https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=43312 --- Comment #3 from Laura Escamilla <Laura.escamilla@bywatersolutions.com> --- Created attachment 206309 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206309&action=edit Bug 43312: Add CSRF header to opac-user.tt article request cancellation The OPAC does not have the api-client.js infrastructure yet. As a minimal fix, this adds the CSRF-TOKEN header manually to the jQuery.ajax DELETE call for cancelling article requests. The token is read from the csrf-token meta tag which is already present in the OPAC head. Test plan: 1. Apply patch 2. Log into the OPAC as a patron with an article request 3. Go to Your account > click cancel on an article request => SUCCESS: Request cancelled without 403 error 4. Sign off :-D Signed-off-by: Owen Leonard <oleonard@myacpl.org> Signed-off-by: Laura_Escamilla <laura.escamilla@bywatersolutions.com> -- You are receiving this mail because: You are watching all bug changes.