Details
-
Task
-
Resolution: Unresolved
-
Major
-
Unknown
-
Description
And explain the XWiki strategy, i.e. when we use CSRF protection and when we don't (we might need to agree about this first ).
Example: Have CSRF protection whenever there are forms which modify things in XWiki. Don't add CSRF protection for forms that don't modify things (such as XAR export).
Also need to update https://www.xwiki.org/xwiki/bin/view/Documentation/AdminGuide/Security#HCrosssiterequestforgery28CSRF29 which is completely wrong...