On 04/11/13 14:52, Andrea Aime wrote:
> On Mon, Nov 4, 2013 at 4:34 AM, Ben Caradoc-Davies
> <[email protected] <mailto:[email protected]>> wrote:
>     Why is JSONP disabled by default?
>     Security/CSRF concerns? As JSONP is an outputformat, I do not see how
>     enabling it provides any greater risk of CSRF than JSON output. Perhaps
>     someone more familiar could shed some light.
> Ben,
> if you search in the archives I believe there was a discussion between
> Carlo and
> Tim about it

Thanks, Andrea, I found it. Tim gives a hypothetical example of data 
stealing using CSRF:
http://osgeo-org.1560.x6.nabble.com/GSIP-79-Json-support-and-WFS-and-WMS-ExceptionHandler-s-tp4999973p5000874.html

Carlo then disabled JSONP by default.

Kind regards,

-- 
Ben Caradoc-Davies <[email protected]>
Software Engineer
CSIRO Earth Science and Resource Engineering
Australian Resources Research Centre

------------------------------------------------------------------------------
Android is increasing in popularity, but the open development platform that
developers love is also attractive to malware creators. Download this white
paper to learn more about secure code signing practices that can help keep
Android apps secure.
http://pubads.g.doubleclick.net/gampad/clk?id=65839951&iu=/4140/ostg.clktrk
_______________________________________________
Geoserver-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Reply via email to