3 ms·
Yeah... from personal experience, if an app is intentionally or unintentionally built without XSS or CSRF protection, a complete fix-up of a codebase as large
by fretlessjazz 17y ago
Yeah... from personal experience, if an app is intentionally or unintentionally built without XSS or CSRF protection, a complete fix-up of a codebase as large as Basecamp is pretty expensive. Granted there are solutions that take care of 99% of the vulnerabilities, but the amount of testing/debugging/coding to close that 1% gap is huge.
Especially when you're still required to churn out new features in parallel.
- dfranke 17y agoFixing CSRF is pretty formulaic. You can probably do it across your whole codebase using nothing but sed. Stick a copy of your session cookie as a hidden field in every HTML form, and validate it as the first step of every form processing routine. The only time you need to introduce anything more thoughtful is if in some cases cross-site requests really are a feature, e.g. API calls.
- laktek 17y agoRails has built-in Request Forgery Protection. Seems Basecamp runs on a legacy version of Rails, which don't harness these features..