<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: enable Alfresco-CSRF-Token in alfresco in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20211#M8956</link>
    <description>&lt;P&gt;Hi &lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/7593"&gt;@bhargav_vempall&lt;/A&gt; did you find how to set cookie to httpOnly flag. If u have done please help me in doing the same.&lt;/P&gt;&lt;P&gt;Waiting for your reply.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Aug 2020 11:06:32 GMT</pubDate>
    <dc:creator>akash251998</dc:creator>
    <dc:date>2020-08-13T11:06:32Z</dc:date>
    <item>
      <title>enable Alfresco-CSRF-Token in alfresco</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20206#M8951</link>
      <description>Hi,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;My alfresco application&amp;nbsp;is working as expected.&amp;nbsp;But my security guy has found&amp;nbsp;out that the alfresco site is&amp;nbsp;has CSRF&amp;nbsp;vulnerable.&amp;nbsp;Our application is configured using CAS&amp;nbsp;for login and&amp;nbsp;works through proxy server. I did not Specifically configure CSRF filter.&amp;nbsp;Please&amp;nbsp;help me&amp;nbsp;fix this CSRF vulne</description>
      <pubDate>Mon, 13 Nov 2017 18:55:15 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20206#M8951</guid>
      <dc:creator>bhargav_vempall</dc:creator>
      <dc:date>2017-11-13T18:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: enable Alfresco-CSRF-Token in alfresco</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20207#M8952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know all the configuration you need for CRSF is in the&amp;nbsp;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;share-security-config.xml.&amp;nbsp;&lt;/SPAN&gt;You will find a section&amp;nbsp;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;config evaluator="string-compare" condition="CSRFPolicy"&amp;gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can copy the content in the &lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;share-custom-config.xml &lt;/SPAN&gt;and change the multiple Referers ans Origins.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which version of alfresco you have?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source:&amp;nbsp;&lt;A class="link-titled" href="http://docs.alfresco.com/5.2/concepts/csrf-policy.html" title="http://docs.alfresco.com/5.2/concepts/csrf-policy.html" rel="nofollow noopener noreferrer"&gt;Cross-Site Request Forgery (CSRF) filters | Alfresco Documentation&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 07:52:48 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20207#M8952</guid>
      <dc:creator>gluck113</dc:creator>
      <dc:date>2017-11-14T07:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: enable Alfresco-CSRF-Token in alfresco</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20208#M8953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the version I have seen in my alfresco readme file.&lt;/P&gt;&lt;P&gt;Contains:&lt;BR /&gt;&amp;nbsp;- Alfresco Platform:&amp;nbsp;5.2.g&lt;BR /&gt;&amp;nbsp;- Alfresco Share:&amp;nbsp;&amp;nbsp;5.2.f&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen this document you sent me, but what should I change is the question I have modified the following&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My issue here is to set the Alfresco-CSRFToken cookie to secure and Httponly.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 15:05:09 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20208#M8953</guid>
      <dc:creator>bhargav_vempall</dc:creator>
      <dc:date>2017-11-14T15:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: enable Alfresco-CSRF-Token in alfresco</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20209#M8954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So in your tomcat folder of your installation go to the following path &lt;SPAN class=""&gt;shared/classes/alfresco/web-extension/ &lt;/SPAN&gt;and you should find a shared-config-custom.xml. In this file you should copy the section I mentionned in my earlier reply (&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;config evaluator="string-compare" condition="CSRFPolicy"&amp;gt;&lt;/SPAN&gt; ).&lt;/P&gt;&lt;P&gt;The origin and referer should be the dns of your server if the share and alfresco applications are deployed on the same server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More information on origin and referer in http request:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet#Checking_the_Origin_Header" title="https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet#Checking_the_Origin_Header" rel="nofollow noopener noreferrer"&gt;Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet - OWASP&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Otherwise ask your security guy what you should put as values. Then you need to restart tomcat and he can check directly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 20:33:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20209#M8954</guid>
      <dc:creator>gluck113</dc:creator>
      <dc:date>2017-11-15T20:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: enable Alfresco-CSRF-Token in alfresco</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20210#M8955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Simon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I did change the "The origin and referer should be the dns of your server" in shared-config-custom.xml it still did not work. Still my &lt;STRONG&gt;Alfresco-CSRFToken cookie is not set to secure and Httponly in the firefox firebug cookie column. &lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 21:07:56 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20210#M8955</guid>
      <dc:creator>bhargav_vempall</dc:creator>
      <dc:date>2017-11-15T21:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: enable Alfresco-CSRF-Token in alfresco</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20211#M8956</link>
      <description>&lt;P&gt;Hi &lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/7593"&gt;@bhargav_vempall&lt;/A&gt; did you find how to set cookie to httpOnly flag. If u have done please help me in doing the same.&lt;/P&gt;&lt;P&gt;Waiting for your reply.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 11:06:32 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/enable-alfresco-csrf-token-in-alfresco/m-p/20211#M8956</guid>
      <dc:creator>akash251998</dc:creator>
      <dc:date>2020-08-13T11:06:32Z</dc:date>
    </item>
  </channel>
</rss>

