Activity

From 2017-03-31 to 2017-04-29

2017-04-26

03:54 Bug #158 (Closed): Can't pay by Bitcoin - CSRF error
Thanks. I have also moved the blockchain data onto SSD-backed storage which will hopefully help prevent the daemon ge... admin
03:47 Bug #158: Can't pay by Bitcoin - CSRF error
Works, receives payment, marks invoice as paid. Looks closable.
jetalone

2017-04-24

03:21 Bug #158: Can't pay by Bitcoin - CSRF error
Sorry, that is just the result of a timeout while the bitcoind was busy catching up with the blockchain. I need to ma... admin
02:58 Bug #158: Can't pay by Bitcoin - CSRF error
We're sorry, there was a problem with our bitcoin server. We've now been made aware of the problem and are looking in... jetalone
02:43 Bug #158 (Feedback): Can't pay by Bitcoin - CSRF error
I believe this is now fixed. Please could you give it another try? Thanks! admin

2017-04-23

23:52 Bug #158 (In Progress): Can't pay by Bitcoin - CSRF error
Sorry about that. Will be a bug introduced when adding anti-Cross Site Request Forgery checks for issue #156. Looking... admin
23:43 Bug #158 (Closed): Can't pay by Bitcoin - CSRF error
The error is "Anti-CSRF token missing!"; I tried both Safari 10.1 (11603.1.30.0.34) and Firefox 52.0.2 on OS X 10.11.6. jetalone

2017-04-11

15:46 Feature #157 (New): Reduce idle timeout on security-sensitive pages
The default session timeout of 30 minutes may not be appropriate for security-sensitive pages. Consider reducing it (... admin
13:50 Bug #156 (Resolved): Secure all forms against CSRF
All remaining forms have now been secured against CSRF. admin

2017-04-09

21:13 Bug #156: Secure all forms against CSRF
Done:
> * /account/invoices/pay/
admin

2017-04-08

21:29 Bug #156: Secure all forms against CSRF
Done:
> * /account/
admin
18:43 Bug #156: Secure all forms against CSRF
These two done (on test site):
> * /xfer/
> * /account/config/
admin

2017-04-06

15:10 Bug #156: Secure all forms against CSRF
As the remaining forms are only for trivial uses, or redirect to third party suppliers (e.g. for payment), there's pr... admin

2017-04-04

20:19 Bug #156 (Closed): Secure all forms against CSRF
A number of forms on the Panel are susceptible to Cross-Site Request Forgery. Any form which does a POST will need pr... admin
« Previous
Next »
 

Also available in: Atom