instiki/app
Jacques Distler 2484542f12 Security: HTTP GET Bypassed Spam Protection
Apparently, the form_spam_protect plugin only works with HTTP POST, not GET.
Unsafe operations (save and file-upload) should be POSTs anyway.
Fixed.

Also, two broken tests fixed. Only two Unit Tests now fail: both are minor bugs in XHTMLDiff.
2007-10-07 01:59:50 -05:00
..
controllers Security: HTTP GET Bypassed Spam Protection 2007-10-07 01:59:50 -05:00
helpers rel=nofollow 2007-09-27 20:04:27 -05:00
models Sync with Instiki Trunk 2007-05-11 11:47:38 -05:00
views Whoops! 2007-10-04 15:46:20 -05:00