- Notifications
You must be signed in to change notification settings - Fork243
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
🐛 Use Cancel-Button results in Ajax-Unauthorized Response#701
base:develop
Are you sure you want to change the base?
Conversation
When calling cancel button in edit or creation dialog the ajax request responded with unauthorized 401. This results in login mask when using IIS with Windows Authentication. You can continue to use itop without enter credentials, but it appears everytime canceling a edit mask. The reason is the Transaction_id validation in ajax.render.php failed. After changing the ReadPostedParam Parameter "sSanitizationFilter" from default "parameter" to "transaction_id" the validation is true and itop is handleling everything fine.
Hello, thanks for your contribution :) |
Hello, thanks for your info. |
Base information
Symptom (bug) / Objective (enhancement)
When calling "cancel button" in edit or creation dialog the ajax request responded with unauthorized 401. This results in login mask when using IIS with Windows Authentication. You can continue to use itop without enter credentials, but it appears everytime canceling a edit/new mask. The reason is the Transaction_id validation in ajax.render.php failed. After changing the ReadPostedParam Parameter "sSanitizationFilter" from default "parameter" to "transaction_id" the validation is true and itop is handleling everything fine.
Reproduction procedure (bug)
Cause (bug)
The reason is when unloading the new object page or edit page the unload function calls a function where the transaction_id verification failed.
Proposed solution (bug and enhancement)
Editing one line in ajax.render.php for header and transaction_id check from using the default parameters of ReadPostedParam to specific parameter "transaction_id" as sSanitizationFilter
Checklist before requesting a review
Checklist of things to do before PR is ready to merge