Skip to content

aborted transaction due to no CSRF on @@history links in version_history_form #57

Description

@ewohnlich

I was surprised to see this issue on one of my sites recently, as I don't know what could possibly be writing to the database by accessing @@history. I would have expected that to be read only. Debugging in plone.protect shows that the registered object is the Plone site itself.

Perhaps it doesn't matter, I don't think adding context/@@authenticator/token to the links on version_history_form should harm anything.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions