Explorar o código

Mark many as read must be a POST action

See https://github.com/marienfressinaud/FreshRSS/issues/599
Marien Fressinaud %!s(int64=11) %!d(string=hai) anos
pai
achega
1e5efc9299
Modificáronse 1 ficheiros con 4 adicións e 0 borrados
  1. 4 0
      app/Controllers/entryController.php

+ 4 - 0
app/Controllers/entryController.php

@@ -45,6 +45,10 @@ class FreshRSS_entry_Controller extends Minz_ActionController {
 
 		$entryDAO = FreshRSS_Factory::createEntryDao();
 		if ($id == false) {
+			if (!Minz_Request::isPost()) {
+				return;
+			}
+
 			if (!$get) {
 				$entryDAO->markReadEntries ($idMax);
 			} else {