-
Notifications
You must be signed in to change notification settings - Fork 11
Use POST for logout (CSRF) #92
Copy link
Copy link
Open
Labels
backendImported from GitLab export mappingImported from GitLab export mappingbugSomething isn't workingSomething isn't workingfrontendImported from GitLab export mappingImported from GitLab export mappingsecuritySecurity-related issuesSecurity-related issues
Metadata
Metadata
Assignees
Labels
backendImported from GitLab export mappingImported from GitLab export mappingbugSomething isn't workingSomething isn't workingfrontendImported from GitLab export mappingImported from GitLab export mappingsecuritySecurity-related issuesSecurity-related issues
Source:
gitlab-issues-export.md(Issue 12)Weight: 3
Problem / context
LogoutHandleronly implementsget; a third party can trigger logout via crafted link (session inconvenience / mild DoS).Suggested approach / acceptance criteria
postwith XSRF where applicable; update templates/JS to POST logout.