Issue Type: Bug Bug
Assignee: Jesse Glick
Components: build-token-root-plugin
Created: 16/Nov/14 12:18 PM
Description:

Just like similar plugins, (e.g. GitHub and GitLab), the Build Token Root Plugin does not play nice whith CSRF protection enabled.
The root cause seems to be JENKINS-22474 (documented by Jesse Glick), but until that is fixed, the Build Token Root Plugin should probably add a CrumbExclusion for the URL it is listening on.
See JENKINS-20140 for a similar issue in the GitHub Plugin, that has been resolved.

Project: Jenkins
Labels: plugin csrf
Priority: Minor Minor
Reporter: kflorian
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira

--
You received this message because you are subscribed to the Google Groups "Jenkins Issues" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to