Inspecting $_POST on confirmations may lead to CSRF vulnerabilities: one should use a submit handler. This patch went into 5.x as well.

CommentFileSizeAuthor
#2 confirm_form_doc.patch908 bytesHeine
6_confirm_form.patch620 bytesHeine
Support from Acquia helps fund testing for Drupal Acquia logo

Comments

Heine’s picture

patch was by barry jaspan btw.

Heine’s picture

FileSize
908 bytes

Instead of making a mistery of what file changed, a patch with complete headers.

Gábor Hojtsy’s picture

Status: Needs review » Fixed

Committed, thanks.

Anonymous’s picture

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for two weeks with no activity.