These should not be in the public plugin accessible via a GET. At the very least they should require an environment variable and CSRF protection. I'm removing them because they don't seem commonly used. |
||
|---|---|---|
| .. | ||
| locales | ||
| routes.rb | ||
These should not be in the public plugin accessible via a GET. At the very least they should require an environment variable and CSRF protection. I'm removing them because they don't seem commonly used. |
||
|---|---|---|
| .. | ||
| locales | ||
| routes.rb | ||