Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verify the request headers coming from the cmsweb frontend #63

Open
nikmagini opened this issue Apr 27, 2015 · 0 comments
Open

Verify the request headers coming from the cmsweb frontend #63

nikmagini opened this issue Apr 27, 2015 · 0 comments

Comments

@nikmagini
Copy link
Contributor

From Diego:

One thing that is missing in the setup but is not critical for now is
that both popdbweb and victorweb are not verifying the headers coming
from the cmsweb frontends. Every back-end service must check them to
make sure requests have not been tampered with or crafted locally by
exploiting some failure in some other service running on the same
back-end. Once that protection would be in place, we cannot anymore
generate requests locally.

On a separate note, it is also important all requests pass through the
frontends for the proper accountability and indentification of all the
clients.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant