Skip to content

Commit a87c5e2

Browse files
authored
Merge pull request #1344 from EC-CUBE/fix/security-csrf-delivery-delete
Fix CSRF: お届け先削除をPOSTリクエストに限定
2 parents cbde274 + a65e07b commit a87c5e2

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

data/class/pages/mypage/LC_Page_Mypage_Delivery.php

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,9 @@ class LC_Page_Mypage_Delivery extends LC_Page_AbstractMypage_Ex
3333
/** @var array */
3434
public $arrOtherDeliv;
3535

36+
/** POST に限定する mode */
37+
public $arrLimitPostMode = ['delete'];
38+
3639
/**
3740
* Page を初期化する.
3841
*

0 commit comments

Comments
 (0)