Ref T4339. We didn't previously check isFormPost() on these, but now should.
Details
Details
- Reviewers
btrahan chad - Maniphest Tasks
- T4339: Support CSRF for logged-out users
- Commits
- Restricted Diffusion Commit
rPfebc494737be: Actually check CSRF on Password and LDAP forms
Changed csrf token on login, got kicked out.
Diff Detail
Diff Detail
- Lint
Lint Skipped - Unit
Tests Skipped