XMLWordPrintableJSON

    Details

    • Sprint:
      Bug Crush Event - 21/2/2015

      Description

      When trying to remove a product feature from the quick admin page of a product, you get the following error :

      The Following Errors Occurred:
      
      Error calling event: org.ofbiz.webapp.event.EventHandlerException: Found URL parameter [productId] passed to secure (https) request-map with uri [quickAdminRemoveFeatureFromProduct] with an event that calls service [removeFeatureFromProduct]; this is not allowed for security reasons! The data should be encrypted by making it part of the request body (a form field) instead of the request URL. Moreover it would be kind if you could create a Jira sub-task of https://issues.apache.org/jira/browse/OFBIZ-2330 (check before if a sub-task for this error does not exist). If you are not sure how to create a Jira issue please have a look before at http://cwiki.apache.org/confluence/x/JIB2 Thank you in advance for your help.
      

      As the error aks for, I'm creating this Jira.
      I checked in the created sub-task and this one was not registered (but there was one for removing feature in Product Category).

      Step to reproduce the error :

        Attachments

        1. OFBIZ-7319.patch
          2 kB
          Ravi Lodhi

          Activity

            People

            • Assignee:
              jacques.le.roux Jacques Le Roux
              Reporter:
              Florian M Montalbano Florian
            • Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: