Uploaded image for project: 'Magnolia Multisite Module'
  1. Magnolia Multisite Module
  2. MULTISITE-44

Review default bypasses for CrossSiteSecurityFilter

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • None
    • Yes

      Up until Magnolia 5.3, /.resources was used only for admincentral resources. Presumably, that's why CrossSiteSecurityFilter is configured by default with a bypass for this path.
      Starting with 5.4 and resources module 2.4, /.resources will be used to serve resources (through ResourcesServlet and new ResourcePath API). Maybe we need to change the default bypass to make this more visible to users upgrading ? And/or simply document this ?

        Acceptance criteria

              Unassigned Unassigned
              gjoseph Magnolia International
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:

                  Task DoR