Skip to content
Snippets Groups Projects
  1. Jul 24, 2013
  2. Jul 17, 2013
  3. Feb 28, 2013
  4. Feb 22, 2013
  5. Feb 20, 2013
  6. Dec 14, 2012
  7. Oct 29, 2012
  8. Oct 28, 2012
  9. Oct 08, 2012
  10. Jul 25, 2012
  11. Jul 23, 2012
  12. Jul 20, 2012
  13. Jul 09, 2012
  14. Jun 20, 2012
    • Jared Hancock's avatar
      Implement simple CSRF protection scheme · ff1d8b9e
      Jared Hancock authored
      Protect againts cross-site request forgery attacks by requiring a special
      form-field or header to be sent with requests that modify ticket system
      data.
      
      This meant a slight change to the AJAX ticket locking mechanism. It was
      defined to lock with a GET request; however, GET requests are defined as
      safe methods and should not modify backend data (such as a lock
      acquisition). Therefore, the the lock acquire AJAX method was changed to
      require a POST method.
      
      Also remove old, no-longer-used staff panel include files
      ff1d8b9e
  15. Apr 29, 2012
  16. Apr 27, 2012
  17. Apr 22, 2012
  18. Apr 09, 2012
  19. Apr 01, 2012
  20. Mar 30, 2012
  21. Mar 26, 2012
  22. Mar 19, 2012
Loading