summaryrefslogtreecommitdiff
path: root/app/Http/RequestHandlers/RegisterPage.php
diff options
context:
space:
mode:
authorGreg Roach <greg@subaqua.co.uk>2021-09-05 19:41:55 +0100
committerGreg Roach <greg@subaqua.co.uk>2021-09-07 12:40:37 +0100
commitf91b88bbf38a16e50b92fec16f3630ea823ce5ac (patch)
treeb3758d80d296173033695b956e5f4f51ec7d94a2 /app/Http/RequestHandlers/RegisterPage.php
parent06707ebb55ff2529f5b3104794be4bc69163e80d (diff)
downloadwebtrees-f91b88bbf38a16e50b92fec16f3630ea823ce5ac.tar.gz
webtrees-f91b88bbf38a16e50b92fec16f3630ea823ce5ac.tar.bz2
webtrees-f91b88bbf38a16e50b92fec16f3630ea823ce5ac.zip
Fix: do not pass email/username in URL parameters
Diffstat (limited to 'app/Http/RequestHandlers/RegisterPage.php')
-rw-r--r--app/Http/RequestHandlers/RegisterPage.php9
1 files changed, 5 insertions, 4 deletions
diff --git a/app/Http/RequestHandlers/RegisterPage.php b/app/Http/RequestHandlers/RegisterPage.php
index 6e3ec0c5cf..5669b8fafd 100644
--- a/app/Http/RequestHandlers/RegisterPage.php
+++ b/app/Http/RequestHandlers/RegisterPage.php
@@ -23,6 +23,7 @@ use Fisharebest\Webtrees\Exceptions\HttpNotFoundException;
use Fisharebest\Webtrees\Http\ViewResponseTrait;
use Fisharebest\Webtrees\I18N;
use Fisharebest\Webtrees\Services\CaptchaService;
+use Fisharebest\Webtrees\Session;
use Fisharebest\Webtrees\Site;
use Psr\Http\Message\ResponseInterface;
use Psr\Http\Message\ServerRequestInterface;
@@ -57,10 +58,10 @@ class RegisterPage implements RequestHandlerInterface
$this->checkRegistrationAllowed();
$tree = $request->getAttribute('tree');
- $comments = $request->getQueryParams()['comments'] ?? '';
- $email = $request->getQueryParams()['email'] ?? '';
- $realname = $request->getQueryParams()['realname'] ?? '';
- $username = $request->getQueryParams()['username'] ?? '';
+ $comments = Session::get('register_comments', '');
+ $email = Session::get('register_email', '');
+ $realname = Session::get('register_realname', '');
+ $username = Session::get('register_username', '');
$show_caution = Site::getPreference('SHOW_REGISTER_CAUTION') === '1';