Github webhook override breaks CSRF exclusion

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      If you have CSRF checking turned on in Global Security Settings:

       

      And you have the Github webhook URL overridden in Jenkins Settings:

      Then each webhook payload will hit a CSRF error:

      I believe this is because the url /github-webhook is hardcoded in GitHubWebHookCrumbExclusion.java.

        1. image-2020-02-18-13-35-59-338.png
          152 kB
          Eric Winer
        2. image-2020-02-18-13-36-51-430.png
          45 kB
          Eric Winer
        3. image-2020-02-18-13-38-47-192.png
          36 kB
          Eric Winer

            Assignee:
            Kirill Merkushev
            Reporter:
            Eric Winer
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Archived: