Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-55034

GET request Includes sesskey during External Blog deletion

XMLWordPrintable

      When deleting a External Blog entry from a user profile, the GET is showing the referer address with the sesskey value of the user session. This can be seen using Chrome Developer Tools Networking.

      Steps to Replicate

      1. Ensure that External Blogs are enabled in the system
      2. Go to User Profile
      3. Preferences > External Blogs
      4. Add an External Blog RSS Feed and save
      5. Open up Developer Tools in Chrome
      6. Go to Networking
      7. Go back to the Moodle page
      8. Unregister/Delete blog in Moodle
      9. Look at the GET transactions (specifically Javascript)
      10. There will be one that has a referer that looks like the following:
        https://<URL>/blog/external_blogs.php?delete=2&sesskey=<sesskey>

      The system should not be sending a sesskey value as part of the GET

            pholden Paul Holden
            kmccarthy Kevin McCarthy
            Andrew Gosali Andrew Gosali
            Sara Arjona (@sarjona) Sara Arjona (@sarjona)
            Kim Jared Lucas Kim Jared Lucas
            Votes:
            2 Vote for this issue
            Watchers:
            11 Start watching this issue

              Created:
              Updated:
              Resolved:

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 1 hour, 49 minutes
                1h 49m

                  Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.