This allows browsers (Chorme, Firefox) to add Phabricator as a search engine.
The CSRF token that was previously generated (as it was a POST) was not checked anyway, and I don't think this is exploitable.
Differential D10954
Don't force main menu search form to use POST talshiri on Dec 10 2014, 3:13 AM. Authored by Tags None Referenced Files
Subscribers
Details
This allows browsers (Chorme, Firefox) to add Phabricator as a search engine. The CSRF token that was previously generated (as it was a POST) was not checked anyway, and I don't think this is exploitable. Right clicked on Chrome, as "Add As Search Engine". Tried out the search and it worked.
Diff Detail
Event TimelineComment Actions We haven't seen other interest in this so I'm not interested in bringing it upstream. |