hydra/src
Eelco Dolstra c928c41ee1 Add XSRF protection for POST requests
Some Hydra API requests were vulnerable to XSRF attacks, e.g. you
could have a form on another website using http://hydra/logout as the
form action. So we now require POST requests to come from the same
origin.

Reported by Hans-Christian Esperer.
2016-10-20 16:11:33 +02:00
..
hydra-eval-jobs hydra-eval-jobs: Fix build 2016-10-06 15:05:05 +02:00
hydra-evaluator Concurrent hydra-evaluator 2016-10-14 14:22:12 +02:00
hydra-queue-runner Concurrent hydra-evaluator 2016-10-14 14:22:12 +02:00
lib Add XSRF protection for POST requests 2016-10-20 16:11:33 +02:00
libhydra Concurrent hydra-evaluator 2016-10-14 14:22:12 +02:00
root Remove Persona support 2016-10-20 14:14:04 +02:00
script Remove Persona support 2016-10-20 14:14:04 +02:00
sql Remove Persona support 2016-10-20 14:14:04 +02:00
ttf Add font for the captcha 2013-03-04 12:16:13 +01:00
xsl Fix UTF-8 handling of log files 2014-08-13 18:53:29 +02:00
Makefile.am Concurrent hydra-evaluator 2016-10-14 14:22:12 +02:00
Makefile.PL * Move everything up one directory. 2009-03-05 13:41:57 +00:00