-
Feature Request
-
Resolution: Done
-
L3 - Default
-
None
- given:
- I log in to Optimize
- when:
- In another tab I click on a link that contains a forged request to Optimize, which would perform an action that I don't want to perform, e.g. deleting a report.
- then:
- the forged request is not being executed
- such that:
- Optimize only performs actions that I authorized it to do and attackers acan't force me to execute unwanted actions
AT:
- Optimize is protected against CSRF attacks
- There is a security notice informing users that the Optimize 2.5 contains a protection mechanism agains CSRF attacks
This is the controller panel for Smart Panels app
1.
|
Add CSRF-Protection | Done | Unassigned | |
2.
|
Store csrf session token in front-end | Done | Unassigned | |
3.
|
Write security notice about CRSF protection | Done | Unassigned |
Protect Optimize from CSRF attacks
-
Feature Request
-
Resolution: Done
-
L3 - Default
-
None
- given:
- I log in to Optimize
- when:
- In another tab I click on a link that contains a forged request to Optimize, which would perform an action that I don't want to perform, e.g. deleting a report.
- then:
- the forged request is not being executed
- such that:
- Optimize only performs actions that I authorized it to do and attackers acan't force me to execute unwanted actions
AT:
- Optimize is protected against CSRF attacks
- There is a security notice informing users that the Optimize 2.5 contains a protection mechanism agains CSRF attacks
This is the controller panel for Smart Panels app
- is related to
-
OPT-1929 Add CSRF-Protection
- Done
1.
|
Add CSRF-Protection | Done | Unassigned | |
2.
|
Store csrf session token in front-end | Done | Unassigned | |
3.
|
Write security notice about CRSF protection | Done | Unassigned |