aws-samples / pcluster-manager

Manage AWS ParallelCluster through an easy to use web interface
https://pcluster.cloud
Apache License 2.0
65 stars 27 forks source link

Fetch and send CSRF token on every request #409

Closed mendaomn closed 1 year ago

mendaomn commented 1 year ago

Description

This PR implements the Double Submit Cookie strategy on the frontend to prevent CSRF attacks.

Changes

How Has This Been Tested?

References

PR Quality Checklist

In order to increase the likelihood of your contribution being accepted, please make sure you have read both the Contributing Guidelines and the Project Guidelines

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.