XMLWordPrintableJSON

Details

    • Sub-task
    • Status: Closed
    • Major
    • Resolution: Duplicate
    • Release Branch 09.04, Trunk
    • Release Branch 09.04, Trunk
    • order
    • None
    • Bug Crush Event - 21/2/2015

    Description

      Another one found in error.log

      2009-04-19 13:49:51,262 (TP-Processor17) [ RequestHandler.java:399:ERROR] Request createOrderAdjustment caused an error with the following message: Error calling event: org.ofbiz.webapp.event.EventHandlerException: Found URL parameter [orderId] passed to secure (https) request-map with uri [createOrderAdjustment] with an event that calls service [createOrderAdjustment]; this is not allowed for security reasons! The data should be encrypted by making it part of the request body (a form field) instead of the request URL.

      but this one is another exception : (paramString contains orderId...)

      <form name="addAdjustmentForm" method="post" action="<@ofbizUrl>createOrderAdjustment?${paramString}</@ofbizUrl>">

      The decision on ML is to rewrite all (upstream). More work but certainly the better solution...

      Attachments

        Activity

          People

            Unassigned Unassigned
            jleroux Jacques Le Roux
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: