From 9aa2b6b9a46427a8b9611231d672fab9df127e3e Mon Sep 17 00:00:00 2001
From: Jean-Philippe Lang <jp_lang@yahoo.fr>
Date: Sun, 25 Oct 2009 13:38:48 +0000
Subject: [PATCH] IssuesController#destroy accepts POST only (#4107).

git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@2980 e93f8b46-1217-0410-a6f0-8f06a7374b81
---
 app/controllers/issues_controller.rb | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/app/controllers/issues_controller.rb b/app/controllers/issues_controller.rb
index bebba10a4..426143439 100644
--- a/app/controllers/issues_controller.rb
+++ b/app/controllers/issues_controller.rb
@@ -44,6 +44,10 @@ class IssuesController < ApplicationController
   helper :timelog
   include Redmine::Export::PDF
 
+  verify :method => :post,
+         :only => :destroy,
+         :render => { :nothing => true, :status => :method_not_allowed }
+           
   def index
     retrieve_query
     sort_init(@query.sort_criteria.empty? ? [['id', 'desc']] : @query.sort_criteria)
-- 
GitLab