[Koha-bugs] [Bug 36349] Login for SCO/SCI broken by CSRF

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Sun Mar 24 01:29:16 CET 2024


https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=36349

--- Comment #17 from Victor Grousset/tuxayo <victor at tuxayo.net> ---
oops, I though the confusion was about whether or not both SCI and SCO were
affected by the bug. Turns out patches indeed addresses both even if touching
opac/sci/sci-main.pl wasn't needed.

---

Anyway, found this while testing:
1. Open both
  http://localhost:8080/cgi-bin/koha/sci/sci-main.pl
  and http://localhost:8080/cgi-bin/koha/sco/sco-main.pl
2. log in and log out from SCI
3. go back to the SCO tab and try to log in
4. "The form submission failed (Wrong CSRF token). Try to come back, refresh
the page, then try again."

That would likely only affect testing scenarios depending on detailed testing
habits about when opening stuff. So not much impact likely.
I don't know if the cause of that could still have a wider relevance.

-- 
You are receiving this mail because:
You are watching all bug changes.


More information about the Koha-bugs mailing list