Mercurial > p > roundup > code
annotate website/issues/html/query.item.html @ 6681:ab2ed11c021e
issue2551205: Add support for specifying valid origins for api: xmlrpc/rest
We now have an allow list to filter the hosts allowed to do api
requests. An element of this allow list must match the http ORIGIN
header exactly or the rest/xmlrpc CORS request will result in an
error.
The tracker host is always allowed to do a request.
| author | John Rouillard <rouilj@ieee.org> |
|---|---|
| date | Tue, 17 May 2022 17:18:51 -0400 |
| parents | 578b5294e888 |
| children |
| rev | line source |
|---|---|
|
4024
c2d0d3e9099d
svn repository setup
Stefan Seefeld <stefan@users.sourceforge.net>
parents:
diff
changeset
|
1 <!-- query.item --> |
|
5286
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
2 <span tal:condition="context/is_view_ok" tal:replace="structure |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
3 context/renderQueryForm" /> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
4 <tal:block tal:condition="not:context/is_view_ok"> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
5 <tal:block metal:use-macro="templates/page/macros/icing"> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
6 <title metal:fill-slot="head_title">You can not view query</title> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
7 <tal:block metal:fill-slot="body_title"> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
8 You can not view query. |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
9 </tal:block> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
10 <td class="content" metal:fill-slot="content"> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
11 You are not allowed to view <span tal:content="context/_classname"/> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
12 with id <span tal:content="context/id"/> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
13 </td> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
14 </tal:block> |
|
578b5294e888
Update to current classic config. Fixes issue with users being able to
John Rouillard <rouilj@ieee.org>
parents:
4024
diff
changeset
|
15 </tal:block> |
