v18 LibreELEC Testbuilds for RaspberryPi (Kodi 18.0)
(2017-06-08, 01:43)Milhouse Wrote:
(2017-06-08, 01:30)kkoa Wrote: Added: [pkg] PR:12265: [webserver] dont allow jsonrpc over http get

I think this change is not good as I sometimes use JSON RPC via the webbrowser for non read-only methods which then won't work anymore.

The problem is that using GET requests to modify data is a security risk as any website open in your browser could silently execute a GET request against a local Kodi web server (assuming it knows the IP address and port). The original discussion started here (see "Security concerns" section). If you have concerns you'd best post a comment in the PR while it's still open.

Yeah, I read the PR. Doubt they would change it just for me even though I have never heard of anybody hijacking Kodi. For extended security one could just set a password for the web interface.

Wouldn't it still be possbile to make a form targetting a frame to hijack Kodi with a post request then?


Messages In This Thread
RE: LibreELEC Testbuilds for RaspberryPi (Kodi 18.0) - by kkoa - 2017-06-08, 02:43
WD MyCloud - by crisp waffles - 2017-09-06, 03:11
No 3D Playback since Version - by Mike74 - 2017-10-09, 19:25
Migrating from RPi2 to RPi1 - by RappaSan - 2017-11-10, 14:45
RE: Migrating from RPi2 to RPi1 - by Milhouse - 2017-11-10, 21:06
RE: Migrating from RPi2 to RPi1 - by RappaSan - 2017-11-11, 09:17
Resolution broken after 0415 - by lozbrown85 - 2018-04-20, 11:48
popt 1.16 - by n0n4m3 - 2018-06-29, 00:28
RE: popt 1.16 - by Milhouse - 2018-06-29, 06:39
A plugin to be resurrected - by ArminiusTux - 2018-10-22, 22:02
RE: A plugin to be resurrected - by Milhouse - 2018-10-23, 02:46
Logout Mark Read Team Forum Stats Members Help
LibreELEC Testbuilds for RaspberryPi (Kodi 18.0)24