Uploaded image for project: 'Help-Desk'
  1. Help-Desk
  2. HELP-13462

[fiware-stackoverflow] CSRF implementation in core CKAN code

    Details

    • Type: Monitor
    • Status: Closed
    • Priority: Major
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: 2021
    • Component/s: FIWARE-TECH-HELP
    • Labels:

      Description

      Created question in FIWARE Q/A platform on 12-02-2018 at 15:02
      Please, ANSWER this question AT https://stackoverflow.com/questions/48748288/csrf-implementation-in-core-ckan-code

      Question:
      CSRF implementation in core CKAN code

      Description:
      This extension to CKAN could work to provide security features in CKAN. This extension provides Cookie-based CSRF protection for requests in CKAN. But according to this , it is not implemented as a part of core CKAN because the method used in this extension to provide CSRF protection is conflicting with the future plan of CKAN's own implementation of CSRF protection.

      So, my question is
      1. Is there any implementation of CSRF protection in core CKAN code?
      2. What are different methods we can use to implement CSRF protection and what is the best method to implement it in core CKAN?

        Activity

        fla Fernando Lopez made changes -
        Fix Version/s 2021 [ 12600 ]
        veronika Veronika Vlnkova made changes -
        Resolution Done [ 10000 ]
        Status Answered [ 10104 ] Closed [ 6 ]
        veronika Veronika Vlnkova made changes -
        HD-Enabler CKAN [ 10870 ]
        backlogmanager Backlog Manager made changes -
        Status In Progress [ 3 ] Answered [ 10104 ]
        backlogmanager Backlog Manager made changes -
        Status Open [ 1 ] In Progress [ 3 ]
        veronika Veronika Vlnkova made changes -
        Assignee Francisco de la Vega [ fdelavega ]
        backlogmanager Backlog Manager made changes -
        Field Original Value New Value
        Component/s FIWARE-TECH-HELP [ 10278 ]
        backlogmanager Backlog Manager created issue -

          People

          • Assignee:
            fdelavega Francisco de la Vega
            Reporter:
            backlogmanager Backlog Manager
          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: