CSRF Tokens not working properly

Created on 4 March 2025, 6 days ago

Problem/Motivation

I may be missing something, but here is what I am seeing:

I have tokens enabled for all roles.

If I copy the url from a product using a logged in user, then open a new browser where Im not logged in (completely different browser, new session) and paste that url, The product is added to the cart.

This bypasses the whole point of the token, no? Any user can use any ones tokens.

Search engines could crawl these links, adding items to a cart.

Am I correct in assuming that only the current user should be able to use the link shown to them? If thats not the intended purpose, what is?

Thanks!

πŸ› Bug report
Status

Active

Version

2.1

Component

Code

Created by

πŸ‡ΊπŸ‡ΈUnited States loze Los Angeles

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024