Ref T4339. We didn't previously check isFormPost() on these, but now should.
Details
Details
- Reviewers
btrahan chad - Maniphest Tasks
- T4339: Support CSRF for logged-out users
- Commits
- Restricted Diffusion Commit
rPfebc494737be: Actually check CSRF on Password and LDAP forms
Changed csrf token on login, got kicked out.
Diff Detail
Diff Detail
- Branch
- csrfx
- Lint
Lint Passed Severity Location Code Message Advice src/applications/auth/provider/PhabricatorAuthProviderLDAP.php:160 XHP16 TODO Comment Advice src/applications/auth/provider/PhabricatorAuthProviderLDAP.php:171 XHP16 TODO Comment - Unit
No Test Coverage