Details

    • PM Priority:
      60

      Description

      • given:
        • I log in to Optimize
      • when:
        • In another tab I click on a link that contains a forged request to Optimize, which would perform an action that I don't want to perform, e.g. deleting a report.
      • then:
        • the forged request is not being executed
      • such that:
        • Optimize only performs actions that I authorized it to do and attackers acan't force me to execute unwanted actions

      AT:

      • Optimize is protected against CSRF attacks
      • There is a security notice informing users that the Optimize 2.5 contains a protection mechanism agains CSRF attacks

        Issue Links

          Activity

          There are no comments yet on this issue.

            People

            • Assignee:
              Unassigned
              Reporter:
              felix.mueller Felix Müller
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: