[wp-trac] [WordPress Trac] #36362: check_ajax_referer() does not send a 403 response code upon failure

WordPress Trac noreply at wordpress.org
Tue Mar 29 02:17:04 UTC 2016


#36362: check_ajax_referer() does not send a 403 response code upon failure
--------------------------+-----------------------------
 Reporter:  johnbillion   |      Owner:
     Type:  defect (bug)  |     Status:  new
 Priority:  normal        |  Milestone:  Awaiting Review
Component:  Security      |    Version:  3.4
 Severity:  normal        |   Keywords:
  Focuses:                |
--------------------------+-----------------------------
 When `check_ajax_referer()` fails, a `200` HTTP response code is still
 sent back to the client, whereas `check_admin_referer()` correctly returns
 a `403`.

 The `_ajax_wp_die_handler()` function lacks the ability to provide an HTTP
 response code.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/36362>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list