-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
Closed
Labels
1. to developAccepted and waiting to be taken care ofAccepted and waiting to be taken care ofenhancementfeature: authenticationfeature: davgood first issueSmall tasks with clear documentation about how and in which place you need to fix things in.Small tasks with clear documentation about how and in which place you need to fix things in.security
Description
In the file /apps/dav/lib/Connector/Sabre/Auth Line 173 (Function requiresCSRFCheck) we skip CSRF checks only for GET requests. Why not for HEAD requests?
I mean a HEAD request is a GET request without the BODY:
Can we add a the HEAD method here too? If yes I can create a pull request if you want.
Metadata
Metadata
Assignees
Labels
1. to developAccepted and waiting to be taken care ofAccepted and waiting to be taken care ofenhancementfeature: authenticationfeature: davgood first issueSmall tasks with clear documentation about how and in which place you need to fix things in.Small tasks with clear documentation about how and in which place you need to fix things in.security