提交 23fc934c 编写于 作者: O OHTAKE Tomohiro

[FIXED JENKINS-7847] Require POST for doConfigSubmit on jobs

上级 d951f381
......@@ -56,8 +56,8 @@ Upcoming changes</a>
<div id="trunk" style="display:none"><!--=TRUNK-BEGIN=-->
<ul class=image>
<li class=bug>
Configuring view when not logged in wipes view configuration
(<a href="https://issues.jenkins-ci.org/browse/JENKINS-11397">issue 11397</a>)
GET request to configSubmit wipes some configuration
(<a href="https://issues.jenkins-ci.org/browse/JENKINS-11397">issue 11397</a>, <a href="https://issues.jenkins-ci.org/browse/JENKINS-7847">issue 7847</a>)
</ul>
</div><!--=TRUNK-END=-->
......
......@@ -941,6 +941,7 @@ public abstract class Job<JobT extends Job<JobT, RunT>, RunT extends Run<JobT, R
public synchronized void doConfigSubmit(StaplerRequest req,
StaplerResponse rsp) throws IOException, ServletException, FormException {
checkPermission(CONFIGURE);
requirePOST();
description = req.getParameter("description");
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册