Files
odoo_source/addons/website_form/controllers
Laurent Stukkens (LTU) b192d8d23f [FIX] website_form: allow to submit form without csrf if not logged
Chrome recently changed their SameSite policy default value from None to Lax,
the session is no more shared between the webpage and the iframe.
As a result, the csrf check systematically fails.

After this commit, the csrf_token check is only made when you have a session.

In case you are using your form in an iframe on another site, with the new
cookies policy, your cookies with the session_id (linked to the csrf token)
is not sent to the server and the check csrf always fails.

Since the purpose of the csrf is to prevent another website to submit a form
with your 'authenticated account', we can consider that if you are not logged
and so have no session_id, it is no critical and we can ignore the csrf check.

opw-2330286

closes odoo/odoo#58050

X-original-commit: 9a0c9f3192bc7043add89446cbe6c2650499a654
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-09-18 15:09:51 +00:00
..
…