Skip to content

fix(admin): send the CSRF token in the request body and drop the tables on delete - #10

Merged
anoziere merged 4 commits into
mainfrom
fix/backoffice-token-in-body
Oct 5, 2026
Merged

anoziere merged 4 commits into
mainfrom
fix/backoffice-token-in-body

Conversation

@anoziere

@anoziere anoziere commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

default-twig 1.2.0 removed the token_url() Twig function, so the rule list now fails with a 500: Unknown "token_url" function in "QueryBuilder/rule-list.html.twig" at line 85.

Changes:

  • The toggle and delete forms of rules and actions post to path() and carry the CSRF token in a hidden _token field. The four controller actions read it with checkRequestToken(), so the token is never sent in the URL.
  • destroy() drops query_builder_suggestion, query_builder_action and query_builder_rule when the module is deleted with its data. Before, the three tables were left behind.

Checked on a fresh thelia/thelia-project 3.2.0 shop with demo data:

  • Published 2.1.0: /admin/query_builder returns 500. Deleting the module with its data leaves the three tables.
  • This branch: the list and edit pages return 200. Rule toggle and delete and action toggle and delete were run from the browser, and each one changed the database as expected. No token appears in any URL, and the log has no query-string token deprecation.
  • Deleting the module with its data drops the three tables. Reinstalling it creates them again.

@anoziere
anoziere merged commit 62c61e8 into main Oct 5, 2026
3 checks passed
@anoziere
anoziere deleted the fix/backoffice-token-in-body branch October 5, 2026 06:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant