diff options
| author | Michael Merickel <mmerickel@users.noreply.github.com> | 2016-04-16 15:17:52 -0500 |
|---|---|---|
| committer | Michael Merickel <mmerickel@users.noreply.github.com> | 2016-04-16 15:17:52 -0500 |
| commit | 4a4d4b90d108f545000666080b873363386d3ac9 (patch) | |
| tree | 6185b4704a6de2261d5568773c260d50e209d0aa /CHANGES.txt | |
| parent | 1799be9dd8666d10d6b4a04a9b75fc57f8626c6f (diff) | |
| parent | 65dee6e4ca0c0c607e97db0c9e55768f10591a58 (diff) | |
| download | pyramid-4a4d4b90d108f545000666080b873363386d3ac9.tar.gz pyramid-4a4d4b90d108f545000666080b873363386d3ac9.tar.bz2 pyramid-4a4d4b90d108f545000666080b873363386d3ac9.zip | |
Merge pull request #2501 from dstufft/check-origin-csrf
In addition to CSRF token, verify the origin too
Diffstat (limited to 'CHANGES.txt')
| -rw-r--r-- | CHANGES.txt | 12 |
1 files changed, 12 insertions, 0 deletions
diff --git a/CHANGES.txt b/CHANGES.txt index 0a7bdef1a..0cd2c0c9a 100644 --- a/CHANGES.txt +++ b/CHANGES.txt @@ -35,6 +35,18 @@ Features https://github.com/Pylons/pyramid/pull/2413 and https://github.com/Pylons/pyramid/pull/2500 +- Added an additional CSRF validation that checks the origin/referrer of a + request and makes sure it matches the current ``request.domain``. This + particular check is only active when accessing a site over HTTPS as otherwise + browsers don't always send the required information. If this additional CSRF + validation fails a ``BadCSRFOrigin`` exception will be raised and may be + caught by exception views (the default response is ``400 Bad Request``). + Additional allowed origins may be configured by setting + ``pyramid.csrf_trusted_origins`` to a list of domain names (with ports if on + a non standard port) to allow. Subdomains are not allowed unless the domain + name has been prefixed with a ``.``. See: + https://github.com/Pylons/pyramid/pull/2501 + - Pyramid HTTPExceptions will now take into account the best match for the clients Accept header, and depending on what is requested will return text/html, application/json or text/plain. The default for */* is still |
