bamaer opened a new pull request, #8390:
URL: https://github.com/apache/hop/pull/8390

   The servlets answer state-changing operations on GET, so a page an operator 
is visiting could drive them with the operator's browser and credentials. 
Origin is no defence: browsers omit it on cross-site GET.
   
   A CrossSitePolicy keyed on Sec-Fetch-Site is applied in both places the 
servlets are deployed: a Jetty handler wrapped around every context in 
WebServer (ahead of authentication, covering both the auth-enabled and 
auth-disabled branches), and a servlet filter mapped on /hop/* in Hop Web, 
which co-deploys the same servlets outside WebServer. Cross-site top-level 
navigations are rejected too; the usual carve-out assumes a GET navigation is 
safe, which is what does not hold here.
   
   Requests carrying no Sec-Fetch-* headers at all (hop-run, the Hop GUI, curl, 
automation) are always allowed, so existing integrations are unaffected. The 
default same-site policy also allows another host of the same registrable 
domain; same-origin is stricter and off disables the check. Configured with 
--cross-site-policy / HOP_SERVER_CROSS_SITE_POLICY on hop-server, and in Hop 
Web via Configuration -> Security -> General, security-config.json, or the same 
environment variable.
   
   Constraining the ExecPipelineServlet VFS path is tracked separately in #8373.
   
   **Please** add a meaningful description for your change here
   
   ------------------------
   
   Thank you for your contribution! Follow this checklist to help us 
incorporate your contribution quickly and easily:
   - [x] Run `mvn clean install apache-rat:check` to make sure basic checks 
pass. A more thorough check will be performed on your pull request 
automatically.
   - [x] If you have a group of commits related to the same change, please 
squash your commits into one and force push your branch using `git rebase -i`.
   - [x] Mention the appropriate issue in your description (for example: 
`addresses #123`), if applicable.
   
   To make clear that you license your contribution under the [Apache License 
Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0)
   you have to acknowledge this by using the following check-box.
   
   - [x] I hereby declare this contribution to be licensed under the [Apache 
License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0)
   - [ ] In any other case, please file an [Apache Individual Contributor 
License Agreement](https://www.apache.org/licenses/icla.pdf).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to