Edgewall Software

Opened 3 years ago

Last modified 3 years ago

#13348 closed defect

Pref panel on roadmap page adds __FORM_TOKEN to GET request — at Initial Version

Reported by: Cinc-th Owned by:
Priority: normal Milestone: 1.4.3
Component: roadmap Version: 1.4.2
Severity: normal Keywords:
Cc: Branch:
Release Notes:
API Changes:
Internal Changes:

Description

When changing the preferences on the roadmap page (e.g. Show completed milestones) and clicking Update a new GET request is sent to Trac.

The GET request has __FORM_TOKEN added as a parameter. This can be seen on this running instance of Trac, too. IMHO the token shouldn't be added for a GET request.

The template where this happens is:

trunk/trac/ticket/templates/roadmap.html@17500:29#L27

Tested with Trac 1.4.2.

Change History (0)

Note: See TracTickets for help on using tickets.