Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-28905

CSRF token is not regenerated through sessions

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • core

      When you enable CSRF protection there is a ".crumb" header generated for login form and ajax requests. The problem is that this token is regenerated through sessions so basically it's useless.

          [JENKINS-28905] CSRF token is not regenerated through sessions

          There are no comments yet on this issue.

            Unassigned Unassigned
            dimitaremp Dimitar Kostov
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: