]> source.dussan.org Git - archiva.git/commitdiff
reverted previous csrf fixes committed in -r1081111
authorMaria Odea B. Ching <oching@apache.org>
Tue, 12 Apr 2011 07:07:05 +0000 (07:07 +0000)
committerMaria Odea B. Ching <oching@apache.org>
Tue, 12 Apr 2011 07:07:05 +0000 (07:07 +0000)
git-svn-id: https://svn.apache.org/repos/asf/archiva/branches/archiva-1.3.x@1091313 13f79535-47bb-0310-9956-ffa450edef68

archiva-modules/archiva-web/archiva-webapp/src/main/webapp/WEB-INF/jsp/decorators/default.jsp
archiva-modules/archiva-web/archiva-webapp/src/main/webapp/WEB-INF/jsp/quickSearch.jsp
archiva-modules/archiva-web/archiva-webapp/src/main/webapp/WEB-INF/jsp/results.jsp
archiva-modules/archiva-web/archiva-webapp/src/main/webapp/WEB-INF/web.xml

index 191af1d71c7b471a18109be53de7ceb67c471860..89195fae61b8d23eddcb7b88fce776068b7aae22 100644 (file)
@@ -80,7 +80,7 @@
 
 
 <div id="topSearchBox">
-    <s:form method="post" action="quickSearch" namespace="/" validate="true">
+    <s:form method="get" action="quickSearch" namespace="/" validate="true">
         <s:textfield label="Search for" size="30" name="q"/>
     </s:form>
 </div>
index 7b0c39c56cbd136ee03302980c047e6505128e15..8dbf9b438facbd5a627c807858e7672e42bf7f51 100644 (file)
@@ -94,7 +94,7 @@
 
   <c:url var="iconCreateUrl" value="/images/icons/create.png" />
   
-  <s:form method="post" id="quickSearch" action="quickSearch" validate="true">    
+  <s:form method="get" id="quickSearch" action="quickSearch" validate="true">    
     <s:textfield label="Search for" size="50" name="q"/> 
     <s:hidden name="completeQueryString" value="%{completeQueryString}"/>  
     <s:submit value="Search"/>         
     </tr>
     <tr>
       <td>    
-        <s:form id="filteredSearch" method="post" action="filteredSearch" validate="true">
+        <s:form id="filteredSearch" method="get" action="filteredSearch" validate="true">  
           <label><strong>Advanced Search Fields: </strong></label><s:select name="searchField" list="searchFields" theme="simple"/> 
           <s:a href="#" title="Add Search Field" onclick="addSearchField( document.filteredSearch.searchField.options[document.filteredSearch.searchField.selectedIndex].text, document.filteredSearch.searchField.value, 'dynamicFields' )" theme="simple">
             <img src="${iconCreateUrl}" />
index ae8e5f8a21832932ccf9cf274dab1e29d72de412..bc6c4a5f2b4590205947b60683c23ea8e7561146 100644 (file)
@@ -85,7 +85,7 @@
         </tr>
         <tr>
           <td>
-          <s:form id="filteredSearch" method="post" action="filteredSearch" validate="true">
+          <s:form id="filteredSearch" method="get" action="filteredSearch" validate="true">
             <s:hidden name="fromFilterSearch" value="%{#attr.fromFilterSearch}" theme="simple"/>  
             <label><strong>Advanced Search Fields: </strong></label><s:select name="searchField" list="searchFields" theme="simple"/> 
             <s:a href="#" title="Add Search Field" onclick="addSearchField( document.filteredSearch.searchField.options[document.filteredSearch.searchField.selectedIndex].text, document.filteredSearch.searchField.value, 'dynamicFields' )" theme="simple">
       </table>
     </c:if>
     <c:if test="${fromFilterSearch == false}">
-      <s:form method="post" action="quickSearch" validate="true">
+      <s:form method="get" action="quickSearch" validate="true">
         <s:textfield label="Search for" size="50" name="q"/>
         <s:checkbox label="Search within results" name="searchResultsOnly"/>        
         <s:hidden name="completeQueryString" value="%{#attr.completeQueryString}"/>        
index cad63b21eda55a68d6731693e866237a7f2103e7..b4fb373d0ba5ab3111c5184cd8ee65b76961c734 100644 (file)
           <filter-class>org.apache.struts2.dispatcher.ActionContextCleanUp</filter-class>
         </filter>
 
-  <!-- To enable this filter, uncomment the corresponding filter-mapping -->
-  <filter>
-    <filter-name>redback-csrf</filter-name>
-    <filter-class>org.codehaus.plexus.redback.struts2.filter.RedbackCSRFFilter</filter-class>
-    <init-param>
-      <param-name>nonceCacheSize</param-name>
-      <param-value>20</param-value>
-    </init-param>
-    <init-param>
-      <param-name>excludedPaths</param-name>
-      <param-value>/css/**,/images/**,/struts/**,/favicon.ico,/js/**,//repository/**,//xmlrpc/**,//feeds/**</param-value>
-    </init-param>
-  </filter>
-
-
        <filter>
                <filter-name>sitemesh</filter-name>
                <filter-class>
                        <param-name>forceEncoding</param-name>
                        <param-value>true</param-value>
                </init-param>
-       </filter>
-
-  <!-- Uncomment this to apply the CSRF filter mapping in Archiva
-  <filter-mapping>
-    <filter-name>redback-csrf</filter-name>
-    <url-pattern>/*</url-pattern>
-  </filter-mapping>
-  -->
-
+       </filter>  
+  
        <filter-mapping>
                <filter-name>encodingFilter</filter-name>
                <url-pattern>/*</url-pattern>
        </filter-mapping>
 
-  <!-- this must be before the sitemesh filter -->
-  <filter-mapping>
-    <filter-name>webwork-cleanup</filter-name>
-    <url-pattern>/*</url-pattern>
-  </filter-mapping>
+       <!-- this must be before the sitemesh filter -->
+       <filter-mapping>
+               <filter-name>webwork-cleanup</filter-name>
+               <url-pattern>/*</url-pattern>
+       </filter-mapping>
 
        <filter-mapping>
                <filter-name>sitemesh</filter-name>