aboutsummaryrefslogtreecommitdiffstats
path: root/templates/base/head.tmpl
diff options
context:
space:
mode:
authorLunny Xiao <xiaolunwen@gmail.com>2022-12-30 08:08:16 +0800
committerGitHub <noreply@github.com>2022-12-30 02:08:16 +0200
commit8cd6be1723473f55e50073b9e23deb9c37295bee (patch)
treec3e940dbfc707759e8d80fab5a7b694bb363e1bc /templates/base/head.tmpl
parentf8827472096567c31fa47237cfbe2397d4228591 (diff)
downloadgitea-8cd6be1723473f55e50073b9e23deb9c37295bee.tar.gz
gitea-8cd6be1723473f55e50073b9e23deb9c37295bee.zip
Remove ReverseProxy authentication from the API (#22219) (#22252)
backport #22219 Since we changed the /api/v1/ routes to disallow session authentication we also removed their reliance on CSRF. However, we left the ReverseProxy authentication here - but this means that POSTs to the API are no longer protected by CSRF. Now, ReverseProxy authentication is a kind of session authentication, and is therefore inconsistent with the removal of session from the API. This PR proposes that we simply remove the ReverseProxy authentication from the API and therefore users of the API must explicitly use tokens or basic authentication. Replace #22077 Close #22221 Close #22077 Signed-off-by: Andrew Thornton <art27@cantab.net> Signed-off-by: Andrew Thornton <art27@cantab.net> Co-authored-by: zeripath <art27@cantab.net>
Diffstat (limited to 'templates/base/head.tmpl')
0 files changed, 0 insertions, 0 deletions