mirror of https://github.com/TriliumNext/Notes
fix(csrf): stop leaking the CSRF token in the server logs
As per OWASP: "A CSRF token must not be leaked in the server logs or in the URL.", see: https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#transmissing-csrf-tokens-in-synchronized-patternspull/961/head
parent
283a12b0d5
commit
ec19ccd7a7
Loading…
Reference in New Issue