Mercurial > p > roundup > code
view roundup/cgi/PageTemplates/README.txt @ 7155:89a59e46b3af
improve REST interface security
When using REST, we reflect the client's origin. If the wildcard '*'
is used in allowed_api_origins all origins are allowed. When this is
done, it also added an 'Access-Control-Allow-Credentials: true'
header.
This Credentials header should not be added if the site is matched
only by '*'. This header should be provided only for explicit origins
(e.g. https://example.org) not for the wildcard.
This is now fixed for CORS preflight OPTIONS request as well as normal
GET, PUT, DELETE, POST, PATCH and OPTIONS requests.
A missing Access-Control-Allow-Credentials will prevent the tracker
from being accessed using credentials. This prevents an unauthorized
third party web site from using a user's credentials to access
information in the tracker that is not publicly available.
Added test for this specific case.
In addition, allowed_api_origins can include explicit origins in
addition to '*'. '*' must be first in the list.
Also adapted numerous tests to work with these changes.
Doc updates.
| author | John Rouillard <rouilj@ieee.org> |
|---|---|
| date | Thu, 23 Feb 2023 12:01:33 -0500 |
| parents | b9988e118055 |
| children |
line wrap: on
line source
See <a href="http://dev.zope.org/Wikis/DevSite/Projects/ZPT">the ZPT project Wiki</a> for more information about Page Templates, or <a href="http://www.zope.org/Members/4am/ZPT">the download page</a> for installation instructions and the most recent version of the software. This Product requires the TAL and ZTUtils packages to be installed in your Python path (not Products). See the links above for more information.
