fix: account deletion is a CSRF POST, not a GET with the secret in the URL - #527
Open
t0ma5 wants to merge 1 commit into
Open
fix: account deletion is a CSRF POST, not a GET with the secret in the URL#527t0ma5 wants to merge 1 commit into
t0ma5 wants to merge 1 commit into
Conversation
…e URL GET ?page=user&action=delete used to remove the account as soon as the page was requested. It now shows a confirm form; delete_post requires CSRF and the current password. Existing theme links with id and secret land on the confirm page. Co-authored-by: Cursor <cursoragent@cursor.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
?page=user&action=delete&id=&secret=used to delete the signed-in account on GET. A mail scanner, prefetch, or leaked referrer was enough.delete_postwith a CSRF token and the current password. The session user is used; query id/secret are ignored.user-delete_account.php; core falls back tooc-includes/osclass/gui/when they do not.osc_user_delete_url()is the helper to print (no secret)..potrefs stay POSIX on Windows sonpm run i18ndoes not rewrite every path.Test plan
php tests/user-delete-get.php?page=user&action=delete&id=YOUR_ID&secret=YOUR_SECRET(old theme link): confirm page, account still existsdelete_postdoes not deleteuser-delete_account.phpstill renders the core fallback inside header/footer