Salesforce.com : Setting Session Security - 'Enable CSRF protection on POST requests on non-setup pages = true'

Information

This setting controls whether Cross-Site Request Forgery (CSRF) protection on POST requests on non-setup pages is enabled

Solution

Set the value of enableCSRFOnPost to true.

See Also

http://help.salesforce.com/help/pdfs/en/salesforce_security_impl_guide.pdf

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-2, 800-53|SI-3

Plugin: Salesforce.com

Control ID: d46c1be8e2769798397e3ccb83562dfa33d6075f627167949f70fbebbec96271