Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-11842

Delete version confirmation template does not include a CSRF token

    XMLWordPrintable

    Details

    • Difficulty:
      Unknown
    • Documentation:
      N/A
    • Documentation in Release Notes:
      N/A
    • Similar issues:

      Description

      When reaching the delete versions action URL that needs a confirmation, the template that renders is does not include a CSRF token in the "Yes" button/link, so you can not proceed without causing a CSRF validation error.

        Attachments

          Activity

            People

            Assignee:
            enygma Eduard Moraru
            Reporter:
            enygma Eduard Moraru
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: