Files
heritrix3/engine
Alex Osborne 7939d0d7e1 Reject cross-site requests to the web UI
Add CrossSiteRequestFilter in front of the web UI's router to protect
against cross-site request forgery. POST, PUT and DELETE requests are
rejected with 403 when the browser's Sec-Fetch-Site header says they
came from another site.

Sec-Fetch-Site is set by the browser from its own view of the page and
target URL, so unlike comparing Origin with Host it isn't affected by
reverse proxies rewriting the host or scheme. Requests without the
header, such as from curl and other API clients, are allowed.

Origins listed in the heritrix.trustedOrigins system property (comma
separated) are allowed to send cross-site requests.
2026-10-06 12:21:40 +09:00
..