disable token on forms and add to cart


A simple way (apparently, as I haven't verified this works everywhere) to disable checking the token, regardless if it exists or not, is:

In /classes/sanitize.class.php, in the checkToken() function, there are two places:

The first applies to the admin section. We will leave that as it is for now.

The second applies to when payment gateways call back with transaction results. An exception is created. We will make that exception apply regardless.

In this function, find:

if (!empty($_POST)) {
  $csrf_exception = false;

Change to:

if (!empty($_POST)) {
  $csrf_exception = true; // Set this to false to restore normal CSRF protection!


