Skip to content

Reject API requests with header Sec-Fetch-Site: cross-site #10431

@Al2Klimov

Description

@Al2Klimov

Is your feature request related to a problem? Please describe.

Our API doesn't protect GETs against CSRF to make it working in a browser.

Describe the solution you'd like

Modern browsers even indicate CSRFs, setting Sec-Fetch-Site to cross-site. Simply listen to the browser!

Describe alternatives you've considered

Do nothing.

Additional context

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions