Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-26 Thread Alon Bar-Lev
- Original Message - > From: "Juan Hernandez" > To: "Alon Bar-Lev" , "Vojtech Szocs" > Cc: devel@ovirt.org > Sent: Thursday, July 24, 2014 10:31:12 AM > Subject: Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID > now req

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-24 Thread Juan Hernandez
14 9:46:52 PM >> Subject: Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID >> now requires separate request header >> >> >> >> - Original Message - >>> From: "Alon Bar-Lev" >>> To: "Vojtech Szocs" >&g

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-23 Thread Alon Bar-Lev
- Original Message - > From: "Vojtech Szocs" > To: "Alon Bar-Lev" , "Juan Antonio Hernandez Fernandez" > > Cc: devel@ovirt.org > Sent: Tuesday, July 15, 2014 9:46:52 PM > Subject: Re: [ovirt-devel] UI plugins - talking with Engine via JS

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-16 Thread Juan Hernandez
On 07/15/2014 08:58 PM, Vojtech Szocs wrote: > > > - Original Message - >> From: "Sven Kieske" To: devel@ovirt.org >> Sent: Tuesday, July 15, 2014 8:26:59 PM Subject: Re: >> [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now >>

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-15 Thread Vojtech Szocs
- Original Message - > From: "Sven Kieske" > To: devel@ovirt.org > Sent: Tuesday, July 15, 2014 8:26:59 PM > Subject: Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID > now requires separate request header > > -BEGIN PGP SIGNED MESS

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-15 Thread Vojtech Szocs
- Original Message - > From: "Alon Bar-Lev" > To: "Vojtech Szocs" > Cc: devel@ovirt.org, "Oved Ourfalli" > Sent: Tuesday, July 15, 2014 8:22:06 PM > Subject: Re: [ovirt-devel] UI plugins - talking with Engine via JSESS

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-15 Thread Sven Kieske
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Just a few questions from someone who relies on the rest api: Background: I use rest not for UI plugins but for general management stuff (basically all ovirt operations which are possible via rest) I don't use the cookie based session management but p

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-15 Thread Alon Bar-Lev
- Original Message - > From: "Vojtech Szocs" > To: "Alon Bar-Lev" > Cc: devel@ovirt.org, "Oved Ourfalli" > Sent: Tuesday, July 15, 2014 9:18:44 PM > Subject: Re: [ovirt-devel] UI plugins - talking with Engine via JSESS

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-15 Thread Vojtech Szocs
- Original Message - > From: "Alon Bar-Lev" > To: "Vojtech Szocs" > Cc: devel@ovirt.org, "Oved Ourfalli" , "René Koch" > > Sent: Tuesday, July 15, 2014 7:47:35 PM > Subject: Re: [ovirt-devel] UI plugins - talking with Eng

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-15 Thread Alon Bar-Lev
- Original Message - > From: "Vojtech Szocs" > To: "Alon Bar-Lev" > Cc: devel@ovirt.org, "Oved Ourfalli" , "René Koch" > > Sent: Tuesday, July 15, 2014 8:40:30 PM > Subject: Re: [ovirt-devel] UI plugins - talking with Eng

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-15 Thread Vojtech Szocs
- Original Message - > From: "Alon Bar-Lev" > To: "Vojtech Szocs" > Cc: devel@ovirt.org, "Oved Ourfalli" , "René Koch" > > Sent: Tuesday, July 15, 2014 7:17:40 PM > Subject: Re: [ovirt-devel] UI plugins - talking with Eng

Re: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-15 Thread Alon Bar-Lev
5, 2014 8:06:19 PM > Subject: [ovirt-devel] UI plugins - talking with Engine via JSESSIONID now > requires separate request header > > Hi guys, > > please be advised, patch for master [1] as well as ovirt-engine-3.5 [2] > branch was merged recently. This patch enables CSRF

[ovirt-devel] UI plugins - talking with Engine via JSESSIONID now requires separate request header

2014-07-15 Thread Vojtech Szocs
Hi guys, please be advised, patch for master [1] as well as ovirt-engine-3.5 [2] branch was merged recently. This patch enables CSRF (Cross-Site Request Forgery) protection for REST API session acquired by WebAdmin UI plugin infrastructure. If you maintain UI plugin(s) and utilize "RestApiSession