Skip to content

Validate post requests via the errorreport.php #1211

@roland-d

Description

@roland-d

Is your feature request related to a problem? Please describe.
The problem is that you can create a spam attack via the errorreport.php

Describe the solution you'd like
Add a form token to the error report form. This form token can be checked on submission, if it is invalid no email is send out.

Describe alternatives you've considered
The only real alternative is to turn off the error report form.

Additional context
I posted this first in the Google group, here is my post for reference:
https://groups.google.com/forum/#!topic/simplesamlphp/ccy6fN0PslI

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions