Skip to content
Snippets Groups Projects
Commit 8edac8ab authored by DramixDw's avatar DramixDw Committed by Jeremy Kersten
Browse files

[IMP] website_sale: /shop/cart/update as POST with csrf


The /shop/cart/update was accepting both GET and POST request. Therefore,
we couldn't have csrf on the route meaning any website could change your
cart if the route was known.

task-2263776

closes odoo/odoo#51486

Signed-off-by: default avatarJérémy Kersten (jke) <jke@openerp.com>
parent 0f2cada3
No related branches found
No related tags found
No related merge requests found
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment