[
https://issues.apache.org/jira/browse/GUACAMOLE-956?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17425860#comment-17425860
]
Mike Jumper commented on GUACAMOLE-956:
---------------------------------------
As it's not possible to include arbitrary headers within WebSocket requests, it
will be necessary to provide some other mechanism, such as a means of obtaining
a nonce that can be used one time only in lieu of the token. The HTTP tunnel,
which uses the tunnel UUID in the query string in a similar fashion, may also
need to be adjusted in the spirit of these changes.
> Migrate away from including auth token within REST API URLs
> -----------------------------------------------------------
>
> Key: GUACAMOLE-956
> URL: https://issues.apache.org/jira/browse/GUACAMOLE-956
> Project: Guacamole
> Issue Type: Improvement
> Components: guacamole
> Reporter: Mike Jumper
> Assignee: Mike Jumper
> Priority: Minor
> Fix For: 1.4.0
>
>
> Guacamole's current REST API relies on including the user's auth token within
> the {{token}} query parameter. Using a query parameter in this way is
> generally regarded as bad practice, as other software between the user and
> the webapp may log the content of URLs and GET requests insecurely, including
> these parameters.
> We should instead leverage HTTP headers, allowing the {{token}} parameter to
> be used only for compatibility's sake.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)