On 04/11/13 14:52, Andrea Aime wrote: > On Mon, Nov 4, 2013 at 4:34 AM, Ben Caradoc-Davies > <[email protected] <mailto:[email protected]>> wrote: > Why is JSONP disabled by default? > Security/CSRF concerns? As JSONP is an outputformat, I do not see how > enabling it provides any greater risk of CSRF than JSON output. Perhaps > someone more familiar could shed some light. > Ben, > if you search in the archives I believe there was a discussion between > Carlo and > Tim about it
Thanks, Andrea, I found it. Tim gives a hypothetical example of data stealing using CSRF: http://osgeo-org.1560.x6.nabble.com/GSIP-79-Json-support-and-WFS-and-WMS-ExceptionHandler-s-tp4999973p5000874.html Carlo then disabled JSONP by default. Kind regards, -- Ben Caradoc-Davies <[email protected]> Software Engineer CSIRO Earth Science and Resource Engineering Australian Resources Research Centre ------------------------------------------------------------------------------ Android is increasing in popularity, but the open development platform that developers love is also attractive to malware creators. Download this white paper to learn more about secure code signing practices that can help keep Android apps secure. http://pubads.g.doubleclick.net/gampad/clk?id=65839951&iu=/4140/ostg.clktrk _______________________________________________ Geoserver-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/geoserver-devel
