From 1e5efc92993feddb7916ef675010d0de0e470ac5 Mon Sep 17 00:00:00 2001 From: Marien Fressinaud Date: Tue, 16 Sep 2014 14:23:04 +0200 Subject: Mark many as read must be a POST action See https://github.com/marienfressinaud/FreshRSS/issues/599 --- app/Controllers/entryController.php | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'app/Controllers') diff --git a/app/Controllers/entryController.php b/app/Controllers/entryController.php index ac43587ea..ab66d9198 100755 --- a/app/Controllers/entryController.php +++ b/app/Controllers/entryController.php @@ -45,6 +45,10 @@ class FreshRSS_entry_Controller extends Minz_ActionController { $entryDAO = FreshRSS_Factory::createEntryDao(); if ($id == false) { + if (!Minz_Request::isPost()) { + return; + } + if (!$get) { $entryDAO->markReadEntries ($idMax); } else { -- cgit v1.2.3