Automated Logout
Someone could trigger the log out page without a user doing anything. This would force a user to log out. They could not read any private information or change anything on the site.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Automated Logout to 2.0.2 or 8.x-1.7, whichever branch you are on.
For developers: what the fix changed
Adds `_csrf_token: 'TRUE'` to the module's routes in `autologout.routing.yml` and updates `autologout.module` and `src/Form/AutologoutBlockForm.php` to generate and append CSRF tokens to the corresponding URLs. The JavaScript in `js/autologout.js` is also updated to use these tokenised URLs.
Also in this release Replaced jQuery dialog with Drupal.dialog, removed the js-cookie dependency, and added session existence checks.
.cspell-project-words.txt+14 −0README.md+79 −34autologout.api.php+2 −2autologout.info.yml+1 −2autologout.libraries.yml+1 −2autologout.module+81 −6 fixautologout.post_update.php+22 −2autologout.routing.yml+4 −0 fixcomposer.json+0 −3config/install/autologout.settings.yml+3 −0config/schema/autologout.schema.yml+9 −2js/autologout.js+246 −178 fix