See part 1for how we got here and part 2 for how we changed the OWASP filter. Code cleanup and problems There is some poorly written code in JForum that CSRF now prevents from working. In these cases, I needed to clean up our code. For example: Links/anchors shouldn’t be used to update state. They should [...]
↧