Commit dd6070ee authored by Kevin Falcone's avatar Kevin Falcone
Browse files

Merge branch '3.0/whitelist-rtir-search-results' into 3.0-trunk

parents f0e17eb6 53612b7e
......@@ -79,6 +79,16 @@ my $ticket_sql_parser = Parse::BooleanLogic->new;
# Add the RTIR search result page to the whitelist to allow
# bookmarks to work without CSRF warnings, similar to the RT
# search result page. As noted in the similar RT configuration,
# whitelisted search links can be used for denial-of-service against RT
# (construct a very inefficient query and trick lots of users into
# running them against RT). This is offset by the general usefulness of
# bookmarking search links.
$RT::Interface::Web::is_whitelisted_component{'/RTIR/Search/Results.html'} = 1;
=head2 OurQueue
