瀏覽代碼

AMBARI-7344. CSRF Prevention is broken for the /proxy endpoint. (mpapirkovskyy)

Myroslav Papirkovskyy 10 年之前
父節點
當前提交
94bda46759
共有 1 個文件被更改,包括 1 次插入1 次删除
  1. 1 1
      ambari-server/src/main/java/org/apache/ambari/server/controller/AmbariServer.java

+ 1 - 1
ambari-server/src/main/java/org/apache/ambari/server/controller/AmbariServer.java

@@ -380,7 +380,7 @@ public class AmbariServer {
         sh.setInitParameter("com.sun.jersey.spi.container.ContainerRequestFilters",
                     "org.apache.ambari.server.api.AmbariCsrfProtectionFilter");
         proxy.setInitParameter("com.sun.jersey.spi.container.ContainerRequestFilters",
-                    "com.sun.jersey.api.container.filter.AmbariCsrfProtectionFilter");
+                    "org.apache.ambari.server.api.AmbariCsrfProtectionFilter");
       }
 
       //Set jetty thread pool