Asuka Tsuda Posted September 5, 2023 Posted September 5, 2023 I found "IBI_CSRF_REFERER_MATCH_DOMAIN" in event.log in WebFOCUS 9.0.4.[2023-08-29 00:00:59,505] INFO [com.ibi.monitor.WFContextListener:ApplicationValues] - Application config parameter: IBI_CSRF_REFERER_MATCH_DOMAIN (WFConfigVarList), value=TRUEWhat does this parameter mean?
Patrick Huebgen Posted September 5, 2023 Posted September 5, 2023 This is one of the CSFR settings - https://en.wikipedia.org/wiki/Cross-site_request_forgeryPlease check the security manual for more details https://docs.tibco.com/emp/wf-wf/9.0.4/doc/pdf/TIB_wfwf_9.0.3_security_administration.pdf?id=11
Asuka Tsuda Posted September 6, 2023 Author Posted September 6, 2023 Thanks for the quick response.I looked at THE SECURITY MANUAL and found a description of the following settings, but no mention of "IBI_CSRF_REFERER_MATCH_DOMAIN".・IBI_CSRF_ENFORCE・IBI_CSRF_TOKEN_NAME・IBI_CSRF_ALLOW_LEGACYI know Cross-site request forgery.What is the effect of enabling "IBI_CSRF_REFERERER_MATCH_DOMAIN"?What is the difference between the above three settings?In addition, is there a way to disable it?Best regards,Asuka Tsuda
Patrick Huebgen Posted September 6, 2023 Posted September 6, 2023 This seems to be a setting that is not yet documented - please open a case - I do not see the setting / warning on my system.Is this part of your webfocus.cfg?
Asuka Tsuda Posted September 20, 2023 Author Posted September 20, 2023 I'm sorry for my late of reply.I have opened a new case about this question.Thank you for your help.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now