Skip to content
Grav 2.0 is officially stable. Read the announcement →
Archive

Security in admin plugin

Started by Muut Archive 11 years ago · 3 replies · 277 views
11 years ago

I saw in your blog post you are getting close to version 1.0, congratulations.

I was just wondering if there were any plans to look at security of the admin plugin before the release? In particular CSRF and XSS would seem to be risks once you have a privileged user performing actions via a web interface.

11 years ago

I'm sure we'll add CSRF tokens in time for form submissions. XSS and content injection also.

11 years ago

Great to hear! I did a bit of experimentation using symfony's security-csrf package and got a proof of concept working but ran into a few problems with the tokens being saved to the header of pages. I can send you a branch with my progress if it would be helpful.

11 years ago

sure.. any help there would be appreciated

Suggested topics

Topic Participants Replies Views Activity
Archive · by Deleted User, 9 years ago
0 1338 9 years ago
Archive · by Muut Archive, 9 years ago
2 927 9 years ago
Archive · by Muut Archive, 9 years ago
2 4056 9 years ago
Archive · by Muut Archive, 9 years ago
1 2941 9 years ago
Archive · by Muut Archive, 9 years ago
3 1112 9 years ago