Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 295445

CSRF token generation incompatible with optional route parameters

$
0
0

RouteProcessorCsrf::processOutbound() does not take into account optional parameters when calculating a CSRF token, leading on-request validation to fail on a generated route in which one or more parameters were not provided at the time of generation.


Viewing all articles
Browse latest Browse all 295445


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>