• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Disable CSRF

Scheduled Pinned Locked Moved webGUI
8 Posts 3 Posters 4.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E
    Essential
    last edited by Nov 9, 2012, 8:10 AM

    Hello all!

    My question is how i can disable CSRF at all pages? We trying make some automation for pfsense and this check give for us some problem.

    PS and maybe pfsense have some API? or something like that?

    1 Reply Last reply Reply Quote 0
    • G
      GruensFroeschli
      last edited by Nov 9, 2012, 9:45 AM Nov 9, 2012, 9:42 AM

      It's under System–>Advanced-->Admin Access
      There you can also define alternative names which should be allowed.

      We do what we must, because we can.

      Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

      1 Reply Last reply Reply Quote 0
      • E
        Essential
        last edited by Nov 9, 2012, 10:12 AM

        @GruensFroeschli:

        It's under System–>Advanced-->Admin Access
        There you can also define alternative names which should be allowed.

        What exactly you mean?

        1 Reply Last reply Reply Quote 0
        • G
          GruensFroeschli
          last edited by Nov 9, 2012, 12:05 PM

          I gave the answer to what you asked?
          Just tick the checkbox "Disable HTTP_REFERER enforcement check "

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • E
            Essential
            last edited by Nov 9, 2012, 4:33 PM

            @GruensFroeschli:

            I gave the answer to what you asked?
            Just tick the checkbox "Disable HTTP_REFERER enforcement check "

            This chechbox dont disable csrf check  :(

            1 Reply Last reply Reply Quote 0
            • G
              GruensFroeschli
              last edited by Nov 9, 2012, 11:26 PM

              Then what do you think it does?
              It certainly allows me to access my pfSense with any name i point to the it….

              We do what we must, because we can.

              Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

              1 Reply Last reply Reply Quote 0
              • C
                cmb
                last edited by Nov 10, 2012, 12:21 AM

                The CSRF check is different and completely separate from the REFERER check. There is no way short of editing the source on all the pages to disable the CSRF checks.

                1 Reply Last reply Reply Quote 0
                • G
                  GruensFroeschli
                  last edited by Nov 10, 2012, 8:01 AM

                  D'oh.
                  I feel stupid.
                  Sorry i mixed terms up…
                  i guess the answer is in the other thread in which you wrote where it's described how to change the code.

                  We do what we must, because we can.

                  Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received