1. 19 Jan, 2017 1 commit
    • Vincent Pelletier's avatar
      Base_callDialogMethod: Do not redirect when form has a password field. · fc297215
      Vincent Pelletier authored
      If it is the case *and* the action script does not redirect, the password will be
      in user's browser history.
      There can be two different reasons to not redirect:
      - not following the API (ie, intentionally not redirecting)
      - letting an exception reach ZPublisher
      Also, if the non-redirection causes an HTML page to be rendered, resources
      loaded by that page will have a referrer containing the password, leaking it
      to potentially foreign servers.
      fc297215
  2. 18 Jan, 2017 10 commits
  3. 17 Jan, 2017 13 commits
  4. 16 Jan, 2017 1 commit
  5. 14 Jan, 2017 1 commit
  6. 13 Jan, 2017 2 commits
  7. 12 Jan, 2017 8 commits
  8. 11 Jan, 2017 1 commit
  9. 10 Jan, 2017 3 commits