Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cross-site request forgery.

I should add though that even if this thing gets an XSRF token and it's secure, you might as well take the passwords off your SSH keys if you're running this, because you're coughing up an unprotected remote shell to anyone who can talk to a dev server once you turn this on.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: