OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cmis-browser message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [cmis-browser] cross-site request forgery attacks


Has there been any discussion about providing for server defenses against cross-site request forgery attacks?
The only thing I could find is this comment from Derek in an old email thread, http://lists.oasis-open.org/archives/cmis/200905/msg00036.html:

> scenarios.  There are some issues that we as a TC would need to resolve if
> we introduce a multi-part POST endpoint to support document upload/edit
> specifically around introducing mechanisms to prevent CSRF attack vectors.


If the topic is still open, I'd like to spend a few minutes on it in the next meeting.

Regards,
Scott



  Scott Malabarba

 Software Engineer
 IBM Enterprise Content Management
 3565 Harbor Blvd., Costa Mesa, CA 92626-1420
 Phone (714) 327-5133 / Tieline 3955133
 Email scott.malabarba@us.ibm.com




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]