Details

    • Sub-task
    • Status: Closed
    • Major
    • Resolution: Fixed
    • Release Branch 13.07, Release Branch 14.12, Release Branch 15.12, Trunk
    • 14.12.01, 15.12.01, 13.07.04
    • ecommerce
    • None
    • Bug Crush Event - 21/2/2015

    Description

      Steps to reproduce:
      1) Go to eCommerce
      2) Click on shopping list tab
      3) Click on create new link

      Getting following security error:

      Error calling event: org.ofbiz.webapp.event.EventHandlerException: Found URL parameter [productStoreId] passed to secure (https) request-map with uri [createEmptyShoppingList] with an event that calls service [createShoppingList]; this is not allowed for security reasons! The data should be encrypted by making it part of the request body (a form field) instead of the request URL.

      Attachments

        1. OFBIZ-7270.patch
          2 kB
          Mohammed Rehan Khan
        2. OFBIZ-7270.patch
          2 kB
          Mohammed Rehan Khan
        3. OFBIZ-7270-Releases.patch
          2 kB
          Mohammed Rehan Khan

        Activity

          People

            pandeypranay Pranay Pandey
            rehan.khan Mohammed Rehan Khan
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: