ArchitectureSecurity model
Changes come from the dashboard only
The server refuses a change that has the session cookie but comes from another origin.
The dashboard sends a change with the session cookie. The server accepts it.
1 / 3
A POST, PUT, PATCH or DELETE request with the session cookie must come from the origin of the dashboard. This rule protects you when you open a bad page while your browser has a session.
How the server tests the request
- The server reads the
Sec-Fetch-Siteheader. - If the browser did not send it, the server compares the
Originheader with the host.
If the test fails, the server sends this answer:
| Answer | Message |
|---|---|
403 cross_site_request | this request doesn't come from the dashboard |
You have nothing to set. The protection is always on.
ferryd sends no CORS headers. Thus a page of another origin cannot call the API from a browser.
The pages of the dashboard and of Swagger UI have these headers:
X-Frame-Options: DENY: another site cannot show the page in a frame.Referrer-Policy: no-referrer: the browser does not tell other sites which page you came from.X-Content-Type-Options: nosniff: the browser does not guess the type of a file.