Issue Type: Bug Bug
Affects Versions: current
Assignee: Unassigned
Components: core
Created: 26/Jan/13 12:19 AM
Description:

If the "Prevent cross site forgery request exploit" option is selected in the "Configure global" security page and a change is made and saved on the global settings page - the cross site forgery prevention option is deactivated.

This is causing issues with post-commit hooks that pass the API token as well as the crumb in the HTTP header when making RESTful calls to Jenkins.

Environment: CentOS 6.3 x86-64
Jenkins 1.498
Tomcat 6
Java 6
Project: Jenkins
Labels: core security
Priority: Minor Minor
Reporter: Youssuf ElKalay
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira

Reply via email to