freeipa/ipaserver
Rob Crittenden 2d6eeb205e Require an HTTP Referer header in the server. Send one in ipa tools.
This is to prevent a Cross-Site Request Forgery (CSRF) attack where
a rogue server tricks a user who was logged into the FreeIPA
management interface into visiting a specially-crafted URL where
the attacker could perform FreeIPA oonfiguration changes with the
privileges of the logged-in user.

https://bugzilla.redhat.com/show_bug.cgi?id=747710
2011-12-12 17:36:45 -05:00
..
install activate CLDAP 2011-12-06 08:29:53 -05:00
plugins ticket #1870 - subclass SimpleLDAPObject 2011-11-29 13:31:18 +01:00
__init__.py Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
conn.py Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
ipaldap.py Add connection failure recovery to IPAdmin 2011-12-08 14:58:18 +01:00
ipautil.py Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
rpcserver.py Require an HTTP Referer header in the server. Send one in ipa tools. 2011-12-12 17:36:45 -05:00