I would be reluctant to hire someone to work on my webstore if they didn't know javascript. I may be wrong but I think forms with no parameters can still be treated as straight up links without the security issue.

I agree with your last point however, the front-end should be capable of operating with javascript disabled and for that reason a submit button may be better.

Regards
Scott

On 8/01/2010, at 9:54 AM, Ruth Hoffman wrote:

Hi Scott:
That requires that a person know Javascript. And with really simple forms - say forms with no parameters, why introduce the Javascript overhead?

BTW, there are still people out there that disable Javascript, if you can believe that.
Regards,
Ruth

Scott Gray wrote:
The approach most often taken so far has been to use a link with javascript attached to submit the form.

Regards
Scott

HotWax Media
http://www.hotwaxmedia.com

On 8/01/2010, at 8:15 AM, Ruth Hoffman wrote:

Correct. Depending on the browser, you can style the submit button to look like a link - if you want. What I've done is style my links to look like buttons.
----------------------------------------------------
Find me on the web at http://www.myofbiz.com or Google keyword "myofbiz"
ruth.hoff...@myofbiz.com
Info Olagos wrote:
ok thanks Ruth,

I will try to fix it myself.
Then i suppose i have to use a button instead of a link to click on?

Heidi

2010/1/7 Ruth Hoffman <rhoff...@aesolves.com>


Hi Heidi:
The problem is that several of the existing OFBiz service calls such as this have not been upgraded to the required (when calling from a secured location) new method of invocation - as a form. You may either wait for someone to fix it for you or change the service call to be invoked as part
of a form instead of as a URL.

Hope this helps.
Regards,
Ruth
----------------------------------------------------
Find me on the web at http://www.myofbiz.com or Google keyword "myofbiz"
ruth.hoff...@myofbiz.com


Info Olagos wrote:


This is done now.

Regards,
Heidi

2010/1/7 Jacques Le Roux <jacques.le.r...@les7arts.com>




First thing to do is helping us to help you, please follow the
recommendation

Thanks

Jacques

From: "Info Olagos" <info.ola...@gmail.com>

Hello,



When i try to unsubscribe from a contactlist in the screen "profile" in
the
ecommerce screen, i get the following error:


Error calling event: org.ofbiz.webapp.event.EventHandlerException: Found
URL
parameter [contactListId] passed to secure (https) request- map with uri
[updateContactListParty] with an event that calls service
[updateContactListParty]; this is not allowed for security reasons! The
data
should be encrypted by making it part of the request body (a form field)
instead of the request URL.

Moreover it would be kind if you could create a Jira sub-task of
https://issues.apache.org/jira/browse/OFBIZ-2330
(check before if a sub-task for this error does not exist).
If you are not sure how to create a Jira issue please have a look before
at
http://docs.ofbiz.org/x/r.

Thank you in advance for your help.



Can anyone help me with a solution?



Thanks,

Heidi










Attachment: smime.p7s
Description: S/MIME cryptographic signature

Reply via email to