]> gitweb.erp-flowers.ru Git - erp24_rep/yii-erp24/.git/commit
fix(ERP-244): fix CSRF validation error in ShiftReminderController origin/feature_filippov_ERP-244_fix_shift_reminder_csrf
authorAleksey Filippov <Aleksey.Filippov@erp-flowers.ru>
Fri, 27 Feb 2026 15:06:41 +0000 (18:06 +0300)
committerAleksey Filippov <Aleksey.Filippov@erp-flowers.ru>
Fri, 27 Feb 2026 15:06:41 +0000 (18:06 +0300)
commit6e11256592740b066cb6a78f88f4fc85eb5f846f
treef44dbbf028dc095efcc3b6412b54b3dbc159e40b
parentf43ff2de8eafd71438e05da2a6412ce336450962
fix(ERP-244): fix CSRF validation error in ShiftReminderController

- Disable CSRF validation on ShiftReminderController: endpoint is
  protected by session authentication (AccessControl, roles=['@']).
  CSRF cookies may be absent in browsers with strict privacy settings,
  causing false 400 errors for legitimate authenticated users.
- Stop retrying on 400/401/403 responses in shift-reminder.js to prevent
  cascading error floods in logs when auth/validation fails.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
erp24/controllers/ShiftReminderController.php
erp24/web/js/shift-reminder.js