This was a contentious change is generally a bad idea to blanket all requests with a dependant cookie. We will try something else. Revert enableXsrfCookies setting. Fixes UX issue introduced where the token expires. This should be replaced by a CSRF policy that determines whether this is needed on the front end. |
||
|---|---|---|
| .. | ||
| AuthManager.php | ||
| BackendController.php | ||
| Controller.php | ||
| ControllerBehavior.php | ||
| FilterScope.php | ||
| FormField.php | ||
| FormTabs.php | ||
| FormWidgetBase.php | ||
| ListColumn.php | ||
| NavigationManager.php | ||
| ReportWidgetBase.php | ||
| Skin.php | ||
| WidgetBase.php | ||
| WidgetManager.php | ||