<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSRF and asterisk @sas.web.csrf.referers.knownHosts in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/CSRF-and-asterisk-sas-web-csrf-referers-knownHosts/m-p/833569#M25062</link>
    <description>An asterisk does not meet the format set forth in the prompt for that field, so I think you'd need to do http://*/ and https://*/. I would agree if you want to permit from any host you should instead set "sas.web.csrf.referers.performCheck" to false and restart your middle tier.&lt;BR /&gt;&lt;BR /&gt;Whitelist of Websites and Methods Allowed to Link to SAS Web Applications&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1xtsni38p58t3n1ljd2fy4c3joz.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1xtsni38p58t3n1ljd2fy4c3joz.htm&lt;/A&gt;</description>
    <pubDate>Thu, 15 Sep 2022 12:22:20 GMT</pubDate>
    <dc:creator>gwootton</dc:creator>
    <dc:date>2022-09-15T12:22:20Z</dc:date>
    <item>
      <title>CSRF and asterisk @sas.web.csrf.referers.knownHosts</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/CSRF-and-asterisk-sas-web-csrf-referers-knownHosts/m-p/833557#M25059</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have to create a situation where user needs to see some report directly and therefore the link to exact report is placed at intranet webpage menu, for example &lt;A href="https://web.domain.dn/" target="_blank" rel="noopener"&gt;https://web.domain.dn/somewhere/somepage&lt;/A&gt;. The link to the report is similar to &amp;lt;https://&amp;lt;sas_midtier_host.doman.dn&amp;gt;:8343/SASVisualAnalyticsViewer/?reportSBIP=SBIP://METASERVER/&amp;lt;longer-path-to-report&amp;gt;. &amp;nbsp;So, it means that referer for the sas_midtier_host is different.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, the problem is that even if I do have asterisk at&amp;nbsp;sas.web.csrf.referers.knownHosts value, it still gives &lt;EM&gt;"The referring URL has been logged on the server. Please contact your SAS Administrator if you think the referring URL should be allowed. The SAS Administrator should review the information about cross site request forgery in the&amp;nbsp;&lt;A href="https://support.sas.com/documentation/onlinedoc/intellplatform/index.html" target="_blank" rel="noopener"&gt;SAS Intelligence Platform documentation&lt;/A&gt;&amp;nbsp;for instructions about using the&amp;nbsp;&lt;SPAN class="setting"&gt;sas.web.csrf.referers.knownHosts&lt;/SPAN&gt;&amp;nbsp;setting to whitelist the referring URL."&lt;/EM&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="referer-denies.PNG" style="width: 617px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/75270iE07A0BAD056D8AD8/image-size/large?v=v2&amp;amp;px=999" role="button" title="referer-denies.PNG" alt="referer-denies.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="referer-knownhosts-asterix.PNG" style="width: 646px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/75272i96C7C1E1CBF535DD/image-size/large?v=v2&amp;amp;px=999" role="button" title="referer-knownhosts-asterix.PNG" alt="referer-knownhosts-asterix.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I remember the asterisk was typed while installing the environment:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="referer-asterix-typed.PNG" style="width: 577px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/75273i4E3FCEB60F339E87/image-size/large?v=v2&amp;amp;px=999" role="button" title="referer-asterix-typed.PNG" alt="referer-asterix-typed.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The easiest solution would be turning CSFR off completely as the asterisk shouldn't restrict anybody anyway. But I'm still curious why it gives me the denial because of referer, is asterisk suitable for the cell?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PriitL&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 11:19:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/CSRF-and-asterisk-sas-web-csrf-referers-knownHosts/m-p/833557#M25059</guid>
      <dc:creator>PriitL</dc:creator>
      <dc:date>2022-09-15T11:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF and asterisk @sas.web.csrf.referers.knownHosts</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/CSRF-and-asterisk-sas-web-csrf-referers-knownHosts/m-p/833569#M25062</link>
      <description>An asterisk does not meet the format set forth in the prompt for that field, so I think you'd need to do http://*/ and https://*/. I would agree if you want to permit from any host you should instead set "sas.web.csrf.referers.performCheck" to false and restart your middle tier.&lt;BR /&gt;&lt;BR /&gt;Whitelist of Websites and Methods Allowed to Link to SAS Web Applications&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1xtsni38p58t3n1ljd2fy4c3joz.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1xtsni38p58t3n1ljd2fy4c3joz.htm&lt;/A&gt;</description>
      <pubDate>Thu, 15 Sep 2022 12:22:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/CSRF-and-asterisk-sas-web-csrf-referers-knownHosts/m-p/833569#M25062</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2022-09-15T12:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: CSRF and asterisk @sas.web.csrf.referers.knownHosts</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/CSRF-and-asterisk-sas-web-csrf-referers-knownHosts/m-p/833825#M25068</link>
      <description>&lt;P&gt;Thank You for Your reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still, entries "http://*/,https://*/" do not work. The entry should be "http://*.dn/,https://*.dn/" (if domain is domain.dn for example).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 12:03:52 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/CSRF-and-asterisk-sas-web-csrf-referers-knownHosts/m-p/833825#M25068</guid>
      <dc:creator>PriitL</dc:creator>
      <dc:date>2022-09-16T12:03:52Z</dc:date>
    </item>
  </channel>
</rss>

