[GH-ISSUE #246] Modoboa doesn't use csrf token #231

Closed
opened 2026-02-27 11:10:43 +03:00 by kerem · 1 comment
Owner

Originally created by @tonioo on GitHub (Dec 4, 2013).
Original GitHub issue: https://github.com/modoboa/modoboa/issues/246

Originally assigned to: @tonioo on GitHub.

Originally created by Patrick Hetu on 2012-04-17T18:27:26Z

Since emails could hold sensitive data, I would suggest that you add the token to your form and activate the middleware to prevent Cross site request forgery attack.

Originally created by @tonioo on GitHub (Dec 4, 2013). Original GitHub issue: https://github.com/modoboa/modoboa/issues/246 Originally assigned to: @tonioo on GitHub. **Originally created by Patrick Hetu on 2012-04-17T18:27:26Z** Since emails could hold sensitive data, I would suggest that you add the token to your form and activate the middleware to prevent Cross site request forgery attack.
kerem 2026-02-27 11:10:43 +03:00
  • closed this issue
  • added the
    bug
    label
Author
Owner

@tonioo commented on GitHub (Dec 4, 2013):

Posted by Antoine Nguyen on 2012-04-18T20:23:14Z

You're right, Modoboa needs this kind of protection.

The problem is I need to update all forms :D, I'll do it after the 0.9.

<!-- gh-comment-id:29814377 --> @tonioo commented on GitHub (Dec 4, 2013): **Posted by Antoine Nguyen on 2012-04-18T20:23:14Z** You're right, Modoboa needs this kind of protection. The problem is I need to update all forms :D, I'll do it after the 0.9.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/modoboa-modoboa#231
No description provided.