Page MenuHomePhabricator

Don't force main menu search form to use POST
AbandonedPublic

Authored by talshiri on Dec 10 2014, 3:13 AM.
Tags
None
Referenced Files
F17945126: D10954.id.diff
Thu, Jul 31, 11:18 AM
F17943469: D10954.id26306.diff
Thu, Jul 31, 8:24 AM
F17928518: D10954.diff
Wed, Jul 30, 4:15 PM
F17870860: D10954.diff
Mon, Jul 28, 2:53 PM
F17713545: D10954.diff
Jul 17 2025, 2:13 PM
Unknown Object (File)
Jun 28 2025, 10:37 AM
Unknown Object (File)
Jun 27 2025, 3:44 PM
Unknown Object (File)
Jun 6 2025, 2:55 PM
Subscribers

Details

Reviewers
epriestley
Group Reviewers
Blessed Reviewers
Summary

This allows browsers (Chorme, Firefox) to add Phabricator as a search engine.

The CSRF token that was previously generated (as it was a POST) was not checked anyway, and I don't think this is exploitable.

Test Plan

Right clicked on Chrome, as "Add As Search Engine". Tried out the search and it worked.

Diff Detail

Repository
rP Phabricator
Branch
dont_force_search_to_post
Lint
Lint Passed
Unit
Tests Passed
Build Status
Buildable 3207
Build 3213: [Placeholder Plan] Wait for 30 Seconds

Event Timeline

talshiri retitled this revision from to Don't force main menu search form to use POST.
talshiri updated this object.
talshiri edited the test plan for this revision. (Show Details)
talshiri added a reviewer: epriestley.
epriestley edited edge metadata.

We haven't seen other interest in this so I'm not interested in bringing it upstream.

This revision now requires changes to proceed.Nov 23 2015, 4:01 PM