Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: As of https://github.com/jenkinsci/jenkins/pull/1319 the crumb name is no longer an issue

...

Code Block
languagegroovy
titlecsrf.groovy
import hudson.security.csrf.DefaultCrumbIssuer
import jenkins.model.Jenkins

def instance = Jenkins.instance
instance.setCrumbIssuer(new DefaultCrumbIssuer(true))
instance.save()

Gotchas

  • If you are using nginx as a reverse proxy in front of Jenkins, you need an extra system property on Jenkins "-Dhudson.security.csrf.requestfield=Jenkins-Crumb". See JENKINS-23793 for more detailsIf you have scripts and other programs that access Jenkins via REST API, they can be impacted. See its CSRF section for more information about how to update those scripts.