[MGNLGQL-101] GraphQL POST requests fail due to CSRF security Created: 06/Jul/21 Updated: 18/Oct/21 Resolved: 13/Jul/21 |
|
| Status: | Closed |
| Project: | Magnolia GraphQL |
| Component/s: | None |
| Affects Version/s: | None |
| Fix Version/s: | 1.0.1 |
| Type: | Bug | Priority: | Critical |
| Reporter: | Christopher Zimmermann | Assignee: | Michael Duerig |
| Resolution: | Fixed | Votes: | 0 |
| Labels: | csrf | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Issue Links: |
|
||||||||||||
| Template: |
|
||||||||||||
| Acceptance criteria: |
Empty
|
||||||||||||
| Task DoD: |
[X]*
Doc/release notes changes? Comment present?
[X]*
Downstream builds green?
[X]*
Solution information and context easily available?
[X]*
Tests
[X]*
FixVersion filled and not yet released
[ ] 
Architecture Decision Record (ADR)
|
||||||||||||
| Bug DoR: |
[X]*
Steps to reproduce, expected, and actual results filled
[X]*
Affected version filled
|
||||||||||||
| Date of First Response: | |||||||||||||
| Description |
|
POST requests to GraphQL endpoint get 403 security issues. Notes Workaround - Developer note from Rico: 'BypassGraphQL': Implications One implication is that this breaks the Tour Finder on the demo project and on the hosted demo: https://jira.magnolia-cms.com/browse/MGNLDEMO-376 Fix The implemented fix adds a bypass for the CRSF token check by allowing requests to /.graphql without checking the CSRF token. |
| Comments |
| Comment by Michael Duerig [ 13/Jul/21 ] |
|
For RN: Allow GraphQL to bypass the CRSF token check |