From fe259aba572e08df22557251ca9279f512f6862c Mon Sep 17 00:00:00 2001 From: Simon Bennetts Date: Wed, 4 Apr 2018 18:21:33 +0100 Subject: Bug 1446431 - Allow Baseline scan to ignore forms that dont need CSRF Tokens The data-no-csrf attribute is used to signify that a form is 'safe' (ie doesn't actually make any permanent changes) and so doesn't need an anti-csrf token. --- template/en/default/search/search-advanced.html.tmpl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'template/en/default/search/search-advanced.html.tmpl') diff --git a/template/en/default/search/search-advanced.html.tmpl b/template/en/default/search/search-advanced.html.tmpl index 60f47a916..b51906774 100644 --- a/template/en/default/search/search-advanced.html.tmpl +++ b/template/en/default/search/search-advanced.html.tmpl @@ -60,7 +60,7 @@ function remove_token() {

Hover your mouse over each field label to get help for that field.

+ onsubmit="remove_token()" data-no-csrf> [% PROCESS search/form.html.tmpl %] -- cgit v1.2.3-24-g4f1b