Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
* Fix CSRF security issue * CSRF for tests * Disable CSRF for tests * Disable CSRF check on token login * Fix circular imports * Fix attribute * Enable csrf in tests * Revert some changes * Fixes * Fixes * Revert * csrf in api_client * csrf cookie * api_request * no_prefix for csrf request * csrf route without assets * Add additional call for csrf request * Add additional call_count for csrf request * Add additional call_count for csrf request * Add additional call_count for csrf request * exempt internal ml trainer apis * exempt tracking endpoints * Lock exceptiongroup version * Change endpoint for csrf token * Remove unneeded param * Cookie max-age * Linter * Add CSRF token handling through cookies (#202) * Fix CSRF security issue * CSRF for tests * Disable CSRF for tests * Disable CSRF check on token login * Fix circular imports * Fix attribute * Enable csrf in tests * Revert some changes * Fixes * Fixes * Revert * csrf in api_client * csrf cookie * api_request * no_prefix for csrf request * csrf route without assets * Add additional call for csrf request * Add additional call_count for csrf request * Add additional call_count for csrf request * Add additional call_count for csrf request * exempt internal ml trainer apis * exempt tracking endpoints * Lock exceptiongroup version * Change endpoint for csrf token * Remove unneeded param * Add CSRF token handling through cookies * Replace custom getCookie function with Quasar's Cookies Co-authored-by: Maor Katzav <maor.katzav@databand.ai> Co-authored-by: Maor Katzav <maor.katzav@ibm.com> * CR fixes * CR fixes * Comment * replace cy.request with custom cy.request that supports csrf token * fix for the request overwrite * remove cookie before login * Exempt seeding api * Linter * remove cookies on logout * remove token after invitation activation * don't remove token after invitation activation * logout before user activation * Fix CSRF security issue * menu logout before user activation * Linter * skip 'invite user' test * Add csrf token to each ml trainer request for webserver. * Add logs * Exempt more internal bp Co-authored-by: Maor Katzav <maor.katzav@databand.ai> Co-authored-by: Illia Keba <IlliaKeba@ibm.com> Co-authored-by: Roza Prag <rose.prag@databand.ai>
- Loading branch information