Skip to content

CsrfCounterMeasure: accept Sec-Fetch-Site header, if available, instead of token#299

Open
Al2Klimov wants to merge 1 commit into
mainfrom
Al2Klimov-patch-1
Open

CsrfCounterMeasure: accept Sec-Fetch-Site header, if available, instead of token#299
Al2Klimov wants to merge 1 commit into
mainfrom
Al2Klimov-patch-1

Conversation

@Al2Klimov
Copy link
Copy Markdown
Member

This is especially useful if the session and token change suddenly, e.g. due to mod_auth_openidc.

refs Icinga/icingaweb2#5224

@sukhwinder33445 sukhwinder33445 requested a review from nilmerg April 21, 2026 12:53
@Al2Klimov
Copy link
Copy Markdown
Member Author

Damn! I forgot d63c5a7...

@Al2Klimov Al2Klimov removed the request for review from nilmerg May 29, 2026 13:11
@Al2Klimov Al2Klimov marked this pull request as draft May 29, 2026 13:11
@Al2Klimov Al2Klimov self-assigned this May 29, 2026
…ad of token

This is especially useful if the session and token change suddenly, e.g. due to mod_auth_openidc.
@Al2Klimov Al2Klimov force-pushed the Al2Klimov-patch-1 branch from 2813a9c to f827db1 Compare May 29, 2026 13:12
@Al2Klimov Al2Klimov marked this pull request as ready for review May 29, 2026 13:12
@Al2Klimov Al2Klimov requested a review from TheSyscall May 29, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants