Uploaded image for project: 'Help-Desk'
  1. Help-Desk
  2. HELP-13462

[fiware-stackoverflow] CSRF implementation in core CKAN code

    Details

    • Type: Monitor
    • Status: Closed
    • Priority: Major
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: 2021
    • Component/s: FIWARE-TECH-HELP
    • Labels:

      Description

      Created question in FIWARE Q/A platform on 12-02-2018 at 15:02
      Please, ANSWER this question AT https://stackoverflow.com/questions/48748288/csrf-implementation-in-core-ckan-code

      Question:
      CSRF implementation in core CKAN code

      Description:
      This extension to CKAN could work to provide security features in CKAN. This extension provides Cookie-based CSRF protection for requests in CKAN. But according to this , it is not implemented as a part of core CKAN because the method used in this extension to provide CSRF protection is conflicting with the future plan of CKAN's own implementation of CSRF protection.

      So, my question is
      1. Is there any implementation of CSRF protection in core CKAN code?
      2. What are different methods we can use to implement CSRF protection and what is the best method to implement it in core CKAN?

        Activity

        Hide
        backlogmanager Backlog Manager added a comment -

        2018-02-12 15:05|CREATED monitor | # answers= 0, accepted answer= False

        Show
        backlogmanager Backlog Manager added a comment - 2018-02-12 15:05|CREATED monitor | # answers= 0, accepted answer= False
        Hide
        backlogmanager Backlog Manager added a comment -

        2018-02-12 21:05|UPDATED status: transition Answer| # answers= 1, accepted answer= False

        Show
        backlogmanager Backlog Manager added a comment - 2018-02-12 21:05|UPDATED status: transition Answer| # answers= 1, accepted answer= False
        Hide
        backlogmanager Backlog Manager added a comment -

        2018-02-13 00:05|UPDATED status: transition Answered| # answers= 1, accepted answer= False

        Show
        backlogmanager Backlog Manager added a comment - 2018-02-13 00:05|UPDATED status: transition Answered| # answers= 1, accepted answer= False

          People

          • Assignee:
            fdelavega Francisco de la Vega
            Reporter:
            backlogmanager Backlog Manager
          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: