Skip to content

CSRF for extensions #1253

@Wanabo

Description

@Wanabo

Currently I use two extensions:
xExtension-CustomCSS
xExtension-ImageProxy

Problem 1:
With both extentions I cannot manage the extension. I only can enable or disable them.
Providing input in CustomCSS or ImageProxy and saving causes a direct log out with a warning message:

Error 403 - Forbidden

You don’t have permission to access this page [HTTP_REFERER=https://www.nieuwskop.nl/p/i/?c=extension]
← Go back to your RSS feeds

Problem 2:
xExtension-ImageProxy only works when logged in, not for guests. But especially for my guests I want to get rid of insecure content warnings. :(

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions