Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MAIN_SECURITY_FORCERP - HTTP_REFERER #29780

Closed
atm-irvine opened this issue May 29, 2024 · 2 comments
Closed

MAIN_SECURITY_FORCERP - HTTP_REFERER #29780

atm-irvine opened this issue May 29, 2024 · 2 comments
Labels
Bug This is a bug (something does not work as expected) Discussion Some questions or discussions are opened and wait answers of author or other people to be processed

Comments

@atm-irvine
Copy link
Contributor

Bug

Because of the MAIN_SECURITY_FORCERP set by default on strict-origin, in v19, it's impossible to keep the list filter in the URL when you clic on "return list" from an object.
Because of this, HTTP_REFERER is equal to the domain name only and not the page you was from.
In v18, MAIN_SECURITY_FORCERP is set on same-origin and the filters are kept when you clic on "Return list" from an object.
HTTP_REFERER works fine.
I would like to know the reasons of this modification.
Normally, it should be the same problem for all users v19.
Will this have any impact on safety ?

Dolibarr Version

19.0

Environment PHP

No response

Environment Database

No response

Steps to reproduce the behavior and expected behavior

No response

Attached files

No response

@atm-irvine atm-irvine added the Bug This is a bug (something does not work as expected) label May 29, 2024
@ksar-ksar
Copy link
Contributor

@ksar-ksar ksar-ksar added the Discussion Some questions or discussions are opened and wait answers of author or other people to be processed label May 30, 2024
@frederic34
Copy link
Contributor

#29698

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug This is a bug (something does not work as expected) Discussion Some questions or discussions are opened and wait answers of author or other people to be processed
Projects
None yet
Development

No branches or pull requests

3 participants