From aae87ebffd9e50c467d9c41fda8a635b8223be3c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Piotr=20=C5=BBurek?= Date: Tue, 11 Oct 2022 12:05:35 +0200 Subject: [PATCH] PRODSEC-6550 Fix CSRF in the WebScript console Refresh Scripts form (#1483) --- .../alfresco/web-client-security-config.xml | 27 ++++++ packaging/war/src/main/webapp/WEB-INF/web.xml | 6 ++ .../extensions/webscripts/index.get.html.ftl | 82 +++++++++++++++++++ 3 files changed, 115 insertions(+) create mode 100644 remote-api/src/main/resources/alfresco/templates/webscripts/org/springframework/extensions/webscripts/index.get.html.ftl diff --git a/packaging/war/src/main/resources/alfresco/web-client-security-config.xml b/packaging/war/src/main/resources/alfresco/web-client-security-config.xml index 0d5362bd14..9098134659 100644 --- a/packaging/war/src/main/resources/alfresco/web-client-security-config.xml +++ b/packaging/war/src/main/resources/alfresco/web-client-security-config.xml @@ -139,6 +139,33 @@ {token} + + + GET + /s/index|/s/ + + + {token} + {token} + + + + + POST + /s/index|/s/ + + + {token} + {token} + + + {referer} + + + {origin} + + +