summaryrefslogtreecommitdiff
path: root/CHANGES.rst
diff options
context:
space:
mode:
authorTres Seaver <tseaver@palladion.com>2024-06-09 16:28:34 -0400
committerTres Seaver <tseaver@palladion.com>2024-06-09 21:09:19 -0400
commitc9235146e0102d03bb4548711cd0b3b0637d81fa (patch)
tree3a4fee834522fea73a3eaa9eda02c9bb7be0aa69 /CHANGES.rst
parent72f61853beda8e21b669c3520e43fe3e5b224ba3 (diff)
downloadpyramid-c9235146e0102d03bb4548711cd0b3b0637d81fa.tar.gz
pyramid-c9235146e0102d03bb4548711cd0b3b0637d81fa.tar.bz2
pyramid-c9235146e0102d03bb4548711cd0b3b0637d81fa.zip
docs: remove 'came_from' from login view
- The narrative doesn't discuss this (mis-)feature. - Without any authorization, there is no meaninful reason to remember the 'previous' page. - As a general rule, we want to avoid trusting user-supplied data (i.e., from the query string or form params) when constructing redirect URLs.
Diffstat (limited to 'CHANGES.rst')
0 files changed, 0 insertions, 0 deletions