Repository navigation
Make it possible to disable CSRF check for the specified list of paths. - #13904
Merged
Merged
Conversation
azasypkin
commented
Sep 8, 2017
Contributor
Author
There was a problem hiding this comment.
It seems to be the most restrictive way, like people should be very specific about particular URL that is supposed to be white-listed.
Contributor
There was a problem hiding this comment.
++ agreed, I like this approach — I think it needs to be this specific. It's definitely better to have people list multiple urls in the config than to try to be smart here, if possible.
azasypkin
force-pushed
the
issue-xxx-xsrf-whitelist
branch
from
October 26, 2017 08:16
d1ddb6f to
11794f8
Compare
Contributor
Author
|
jenkins, test this |
azasypkin
force-pushed
the
issue-xxx-xsrf-whitelist
branch
from
November 2, 2017 10:42
11794f8 to
34afb7e
Compare
azasypkin
force-pushed
the
issue-xxx-xsrf-whitelist
branch
from
November 3, 2017 11:46
34afb7e to
6ddcbfd
Compare
Contributor
Author
|
We should probably only merge this PR once ES SAML support and https://github.com/elastic/x-pack-kibana/pull/1752 are merged into master, but it's ready for review nevertheless @kjbekkelund |
azasypkin
force-pushed
the
issue-xxx-xsrf-whitelist
branch
from
November 23, 2017 12:16
6ddcbfd to
8d41d90
Compare
Contributor
Author
|
jenkins, test this |
kimjoar
approved these changes
Nov 24, 2017
azasypkin
added a commit
to azasypkin/kibana
that referenced
this pull request
Jan 29, 2018
azasypkin
added a commit
to azasypkin/kibana
that referenced
this pull request
Jan 29, 2018
Contributor
Author
patrykkopycinski
pushed a commit
to patrykkopycinski/kibana
that referenced
this pull request
May 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR adds simple white-list for the paths that should not apply CSRF check.