Fix #593 incorrect result from checkCSRF() in GET+JSON request

This commit is contained in:
Kijin Sung 2016-09-25 12:35:50 +09:00
parent 9a1936de40
commit 4f52122a3c

View file

@ -307,11 +307,6 @@ class Security
*/ */
public static function checkCSRF($referer = null) public static function checkCSRF($referer = null)
{ {
if ($_SERVER['REQUEST_METHOD'] !== 'POST')
{
return false;
}
if (!$referer) if (!$referer)
{ {
$referer = strval($_SERVER['HTTP_REFERER']); $referer = strval($_SERVER['HTTP_REFERER']);