veda-consulting-company / uk.co.vedaconsulting.gdpr

Other
11 stars 55 forks source link

Submitting CommPreferences form without checksum creates activity records #279

Open alantgpl opened 3 years ago

alantgpl commented 3 years ago

If a visitor were to strip away the checksum in the URL, eg. just visiting directly /civicrm/gdpr/comms-prefs/update, and then submitting the form, GDPR activity records are created with no contact reference.

Can the lack of checksum, or an expired one, be blocked from creating records?