Main Koha release repository https://koha-community.org
Find a file
Emily-Rose Francoeur 7d62fd2daf Bug 35019: Add a CSRF token when deleting news
I add a CSRF token as a parameter in the link for deleting a news
entry, which solves the problem.

TEST PLAN
1) Apply the patch
2) Go to "Tools > News > New entry"
3) "Display location" should be set to "Staff interface"
4) Fill in the fields
5) Return to the homepage
6) Delete the created news entry
7) The "Additional contents" page is displayed, and the deleted news
   entry no longer appears
8) Return to the homepage; the news entry no longer displays

Signed-off-by: Owen Leonard <oleonard@myacpl.org>
Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
Edit: adapted the template change to latest master inline
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
(cherry picked from commit f4b8587782)
Signed-off-by: Fridolin Somers <fridolin.somers@biblibre.com>
(cherry picked from commit d9d9587342)
Signed-off-by: Matt Blenkinsop <matt.blenkinsop@ptfs-europe.com>
2023-11-13 14:19:29 +00:00
acqui Bug 34645: (follow-up) save sort1 and sort2 in order 2023-10-17 16:56:24 +00:00
admin Bug 34748: Fix column name in columns configuration for basket table 2023-10-17 12:31:24 +01:00
api Bug 34054: Allow to embed biblio on GET /items 2023-10-17 12:12:46 +01:00
authorities Bug 33406: (QA follow-up) Adjust tests and tidy 2023-10-12 15:45:37 +00:00
basket Bug 33102: Display fields from biblioitems in OPAC/staff interface cart 2023-05-12 16:34:19 +01:00
bin
C4 Bug 34549: Strip non-XML chars during TransformHtmlToMarc 2023-10-17 17:35:41 +00:00
catalogue Bug 33167: (RMAINT fix) Revert 33167 2023-07-20 08:41:00 +00:00
cataloguing Bug 34171: Use barcodedecode when attaching items to another record 2023-11-13 14:19:28 +00:00
circ Bug 27249: Fix code style 2023-11-13 13:45:37 +00:00
clubs
course_reserves
debian Bug 34204: Fix koha-shell under debian 12 2023-11-13 14:03:00 +00:00
docs Bug 34800: Adding openhub links for Koha contributors 2023-11-13 13:45:35 +00:00
erm
errors
etc Bug 30843: Add mfa_range configuration option for TOTP 2023-10-17 16:56:21 +00:00
ill
installer Bug 35064: Extra parenthesis in db_revs/220600072.pl 2023-11-13 14:02:59 +00:00
Koha Bug 34990: Add persistent header when sending msg to RabbitMQ 2023-11-13 14:19:27 +00:00
koha-tmpl Bug 35019: Add a CSRF token when deleting news 2023-11-13 14:19:29 +00:00
labels
lib/CGI/Session/Serialize
members Bug 34870: Perform UTF8 encoding before redirection 2023-10-17 17:23:41 +00:00
misc Bug 32305: Counterpart for es_indexer_daemon.pl 2023-11-13 14:19:27 +00:00
offline_circ
opac Bug 33819: Add page numbers to opac results breadcrumb 2023-10-17 17:35:39 +00:00
patron_lists
patroncards
plugins
pos Bug 34331: Use register from userenv if parameter not passed 2023-08-31 10:23:50 +00:00
recalls Bug 34013: Recalls awaiting pickup doesn't show count on each tab 2023-07-18 11:21:31 +00:00
reports Bug 34859: Remove unnecessary params from reports-home.pl 2023-10-17 17:23:41 +00:00
reserve Bug 34634: Show expirationdate of expired holds on reserve/request.pl 2023-09-15 09:33:06 +00:00
reviews
rotating_collections
serials Bug 34146: Counterpart for serials-edit 2023-07-18 13:11:36 +00:00
services
skel
suggestion Bug 26994: List names in alphabetical order in Suggestion filter 2023-11-13 14:19:28 +00:00
svc Bug 27249: Prevent infinite loop when searching for an open day 2023-11-13 13:45:36 +00:00
t Bug 35053: Regression tests 2023-11-13 14:03:04 +00:00
tags
tools Bug 34349: Validate/escape inputs for task scheduler 2023-09-28 09:18:29 +00:00
virtualshelves Bug 34650: Remove unnecessary CSRF check on edit_form 2023-09-08 09:47:28 +00:00
xt Bug 34911: Test files from HEAD instead of 'master' 2023-10-17 16:56:23 +00:00
.editorconfig
.eslintrc.json
.gitignore Bug 33710: Ignore how-to related files 2023-05-15 13:03:55 +00:00
.htaccess
.mailmap Update .mailmap 2023-07-18 09:22:47 +00:00
.perlcriticrc
.perltidyrc Bug 30002: Adjust perltidy 2023-07-12 09:16:19 +00:00
.proverc.dist
.stylelintrc.json
about.pl Bug 33934: Add more detail to 'No encryption_key in koha-conf.xml' 2023-06-12 11:53:36 +00:00
app.psgi
build-resources.PL
changelanguage.pl
cpanfile
cypress.json Bug 33408: Extend defaultCommandTimeout for cypress 2023-05-15 13:15:43 +00:00
fix-perl-path.PL
gulpfile.js Bug 35079: Replace --force-extract by --generate-pot={always,auto,never} 2023-11-08 12:59:54 +01:00
help.pl
INSTALL
Koha.pm Increment version for 22.11.11 release 2023-11-07 11:37:23 +00:00
koha_perl_deps.pl
kohaversion.pl
LICENSE
mainpage.pl Bug 35019: Add a CSRF token when deleting news 2023-11-13 14:19:29 +00:00
Makefile.PL Bug 30002: (QA follow-up) Add .perltidyrc to Makefile.PL mapping 2023-07-12 09:41:28 +00:00
MANIFEST.SKIP
package.json
README
README.md
README.robots
rewrite-config.PL
tsconfig.json
webpack.config.js
yarn.lock

Koha is a free software integrated library system (ILS).

Koha is distributed under the GNU GPL version 3 or later.

Note: Koha does not accept pull requests from git hosting sites.

Note: This project has its own bug tracker, to report a bug or submit a patch visit http://bugs.koha-community.org.

For guidelines on submitting patches for Koha please visit https://wiki.koha-community.org/wiki/SubmitingAPatch

The developers handbook can be found at https://wiki.koha-community.org/wiki/Developer_handbook

http://koha-community.org/

Koha Logo