Main Koha release repository https://koha-community.org
Find a file
Emily-Rose Francoeur f4b8587782
Bug 35019: Add a CSRF token when deleting news
I add a CSRF token as a parameter in the link for deleting a news
entry, which solves the problem.

TEST PLAN
1) Apply the patch
2) Go to "Tools > News > New entry"
3) "Display location" should be set to "Staff interface"
4) Fill in the fields
5) Return to the homepage
6) Delete the created news entry
7) The "Additional contents" page is displayed, and the deleted news
   entry no longer appears
8) Return to the homepage; the news entry no longer displays

Signed-off-by: Owen Leonard <oleonard@myacpl.org>
Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
Edit: adapted the template change to latest master inline
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
2023-10-20 17:22:02 -03:00
acqui Bug 14092: (QA follow-up) Avoid fiddling with the hash in the template 2023-10-20 16:31:15 -03:00
admin Bug 25393: (QA follow-up) Tidy 2023-10-20 16:31:24 -03:00
api Bug 30708: Adjust spec for train_item 2023-10-20 14:44:05 -03:00
authorities Bug 33406: (QA follow-up) Adjust tests and tidy 2023-09-15 15:50:43 -03:00
basket Bug 34731: Don't call SendQueuedMessages if message_id is bad 2023-09-12 09:44:59 -03:00
bin
C4 Bug 25393: (QA follow-up) simplify auto_renew condition 2023-10-20 16:31:24 -03:00
catalogue Bug 35099: (bug 26314 follow-up) Fix detail view for records with invalid MARCXML 2023-10-20 11:02:52 -03:00
cataloguing Bug 34171: Use barcodedecode when attaching items to another record 2023-10-20 11:43:03 -03:00
circ Bug 34547: Add transfer reason to checkedintable on returns.tt 2023-10-20 11:43:02 -03:00
clubs
course_reserves
debian Bug 30708: Add apache RewriteRule 2023-10-18 15:41:42 -03:00
docs Bug 34800: Adding openhub links for Koha contributors 2023-10-17 14:45:28 -03:00
erm
errors
etc Bug 30708: Add apache RewriteRule 2023-10-18 15:41:42 -03:00
ill Bug 30719: ILL Batches 2023-10-17 14:45:15 -03:00
installer Bug 25393: DBRev 23.06.00.044 2023-10-20 16:31:25 -03:00
Koha Bug 25393: Add new noautorenewalbefore circulation rule 2023-10-20 16:31:17 -03:00
koha-tmpl Bug 35019: Add a CSRF token when deleting news 2023-10-20 17:22:02 -03:00
labels Bug 31633: (follow-up) Group template params 2022-10-03 14:09:59 -03:00
lib/CGI/Session/Serialize
members Bug 34910: (follow-up) alert in patron details 2023-10-18 10:25:59 -03:00
misc Bug 34954: Fixed typo to 'dateexpiry' 2023-10-20 17:22:02 -03:00
offline_circ Bug 32496: Reduce unnecessary unblessings of objects in Circulation.pm 2023-09-22 10:52:39 -03:00
opac Bug 31383: Create a parent-child DB relation for additional content 2023-10-20 14:43:56 -03:00
patron_lists Bug 16446: Add ability to add patrons to list by borrowernumber 2021-10-21 12:24:04 +02:00
patroncards
plugins Bug 30367: (follow-up) Same adjustment for gitlab 2023-05-05 10:18:57 -03:00
pos Bug 34731: Don't call SendQueuedMessages if message_id is bad 2023-09-12 09:44:59 -03:00
preservation Bug 30708: Tidy perl files 2023-10-18 15:42:04 -03:00
recalls
reports Bug 23059: reserve_stats.pl: Simplify reservestatus 2023-10-20 14:44:06 -03:00
reserve Bug 31692: Tidy and rebase fix 2023-10-10 09:58:59 -03:00
reviews
rotating_collections Bug 17600: Standardize our EXPORT_OK 2021-07-16 08:58:47 +02:00
serials Bug 34199: Add full title information to subscription detail page 2023-09-22 11:35:46 -03:00
services
skel
suggestion Bug 26994: List names in alphabetical order in Suggestion filter 2023-10-20 16:31:14 -03:00
svc Bug 25393: (QA follow-up) Tidy 2023-10-20 16:31:24 -03:00
t Bug 34954: Fixed typo to 'dateexpiry' 2023-10-20 17:22:02 -03:00
tags
tools Bug 31383: (QA follow-up) Tidy 2023-10-20 14:44:03 -03:00
virtualshelves Bug 34731: Don't call SendQueuedMessages if message_id is bad 2023-09-12 09:44:59 -03:00
xt Bug 34911: Test files from HEAD instead of 'master' 2023-10-04 09:15:35 -04:00
.editorconfig
.eslintrc.json
.gitignore
.htaccess
.mailmap
.perlcriticrc
.perltidyrc
.proverc.dist
.stylelintrc.json
about.pl Bug 27634: Add a warning to the about page if PatronSelfRegistrationDefaultCategory not set 2023-09-19 16:34:19 -03:00
app.psgi
build-resources.PL
changelanguage.pl
cpanfile Bug 34064: Add SQL::Translator dependency to cpanfile 2023-10-10 10:54:04 -03:00
cypress.config.ts
fix-perl-path.PL
gulpfile.js Bug 35024: Do not wrap translations 2023-10-19 16:00:47 -03:00
help.pl Bug 17600: Standardize our EXPORT_OK 2021-07-16 08:58:47 +02:00
INSTALL
Koha.pm Bug 25393: DBRev 23.06.00.044 2023-10-20 16:31:25 -03:00
koha_perl_deps.pl
kohaversion.pl Bug 26384: Fix executable flags 2020-09-11 09:56:56 +02:00
LICENSE
mainpage.pl Bug 35019: Add a CSRF token when deleting news 2023-10-20 17:22:02 -03:00
Makefile.PL Bug 30708: Add 'preservation' to Makefile.PL 2023-10-20 08:33:34 -03:00
MANIFEST.SKIP
package.json
README
README.md
README.robots
rewrite-config.PL
tsconfig.json
webpack.config.js Bug 30708: Vue app 2023-10-18 15:41:40 -03:00
yarn.lock Bug 34319: Update yarn.lock 2023-09-05 11:52:25 -03:00

Koha is a free software integrated library system (ILS).

Koha is distributed under the GNU GPL version 3 or later.

Note: Koha does not accept pull requests from git hosting sites.

Note: This project has its own bug tracker, to report a bug or submit a patch visit http://bugs.koha-community.org.

For guidelines on submitting patches for Koha please visit https://wiki.koha-community.org/wiki/SubmitingAPatch

The developers handbook can be found at https://wiki.koha-community.org/wiki/Developer_handbook

http://koha-community.org/

Koha Logo