Uploaded image for project: 'Nuxeo Documentation'
  1. Nuxeo Documentation
  2. NXDOC-1564

Fix nuxeo-dev-tools incompatible out of the box with new CSRF policy on FireFox

    XMLWordPrintable

    Details

      Description

      Since CSRF policy was tightened, il is necessary on a development environment, when using the nuxeo dev tools browsers extension, to loosen the default CSRF policy, otherwise the following messages appear on the platform console and server.log:

      2018-04-09 09:35:38,005 WARN  [NuxeoCorsCsrfFilter] CSRF check failure: source: moz-extension://b168a0e9-b1e5-4f9c-adef-77cbb980e2be does not match target: http://localhost:8080/ and not allowed by CORS config
      2018-04-09 09:35:38,050 WARN  [NuxeoCorsCsrfFilter] CSRF check failure: source: moz-extension://b168a0e9-b1e5-4f9c-adef-77cbb980e2be does not match target: http://localhost:8080/ and not allowed by CORS config
      2018-04-09 09:35:38,075 WARN  [NuxeoCorsCsrfFilter] CSRF check failure: source: moz-extension://b168a0e9-b1e5-4f9c-adef-77cbb980e2be does not match target: http://localhost:8080/ and not allowed by CORS config
      

      and the nuxeo-dev-tools says: "No Studio package found!"

      A "correct" CSRF for nuxeo-dev-tools (stricter than just opening everything) should be documented for this particular case.

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - 0 minutes
                  0m
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 hour, 20 minutes
                  1h 20m