Skip to content

Releases: qld-gov-au/ckanext-csrf-filter

Reduce noisy logging

01 Jun 02:01
2a44ce5
Compare
Choose a tag to compare
Merge pull request #13 from qld-gov-au/develop

Develop to main

Add optional protection against Login CSRF

31 May 03:02
daaab58
Compare
Choose a tag to compare

Add a Repoze plugin that can be used to check tokens when logging in, replacing FriendlyForm. This plugin needs to be configured separately, eg in who.ini.

Disable response pass-through

13 May 22:40
a139c2c
Compare
Choose a tag to compare

We need to disable Flask response pass-through mode so that we can inject tokens into the response body. This will have a performance impact but is necessary for CKAN 2.9.

Initial release

10 May 06:43
d061631
Compare
Choose a tag to compare

CSRF filter based on a mixture of Double Submit Cookie and HMAC Based Token patterns.

Protects HTML-based forms and some types of JavaScript-based interaction, with no code changes required.

Does not protect API calls or prevent Login CSRF.