Opened 16 years ago
Closed 14 years ago
#5045 closed defect (bug) (worksforme)
"Delete Post" / "Delete Draft" without JavaScript abuses nonce protection
Reported by: |
|
Owned by: | |
---|---|---|---|
Milestone: | Priority: | normal | |
Severity: | normal | Version: | 2.3 |
Component: | Accessibility | Keywords: | |
Focuses: | Cc: |
Description
If the "Delete Post" / "Delete Draft" button is clicked without JavaScript enabled (on the Write screen), a nonce error page is presented. This is an abuse of the nonce functionality (which is there for anti-CSRF).
Attachments (1)
Change History (5)
Note: See
TracTickets for help on using
tickets.
still current?