Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add referer on post request for CSRF protection bypass issue #138 #142

Merged
merged 1 commit into from Jan 2, 2017

Conversation

spras
Copy link
Contributor

@spras spras commented Dec 23, 2016

I ran on issue #138 using jackrabbit 2.12.6

Tried to add Referer as proposed in the dissussion, it worked.

Here is my PR

@dbu dbu merged commit 25ee784 into jackalope:master Jan 2, 2017
@dbu
Copy link
Member

dbu commented Jan 2, 2017

thanks! i just noticed that the master branch is 1.3 and not yet released. there are a couple of things needed until we can release 1.3, mainly releasing jackalope/jackalope 1.3 and #132. its not that easy to release a 1.2 patch version because i would need to cherry-pick quite a few commits into a 1.2 branch for that, sorting out what should go in there and what not... are you using the dev version 1.3 currently?

@spras
Copy link
Contributor Author

spras commented Jan 2, 2017

you're right, i was working in sulu, which use the 1.2.2 version

@danrot
Copy link
Contributor

danrot commented Mar 6, 2017

@dbu Any roadmap about the 1.3 release? This change is a really big obstacle for new developer trying jackalope...

@dbu
Copy link
Member

dbu commented Mar 6, 2017

good point. currently master is failing on travis - i have to figure out why before i can tag a release. bumped my priority for this.

@dbu
Copy link
Member

dbu commented Apr 7, 2017

1.3.0 is now tagged!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants