Page MenuHomePhabricator

Actually check CSRF on Password and LDAP forms
ClosedPublic

Authored by epriestley on Jan 23 2014, 10:14 PM.
Tags
None
Referenced Files
F13038335: D8051.id.diff
Tue, Apr 16, 12:13 AM
Unknown Object (File)
Thu, Apr 11, 2:39 AM
Unknown Object (File)
Sat, Apr 6, 8:34 AM
Unknown Object (File)
Mar 11 2024, 8:05 PM
Unknown Object (File)
Mar 11 2024, 8:05 PM
Unknown Object (File)
Mar 11 2024, 8:05 PM
Unknown Object (File)
Mar 10 2024, 7:32 PM
Unknown Object (File)
Feb 15 2024, 2:04 AM
Subscribers

Details

Summary

Ref T4339. We didn't previously check isFormPost() on these, but now should.

Test Plan

Changed csrf token on login, got kicked out.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped