SECURITY: Make sure export CSV is generated via a POST

This commit is contained in:
Robin Ward
2015-07-24 12:33:53 -04:00
parent c78dbb7fa5
commit 29439e5534
10 changed files with 33 additions and 78 deletions

View File

@@ -491,7 +491,7 @@ Discourse::Application.routes.draw do
resources :export_csv do
collection do
get "export_entity" => "export_csv#export_entity"
post "export_entity" => "export_csv#export_entity"
end
member do
get "" => "export_csv#show", constraints: { id: /[^\/]+/ }