mirror of
https://github.com/internetarchive/heritrix3.git
synced 2026-10-09 22:01:47 +00:00
Add CrossSiteRequestFilter in front of the web UI's router to protect against cross-site request forgery. POST, PUT and DELETE requests are rejected with 403 when the browser's Sec-Fetch-Site header says they came from another site. Sec-Fetch-Site is set by the browser from its own view of the page and target URL, so unlike comparing Origin with Host it isn't affected by reverse proxies rewriting the host or scheme. Requests without the header, such as from curl and other API clients, are allowed. Origins listed in the heritrix.trustedOrigins system property (comma separated) are allowed to send cross-site requests.