Page MenuHomePhabricator

Actually check CSRF on Password and LDAP forms
ClosedPublic

Authored by epriestley on Jan 23 2014, 10:14 PM.
Tags
None
Referenced Files
F19388365: D8051.id18216.diff
Sat, Dec 27, 4:28 AM
F19072278: D8051.diff
Sun, Nov 30, 10:01 PM
F19001908: D8051.diff
Nov 21 2025, 4:14 AM
F18858918: D8051.diff
Nov 1 2025, 11:29 PM
F18831076: D8051.id.diff
Oct 25 2025, 10:40 AM
F18829396: D8051.diff
Oct 24 2025, 9:41 PM
F18734569: D8051.id.diff
Sep 30 2025, 10:56 PM
F18675119: D8051.diff
Sep 25 2025, 5:19 PM
Subscribers

Details

Summary

Ref T4339. We didn't previously check isFormPost() on these, but now should.

Test Plan

Changed csrf token on login, got kicked out.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped