Files
freeipa/ipalib
Rob Crittenden 9f10fb20e9 Require an HTTP Referer header in the server. Send one in ipa tools.
This is to prevent a Cross-Site Request Forgery (CSRF) attack where
a rogue server tricks a user who was logged into the FreeIPA
management interface into visiting a specially-crafted URL where
the attacker could perform FreeIPA oonfiguration changes with the
privileges of the logged-in user.

https://bugzilla.redhat.com/show_bug.cgi?id=747710
2011-12-05 16:02:24 -05:00
..
2011-09-07 13:21:06 +02:00
2011-04-21 10:41:29 +02:00
2011-04-13 15:58:45 +02:00
2010-12-20 17:19:53 -05:00
2011-10-20 18:25:51 -04:00
2011-04-13 15:58:45 +02:00
2011-08-31 16:46:26 +02:00
2011-08-18 20:35:24 -04:00
2010-12-20 17:19:53 -05:00
2011-01-25 14:01:36 -05:00
2011-09-13 11:36:38 +02:00