This is an automated email from the ASF dual-hosted git repository.

juanpablo pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/jspwiki.git


The following commit(s) were added to refs/heads/master by this push:
     new 55b117915 add missing csrf params
55b117915 is described below

commit 55b117915b2bf3245f0babf4afe54fa4df01e8c5
Author: Juan Pablo Santos Rodríguez <[email protected]>
AuthorDate: Wed Jul 20 17:09:28 2022 +0200

    add missing csrf params
---
 jspwiki-main/src/main/javascript/Wiki.Snips.JSPWiki.js      | 2 +-
 jspwiki-markdown/src/main/javascript/Wiki.Snips.Markdown.js | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/jspwiki-main/src/main/javascript/Wiki.Snips.JSPWiki.js 
b/jspwiki-main/src/main/javascript/Wiki.Snips.JSPWiki.js
index 43f4d6b66..0a5dfbcad 100644
--- a/jspwiki-main/src/main/javascript/Wiki.Snips.JSPWiki.js
+++ b/jspwiki-main/src/main/javascript/Wiki.Snips.JSPWiki.js
@@ -473,7 +473,7 @@ Wiki.Snips = {
 
             new Request({
             url: Wiki.XHRPreview,
-            data: { page: Wiki.PageName, wikimarkup: "[{Groups}]" },
+            data: { page: Wiki.PageName, wikimarkup: "[{Groups}]", 
'X-XSRF-TOKEN': wiki.CsrfProtection },
             onSuccess: function(responseText){
 
                 var body = "Anonymous|Asserted|Authenticated|All";
diff --git a/jspwiki-markdown/src/main/javascript/Wiki.Snips.Markdown.js 
b/jspwiki-markdown/src/main/javascript/Wiki.Snips.Markdown.js
index 6a9f757d3..32bc5ce11 100644
--- a/jspwiki-markdown/src/main/javascript/Wiki.Snips.Markdown.js
+++ b/jspwiki-markdown/src/main/javascript/Wiki.Snips.Markdown.js
@@ -473,7 +473,7 @@ Wiki.Snips = {
 
             new Request({
             url: Wiki.XHRPreview,
-            data: { page: Wiki.PageName, wikimarkup: "[{Groups}]()" },
+            data: { page: Wiki.PageName, wikimarkup: "[{Groups}]()", 
'X-XSRF-TOKEN': wiki.CsrfProtection },
             onSuccess: function(responseText){
 
                 var body = "Anonymous|Asserted|Authenticated|All";

Reply via email to