FerryDocs
ReferenceAPI overview

Changes with the session cookie

A change that uses the session cookie must come from the origin of the dashboard.

Edit on GitHub
POST + cookiePOST + cookieDashboardsame originOther sitedifferent originferryd

A change from the dashboard has the session cookie. ferryd accepts it.

1 / 2

ferryd checks where a change with the comes from.

The rule

The rule applies to a request that has these two properties:

  • the session cookie is its proof
  • its changes something: POST, PUT, PATCH or DELETE

This request must come from the of the dashboard. If not, the answer is 403 cross_site_request.

How ferryd checks

ferryd reads the header Sec-Fetch-Site. If the request does not have it, ferryd compares the header Origin with the host.

See Changes come from the dashboard only.

On this page