diff options
| author | Tres Seaver <tseaver@palladion.com> | 2024-06-09 16:28:34 -0400 |
|---|---|---|
| committer | Tres Seaver <tseaver@palladion.com> | 2024-06-09 21:09:19 -0400 |
| commit | c9235146e0102d03bb4548711cd0b3b0637d81fa (patch) | |
| tree | 3a4fee834522fea73a3eaa9eda02c9bb7be0aa69 /CHANGES.rst | |
| parent | 72f61853beda8e21b669c3520e43fe3e5b224ba3 (diff) | |
| download | pyramid-c9235146e0102d03bb4548711cd0b3b0637d81fa.tar.gz pyramid-c9235146e0102d03bb4548711cd0b3b0637d81fa.tar.bz2 pyramid-c9235146e0102d03bb4548711cd0b3b0637d81fa.zip | |
docs: remove 'came_from' from login view
- The narrative doesn't discuss this (mis-)feature.
- Without any authorization, there is no meaninful reason to remember
the 'previous' page.
- As a general rule, we want to avoid trusting user-supplied data (i.e.,
from the query string or form params) when constructing redirect URLs.
Diffstat (limited to 'CHANGES.rst')
0 files changed, 0 insertions, 0 deletions
