Ticket #1035 (closed enhancement: wontfix)

Opened 3 years ago

Last modified 2 years ago

Form impressions given an ID

Reported by: dread Owned by: thejimmyg
Priority: minor Milestone:
Component: ckan Keywords:
Cc: Repository: ckan
Theme: none

Description

To counter Cross Site Request Forgery attacks, each form generated is assigned a random number in its url, which must be passed when you submit the form.

(Something to consider for the new form mechanism)

Change History

comment:1 Changed 2 years ago by thejimmyg

  • Owner changed from sebbacon to thejimmyg
  • Repository set to ckan
  • Theme set to none
  • Status changed from new to assigned

Re-assigning to me temporarily to investigate now that Seb has left. It may be that this should be deleted given that it is over 6 month's old.

comment:2 Changed 2 years ago by ross

  • Status changed from assigned to closed
  • Resolution set to wontfix

Removing until we can come up with a case for implementing

Note: See TracTickets for help on using tickets.