We can customise the dLocal return_url aka callback_url on a per-request basis, so let's add the wmf_token field, as suggested by @Damilare, to make our forms more secure. It's unclear why we didn't do this with the old streamline integration, but it looks like we can do it with the new integration.
Description
Description
Details
Details
Subject | Repo | Branch | Lines /- | |
---|---|---|---|---|
Add 'wmf_token' CSRF protection to dLocal forms | mediawiki/extensions/DonationInterface | master | 35 -14 |
Event Timeline
Comment Actions
Change 896106 had a related patch set uploaded (by Damilare Adedoyin; author: Damilare Adedoyin):
[mediawiki/extensions/DonationInterface@master] Add 'wmf_token' CSRF protection to dLocal forms
Comment Actions
Change 896106 merged by jenkins-bot:
[mediawiki/extensions/DonationInterface@master] Add 'wmf_token' CSRF protection to dLocal forms