Problem/Motivation
Originally reported on security.drupal.org, but was deemed ok to discuss in public.
The enable/disable client routes provide an AJAX callback that allows the clients to be enabled/disabled. These routes are vulnerable to CSRF.
Proposed resolution
Add CSRF requirement to the routes.
Issue fork openid_connect-3506413
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #7
pfrillingMarking this as RTBC as the code was already reviewed in a patch on s.d.o.
Comment #9
pfrillingComment #10
joseph.olstadAlpha6 causes an issue in keycloak reported by two others
I'm not sure which change in alpha6 is causing this.
Comment #11
mstrelan commentedDoesn't make sense for that to be the parent issue, removing.