HomePhabricator

Support CSRF for logged-out users

Description

Support CSRF for logged-out users

Summary: Fixes T4339. If you're anonymous, we use a digest of your session key to generate a CSRF token. Otherwise, everything works normally.

Test Plan: Logged out, logged in, tweaked CSRF in forms -- I'll add some inlines.

Reviewers: btrahan

Reviewed By: btrahan

CC: aran

Maniphest Tasks: T4339

Differential Revision: https://secure.phabricator.com/D8046

Details

Provenance
epriestleyAuthored on
epriestleyPushed on Jan 23 2014, 10:03 PM
Reviewer
btrahan
Differential Revision
D8046: Support CSRF for logged-out users
Parents
rP24544b1a2f24: Straighten out absolute/relative URIs in login providers
Branches
Unknown
Tags
Unknown
Tasks
T4339: Support CSRF for logged-out users

Event Timeline