https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=37374

--- Comment #8 from Martin Renvoize <[email protected]> ---
We're also failing the tests as there's no 'op' included here ;)

But.. in both cases I believe we're not actually posting a form anyway.. it's
getting caught by JS and submitted via ajax to the API which doesn't yet
require op or a csrf token.

I think we need to clean up a bit in general

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list
[email protected]
https://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to