From 787fc31935b60c5e35509f7a395be1e9815979f8 Mon Sep 17 00:00:00 2001 From: Dan Scott Date: Sat, 4 Aug 2012 10:26:25 -0400 Subject: [PATCH] TPAC locale picker: use POST instead of GET Users could (deliberately or not) change another's language preferences by sharing links with the "set_eg_locale" GET param given the locale picker's current behaviour. By switching to a POST param, we prevent this result from accidentally occurring. Signed-off-by: Dan Scott Signed-off-by: Art Rhyno --- Open-ILS/src/templates/opac/parts/locale_picker.tt2 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Open-ILS/src/templates/opac/parts/locale_picker.tt2 b/Open-ILS/src/templates/opac/parts/locale_picker.tt2 index c3943a61de..c81f1f134d 100644 --- a/Open-ILS/src/templates/opac/parts/locale_picker.tt2 +++ b/Open-ILS/src/templates/opac/parts/locale_picker.tt2 @@ -1,7 +1,7 @@ [%- IF ctx.locales.keys.size > 1; set_locale = CGI.param('set_eg_locale') || CGI.cookie('eg_locale'); %] -
+ [%- FOREACH param IN CGI.params(); -%] [%- NEXT IF param.key == 'set_eg_locale'; -%] -- 2.11.0