CSRF Filter in Tomcat 7

General discussions.

Moderator: moderators

CSRF Filter in Tomcat 7

Postby MidnightJava » Sat Jul 16, 2011 4:45 am

I recently deployed Subsonic as a web app, and ran into the problem wherein Subsonic cannot run on Tomcat 7 because the CSRF filter blocks many URLs. Searching on the forum here, the only answer given for this problem is to use Tomcat 6.

That may be OK for a while, but I'm hoping that's not the end of the story. Are there any plans to fix whatever is causing Subsonic to run afoul of the CSRF filter? It appears to be something in DWRP, but I don't know if it's strictly a DWRP problem, or something that Subsonic can address.

In my web research I came across an apache ticket for back-porting the CSRF filter into Tomcat 6 and 5. It seemed to be only for the Manager and Host-Manager apps, but I can't say for sure it won't be applied to all web apps, as is the case with Tomcat 7.
-Mark
MidnightJava
 
Posts: 5
Joined: Fri Jul 15, 2011 11:00 pm

Return to General

Who is online

Users browsing this forum: No registered users and 24 guests