Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • G gitlabhq1
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 21
    • Issues 21
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 12
    • Merge requests 12
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Packages & Registries
    • Packages & Registries
    • Package Registry
    • Infrastructure Registry
  • Analytics
    • Analytics
    • CI/CD
    • Repository
    • Value stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • gpt
  • large_projects
  • gitlabhq1
  • Issues
  • #9337

Closed
Open
Created May 28, 2015 by Administrator@rootOwner

OmniAuth CSRF protection break the Atlassian Crowd provider

Created by: hudecof

Atlassian Crowd is using OmniAuth::Form to build the login form. In the form is missing the CSRF token. Is there any way how tu push the CSRF token to OmniAuth without patching the OmniAuth provider?

See my hack to get it work on https://github.com/gitlabhq/gitlabhq/issues/1240

I do not think this new feature has been heavy tested and is finished. How could you pass this token to the other providers?

Assignee
Assign to
Time tracking