Thanks. I just found this on github in the version history:
= 15.0.2 =
* bugfix: validate {IP} being an IP address, preventing CSRF or other similar attacks
* other: remove {Referer} substitution variable
I do not understand why this has been removed. It is not a privacy violation to use this header information. In the use case I’m dealing with, people decide how to act on the form based on that (and yes, this practice has been thought about intensively, there is no better way to deal with their specific situation.)
Please add this functionality back into 15.0.4.
-
This reply was modified 4 years, 9 months ago by modus.
-
This reply was modified 4 years, 9 months ago by modus.