Uploaded image for project: 'Magnolia'
  1. Magnolia
  2. MAGNOLIA-8232

Intercept login redirects to reduce bypasses for the login-CSRF filter

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Unresolved
    • Icon: Neutral Neutral
    • None
    • None
    • core

      There is a number of configured bypasses for the CSRFTokenFilter. Within MAGNOLIA-8210 mgeljic brought up the idea to intercept login redirects for getting rid of some of these bypasses. Within this ticket we should:

      • Clarify the approach envisioned by mgeljic
      • Implement a POC
      • Productise the POC if it bring enough value

      Implementation note: may we can use security callbacks?

        Acceptance criteria

              mduerig Michael Duerig
              mduerig Michael Duerig
              Foundation
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:

                  Task DoD