allura-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Cory Johns" <>
Subject [allura:tickets] #7026 Require POST for follow/unfollow actions
Date Mon, 13 Jan 2014 22:41:17 GMT
- **status**: in-progress --> code-review


** [tickets:#7026] Require POST for follow/unfollow actions**

**Status:** code-review
**Labels:** activitystreams security 
**Created:** Mon Jan 06, 2014 07:47 PM UTC by Dave Brondsema
**Last Updated:** Mon Jan 13, 2014 08:00 PM UTC
**Owner:** Cory Johns

`def follow` in `forgeactivity/` should require POST.  And templates and tests should
be changed to send posts (and don't forget the csrf token).


Sent from because is subscribed to

To unsubscribe from further messages, a project admin can change settings at
 Or, if this is a mailing list, you can unsubscribe from the mailing list.
  • Unnamed multipart/related (inline, None, 0 bytes)
View raw message