0 and removed blocked labels Jan 17, 2018
@azasypkin
azasypkin merged commit ac63d37 into elastic:master Jan 17, 2018
@azasypkin
azasypkin deleted the issue-xxx-xsrf-whitelist branch January 17, 2018 09:25
@azasypkin

Copy link
Copy Markdown
Contributor Author

6.2: 5610d54
6.x/6.3: af73955

patrykkopycinski pushed a commit to patrykkopycinski/kibana that referenced this pull request May 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review Team:Core Platform Core services: plugins, logging, config, saved objects, http, ES client, i18n, etc t// v6.2.0 v7.0.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants