Uploaded image for project: 'Ibexa IBX'
  1. Ibexa IBX
  2. IBX-5024

Session check endpoint for REST API should return a valid CSRF token

    XMLWordPrintable

Details

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 4.4.1
    • None
    • None
    • None

    Description

      Currently session check endpoint returns the same CSRF token as is used by the user in the headers.

      This means that it is unusable when user wants to simply acquire CSRF token for future requests, and it requires a full new login to acquire new CSRF token, if the previous one has timed out and/or become invalid - as we do not have any other endpoints that would allow us to get a new one.

      Designs

        Attachments

          Activity

            People

              Unassigned Unassigned
              pawel.niedzielski@ibexa.co Paweł Niedzielski
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: