Merge branch 'security_core_71' into 'security-fixes'
authorseamuslee <seamus@nsw.greens.org.au>
Wed, 4 Dec 2019 05:15:59 +0000 (05:15 +0000)
committerseamuslee <seamus@nsw.greens.org.au>
Wed, 4 Dec 2019 05:15:59 +0000 (05:15 +0000)
security/core#71 Only permit requests where there is the header `HTTP_X_REQUESTED_WITH` and it's value is XMLHttpRequest for APIv4 to prevent CSRF

See merge request security/core!94


Trivial merge