Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Initial ticket: 

Jira Legacy
serverWildix
columnskey,summary,type,created,updated,due,assignee,reporter,priority,status,resolution
serverId1ea7696d-9186-3c7d-b790-c8d05a360ecd
keyWMS-3985

To prevent cross site data interception, 'Origin' header whitelist has been implemented for API queries

Technical Details

Whitelist can be configured in WMS Settings > PBX > Security

Settings are stored in /rw2/etc/pbx/http-security.conf .conf

Different domains are supported for configuration e.g.

Origin: 'https://pbx.wildix.com' is hardcoded in whitelist

Attention

Partners must be informed that any webapi / pbxapi integration will stop working if the domain is not added to the whitelist