Mohammed Rehan Khan created OFBIZ-7292:
------------------------------------------

             Summary: Remove Shopping List Item link is not working - Security 
Error
                 Key: OFBIZ-7292
                 URL: https://issues.apache.org/jira/browse/OFBIZ-7292
             Project: OFBiz
          Issue Type: Sub-task
          Components: specialpurpose/ecommerce
    Affects Versions: Release Branch 15.12, Trunk, Release Branch 14.12, 
Release Branch 13.07
            Reporter: Mohammed Rehan Khan
            Assignee: Mohammed Rehan Khan


Steps to reproduce:
1) Go to eCommerce
2) Add any item in shopping list
3) Click on shopping list tab
4) Click on Remove button of list items section

Getting following security error:

Error calling event: org.ofbiz.webapp.event.EventHandlerException: Found URL 
parameter [shoppingListId] passed to secure (https) request-map with uri 
[removeFromShoppingList] with an event that calls service 
[removeShoppingListItem]; this is not allowed for security reasons! The data 
should be encrypted by making it part of the request body (a form field) 
instead of the request URL.   



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to