<?xml-stylesheet type="text/xsl" href="https://sugarclub.sugarcrm.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>CSRF Tokens in Sugar 7.7</title><link>/dev-club/b/dev-blog/posts/csrf-tokens-in-sugar-7-7</link><description>What is a Cross Site Request Forgery (CSRF)?A CSRF is a type of exploit that a malicious website or attacker could employ to have a user send unauthorized commands to a website or application. It is a type of confused deputy attack agains...</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: CSRF Tokens in Sugar 7.7</title><link>https://sugarclub.sugarcrm.com/dev-club/b/dev-blog/posts/csrf-tokens-in-sugar-7-7</link><pubDate>Fri, 17 Aug 2018 18:14:26 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:6a687b2a-2ae7-4c14-9878-c4c6272df62e</guid><dc:creator>Michael A. Agarenzo</dc:creator><slash:comments>0</slash:comments><description>
&lt;p&gt;Hi again Matt,&lt;/p&gt;&lt;p&gt;My mistake, those steps are indeed working!&lt;/p&gt;&lt;p&gt;I tried including the Smarty tag in the PHP file, rather than separating the HTML form from the PHP file to a Template file and then including the Smarty tag there.&lt;/p&gt;&lt;p&gt;Works as intended now. Thank you!&lt;/p&gt;&lt;p&gt;Best,&lt;/p&gt;&lt;p&gt;Mike&lt;/p&gt;
&lt;img src="https://sugarclub.sugarcrm.com/aggbug?PostID=762&amp;AppID=56&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: CSRF Tokens in Sugar 7.7</title><link>https://sugarclub.sugarcrm.com/dev-club/b/dev-blog/posts/csrf-tokens-in-sugar-7-7</link><pubDate>Thu, 16 Aug 2018 15:46:00 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:6a687b2a-2ae7-4c14-9878-c4c6272df62e</guid><dc:creator>Michael A. Agarenzo</dc:creator><slash:comments>1</slash:comments><description>
&lt;p&gt;Hey Matt,&lt;/p&gt;&lt;p&gt;Currently working with SugarCRM 8.0.1.&lt;/p&gt;&lt;p&gt;Have there been any other explanations (since this one) of how to implement a CSRF token in a BWC HTML form?&lt;/p&gt;&lt;p&gt;All I&amp;#39;ve seen is that we need to implement a CSRF token in our custom modules so as to avoid the XSRF error on form submits, but I have not found steps anywhere on how to actually implement this.&lt;/p&gt;&lt;p&gt;I have tried adding the smarty tag above and it was to no avail. Is there a step-by-step explanation anywhere of how to do this?&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Best,&lt;/p&gt;&lt;p&gt;Mike&lt;/p&gt;
&lt;img src="https://sugarclub.sugarcrm.com/aggbug?PostID=762&amp;AppID=56&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: CSRF Tokens in Sugar 7.7</title><link>https://sugarclub.sugarcrm.com/dev-club/b/dev-blog/posts/csrf-tokens-in-sugar-7-7</link><pubDate>Tue, 08 Aug 2017 07:27:02 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:6a687b2a-2ae7-4c14-9878-c4c6272df62e</guid><dc:creator>SugarCRM Developers</dc:creator><slash:comments>0</slash:comments><description>
&lt;p&gt;&lt;i&gt;Comment originally made by Mehul Bhandari.&lt;/i&gt;&lt;/p&gt;&lt;span&gt;Thanks Matthew&lt;/span&gt;&lt;p&gt;Helpful !!&lt;/p&gt;
&lt;img src="https://sugarclub.sugarcrm.com/aggbug?PostID=762&amp;AppID=56&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item></channel></rss>