Asuka Tsuda Posted September 5, 2023 Share Posted September 5, 2023 I found "IBI_CSRF_REFERER_MATCH_DOMAIN" in event.log in WebFOCUS 9.0.4.[2023-08-29 00:00:59,505] INFO [com.ibi.monitor.WFContextListener:ApplicationValues] - Application config parameter: IBI_CSRF_REFERER_MATCH_DOMAIN (WFConfigVarList), value=TRUEWhat does this parameter mean? Link to comment Share on other sites More sharing options...
Patrick Huebgen Posted September 5, 2023 Share Posted September 5, 2023 This is one of the CSFR settings - https://en.wikipedia.org/wiki/Cross-site_request_forgeryPlease check the security manual for more details https://docs.tibco.com/emp/wf-wf/9.0.4/doc/pdf/TIB_wfwf_9.0.3_security_administration.pdf?id=11 Link to comment Share on other sites More sharing options...
Asuka Tsuda Posted September 6, 2023 Author Share Posted September 6, 2023 Thanks for the quick response.I looked at THE SECURITY MANUAL and found a description of the following settings, but no mention of "IBI_CSRF_REFERER_MATCH_DOMAIN".・IBI_CSRF_ENFORCE・IBI_CSRF_TOKEN_NAME・IBI_CSRF_ALLOW_LEGACYI know Cross-site request forgery.What is the effect of enabling "IBI_CSRF_REFERERER_MATCH_DOMAIN"?What is the difference between the above three settings?In addition, is there a way to disable it?Best regards,Asuka Tsuda Link to comment Share on other sites More sharing options...
Patrick Huebgen Posted September 6, 2023 Share Posted September 6, 2023 This seems to be a setting that is not yet documented - please open a case - I do not see the setting / warning on my system.Is this part of your webfocus.cfg? Link to comment Share on other sites More sharing options...
Asuka Tsuda Posted September 20, 2023 Author Share Posted September 20, 2023 I'm sorry for my late of reply.I have opened a new case about this question.Thank you for your help. Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now