Removes the CSRF cookie in favor of [`CrossOriginProtection`](https://pkg.go.dev/net/http#CrossOriginProtection) which relies purely on HTTP headers. Fixes: https://github.com/go-gitea/gitea/issues/11188 Fixes: https://github.com/go-gitea/gitea/issues/30333 Helps: https://github.com/go-gitea/gitea/issues/35107 TODOs: - [x] Fix tests - [ ] Ideally add tests to validates the protection --------- Signed-off-by: wxiaoguang <wxiaoguang@gmail.com> Co-authored-by: wxiaoguang <wxiaoguang@gmail.com> |
||
|---|---|---|
| .. | ||
| allow_maintainer_edit.tmpl | ||
| assignee_list.tmpl | ||
| due_date.tmpl | ||
| issue_dependencies.tmpl | ||
| issue_management.tmpl | ||
| label_list_item.tmpl | ||
| label_list.tmpl | ||
| milestone_list.tmpl | ||
| participant_list.tmpl | ||
| project_list.tmpl | ||
| reference_link.tmpl | ||
| reviewer_list.tmpl | ||
| stopwatch_timetracker.tmpl | ||
| watch_notification.tmpl | ||
| wip_switch.tmpl | ||