Issue/REST-410 check all mutative methods

Merged
#177 · Created  · Last updated

Merged pull request

Merged in issue/REST-410-block-remote-post-method-restriction (pull request #177)

394c58e·Author: ·Closed by: ·2018-09-27

Description

  • REST-410: Block all mutative requests not just POST requests (instead of logging non-post but mutative requests) in OriginBasedXsrfResourceFilter.

    Signed-off-by: David Black dblack@atlassian.com

  • REST-410: Add tests to cover non-simple requests coming with the same origin are not blocked by OriginBasedXsrfResourceFilter.

    Signed-off-by: David Black dblack@atlassian.com

0 attachments

0 comments

Loading commits...