ReferenceAPI overview
Changes with the session cookie
A change that uses the session cookie must come from the origin of the dashboard.
A change from the dashboard has the session cookie. ferryd accepts it.
1 / 2
ferryd checks where a change with the session cookie comes from.
The rule
The rule applies to a request that has these two properties:
- the session cookie is its proof
- its method changes something:
POST,PUT,PATCHorDELETE
This request must come from the origin of the dashboard. If not, the answer is 403 cross_site_request.
How ferryd checks
ferryd reads the header Sec-Fetch-Site. If the request does not have it, ferryd compares the header Origin with the host.