Opened 14 years ago

Closed 14 years ago

Last modified 12 years ago

#2517 closed defect (wontfix)

Deletions are done using a GET request

Reported by: jacob@… Owned by: xris
Priority: minor Milestone: unknown
Component: mythweb Version: 0.20
Severity: medium Keywords:
Cc: Ticket locked: no

Description

As reported on the mailing list ( http://www.gossamer-threads.com/lists/mythtv/users/228058 ), a visit by a web bot, such as googlebot, will cause all recordings to be lost. This is caused by the fact that deletions are done using a link that does a GET request instead of a POST. Conventional wisdom says that any action which will cause a permanent change be done using a POST. This may only be using the "compact" skin.

Change History (2)

comment:1 Changed 14 years ago by xris

Resolution: wontfix
Status: newclosed

Until you can tell me how an href can submit via post, it'll have to stay this way.

A less kind answer could also be "whoever leaves their mythweb open and unsecured to the internet at large deserves whatever problems they invite by doing so".

comment:2 Changed 12 years ago by anonymous

Make it a small simple form with a hidden field for recording ID.

Then either (a) replace link with submit button or (b) give link onclick action which submits form.

Note: See TracTickets for help on using tickets.