From: Fabien POTENCIER <fabien.potenc...@symfony-project.com>
Date: Mon, 31 Mar 2008 18:21:47 +0200
Local: Mon, Mar 31 2008 12:21 pm
Subject: Re: [symfony-devs] Re: CSRF protection
Francois Zaninotto wrote: You're right. After some thought, I think that when you create a new > Given the 'convention over configuration' mantra, I'm not sure forcing > two config options at creation time is a good idea either. > Documentationwise, that would imply explaining the security caveats of application, it's not the time to force the user to learn about XSS or CSRF. It's too late. Fabien > So I'm more in favor of an "unsecure" default, but with a new doc > My 2c, > François > 2008/3/31, Fabien POTENCIER <fabien.potenc...@symfony-project.com > Lucas Stephanou wrote: > There is no default. When you create an application, you must provide > Fabien > > On Mon, Mar 31, 2008 at 10:11 AM, Fabien POTENCIER > > <mailto:fabien.potenc...@symfony-project.com > > I will post a blog post about security when we will release > > Short story: > > People need to be aware of what kind of things are done > > In beta3, the generate:app task will have new mandatory > > And here is a question for all of you. How to name this/these new > > 2 options, one for XSS and one for CSRF: > > --xss-protection=on / off / both > > --csrf-protection=on / off > > Let's start the discussion ;) > > Fabien > > -- > > sensiolabs.com <http://sensiolabs.com> > > Tél: +33 1 40 99 80 80 > > Ian P. Christian wrote: > > > Why has CSRF been disabled by default? > > > Kind Regards, > > > Ian > > -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||