-
- Downloads
[IMP] website_sale: /shop/cart/update as POST with csrf
The /shop/cart/update was accepting both GET and POST request. Therefore,
we couldn't have csrf on the route meaning any website could change your
cart if the route was known.
task-2263776
closes odoo/odoo#51486
Signed-off-by:
Jérémy Kersten (jke) <jke@openerp.com>
Showing
- addons/website_sale/controllers/main.py 1 addition, 1 deletionaddons/website_sale/controllers/main.py
- addons/website_sale/static/src/js/website_sale.js 8 additions, 18 deletionsaddons/website_sale/static/src/js/website_sale.js
- addons/website_sale_comparison/views/website_sale_comparison_template.xml 1 addition, 0 deletions...ale_comparison/views/website_sale_comparison_template.xml
- addons/website_sale_slides/static/src/js/slides_course_join.js 5 additions, 2 deletions...s/website_sale_slides/static/src/js/slides_course_join.js
- addons/website_sale_slides/views/website_slides_templates.xml 1 addition, 1 deletion...ns/website_sale_slides/views/website_slides_templates.xml
Loading
Please register or sign in to comment