Skip to content
Snippets Groups Projects
  1. Oct 29, 2012
  2. Oct 28, 2012
  3. Oct 08, 2012
  4. Jul 25, 2012
  5. Jul 23, 2012
  6. Jul 20, 2012
  7. Jul 09, 2012
  8. Jun 20, 2012
    • Jared Hancock's avatar
      Implement simple CSRF protection scheme · ff1d8b9e
      Jared Hancock authored
      Protect againts cross-site request forgery attacks by requiring a special
      form-field or header to be sent with requests that modify ticket system
      data.
      
      This meant a slight change to the AJAX ticket locking mechanism. It was
      defined to lock with a GET request; however, GET requests are defined as
      safe methods and should not modify backend data (such as a lock
      acquisition). Therefore, the the lock acquire AJAX method was changed to
      require a POST method.
      
      Also remove old, no-longer-used staff panel include files
      ff1d8b9e
  9. Apr 29, 2012
  10. Apr 27, 2012
  11. Apr 22, 2012
  12. Apr 09, 2012
  13. Apr 01, 2012
  14. Mar 30, 2012
  15. Mar 26, 2012
  16. Mar 19, 2012
Loading