Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

aborted transaction due to no CSRF on @@history links in version_history_form #57

Open
ewohnlich opened this issue May 22, 2018 · 0 comments

Comments

@ewohnlich
Copy link

I was surprised to see this issue on one of my sites recently, as I don't know what could possibly be writing to the database by accessing @@history. I would have expected that to be read only. Debugging in plone.protect shows that the registered object is the Plone site itself.

Perhaps it doesn't matter, I don't think adding context/@@authenticator/token to the links on version_history_form should harm anything.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant