https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=13342

David Nind <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |[email protected]

--- Comment #4 from David Nind <[email protected]> ---
Thanks for the patch Alexandre!

I have tested on main before and after the patch is applied (using
koha-testing-docker).

If I follow the test plan, I now get this error page when I try to submit the
comment (after logging out in another tab):

  Sorry, the requested page is not available
  Error 403
  This message can have the following reason(s):

  The form submission failed (Wrong CSRF token). Try to come back, refresh the 
  page, then try again.

  ... Standard page not found message

Maybe the CSRF patches (bugs 34478 and 36192) have solved this for 24.05 and
later?

I also tested on one of the demo instances (https://koha-community.org/demo/)
for Koha 23.11 and could replicate the issue. So the issue still exists.

I'm not sure of the best way forward here:
1. Fix the CSRF issue (or maybe this is doing what it is supposed to do?)
2. Make this patch for 23.11 and before?
3. A combination of these?

As I'm not a developer, and I don't really understand the CSRF issue, I'm
probably not going to be of any help in solving the actual issue. But happy to
test the patches!


Note: The patch needs to follow the commit message guidelines - see
https://wiki.koha-community.org/wiki/Commit_messages Post here or on the Koha
Community Chat - Development channel if you need help with that
(https://chat.koha-community.org/).

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list
[email protected]
https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to