Skip to content

CSRF on token deletion endpoint missing #425

@phavekes

Description

@phavekes

This issue is imported from pivotal - Originaly created at Nov 6, 2023 by Peter Havekes

The endpoint
/recovery-token/delete/ does not require a valid CSRF token - deletion can be invoked via requests
initiated from other origins through prior knowledge of the UUID

Metadata

Metadata

Assignees

Type

No type

Projects

Status

Backlog

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions