All work
- Set Strict-Transport-Security response headerSECURITY-170Resolved issue: SECURITY-170
- CVE-2024-21742 MIME4J header smuggling - Analysis of vulnerability - Eureka - QuesneliaSECURITY-154Resolved issue: SECURITY-154
- Vert.x 4.2.2, Netty 4.1.72.Final fixing header request smuggling (CVE-2021-43797)OKAPI-1057Resolved issue: OKAPI-1057Julian Ladisch
- Disable x-okapi-trace header by defaultOKAPI-1038Resolved issue: OKAPI-1038Adam Dickmeiss
- Missing headers reported by ZAP need to be addedOKAPI-772
- change login API to return tokens in the body and not in private headersMODLOGIN-119Resolved issue: MODLOGIN-119
- okhttp 3 Information Exposure from illegal character in a headerMODEUSCNT-32Resolved issue: MODEUSCNT-32Tino R.
- Hosted Reference envs - Set Strict-Transport-Security response headerFOLIO-4049Resolved issue: FOLIO-4049John Malconian
- Spike: Provide guidelines for use of Content Security Policy headers with FOLIOFOLIO-2956
- investigate HTTP Response Header injectionFOLIO-2564Resolved issue: FOLIO-2564Craig McNally
- X-Okapi-Module-Tokens response header providing access to unauthenticated usersFOLIO-2286Resolved issue: FOLIO-2286Jakub Skoczen
- Spike: back-end cache headersFOLIO-1663Resolved issue: FOLIO-1663
- HTTP header injection with X-Okapi-TokenEDGRTAC-72Julian Ladisch
- edge-common 4.3.0 fixing tenant header injectionEDGRESOLV-12Resolved issue: EDGRESOLV-12
- edge-common 4.3.0 fixing tenant header injectionEDGPATRON-89Resolved issue: EDGPATRON-89Kyle Felker
- edge-common 4.3.0 fixing tenant header injectionEDGORDERS-60Resolved issue: EDGORDERS-60Andrei Makaranka
- tenant header injection security vulnerability (EDGCOMMON-47).EDGOAIPMH-84Resolved issue: EDGOAIPMH-84
- edge-common 4.3.0 fixing tenant header injectionEDGNCIP-16Resolved issue: EDGNCIP-16Michelle Suranofsky
- edge-lti-courses: edge-common 4.3.1 fixing tenant header injectionEDGLTI-3Resolved issue: EDGLTI-3Adam Dickmeiss
- Allow list fixing header injection in OkapiFeignClientExceptionHandlerEDGFQM-9Resolved issue: EDGFQM-9Matt Weaver
- edge-common 4.3.0 fixing tenant header injectionEDGDEMATIC-67Resolved issue: EDGDEMATIC-67
- Fix behavior when tenant header is present in a requestEDGCOMMON-47Resolved issue: EDGCOMMON-47Julian Ladisch
22 of 22