summaryrefslogtreecommitdiff
path: root/docs/narr/csrf.rst
diff options
context:
space:
mode:
authorChris McDonough <chrism@plope.com>2010-12-29 13:57:54 -0500
committerChris McDonough <chrism@plope.com>2010-12-29 13:57:54 -0500
commit7f14c3750dcf2b79e9146b0a3750af307fd1a86b (patch)
tree198d67733a6303f3ce0c8f17e3938d0619f37ed2 /docs/narr/csrf.rst
parentfcfc5aebc259fa34d8d2313adde7c2f57bab2e53 (diff)
parent581a401c26047a6cddb6521393de4030ce0a962a (diff)
downloadpyramid-7f14c3750dcf2b79e9146b0a3750af307fd1a86b.tar.gz
pyramid-7f14c3750dcf2b79e9146b0a3750af307fd1a86b.tar.bz2
pyramid-7f14c3750dcf2b79e9146b0a3750af307fd1a86b.zip
Merge branch 'master' into viewderiver
Diffstat (limited to 'docs/narr/csrf.rst')
-rw-r--r--docs/narr/csrf.rst2
1 files changed, 1 insertions, 1 deletions
diff --git a/docs/narr/csrf.rst b/docs/narr/csrf.rst
index 7586b0ed7..2f545fb4f 100644
--- a/docs/narr/csrf.rst
+++ b/docs/narr/csrf.rst
@@ -9,7 +9,7 @@ phenomenon whereby a user with an identity on your website might click on a
URL or button on another website which unwittingly redirects the user to your
application to perform some command that requires elevated privileges.
-You can avoid most of these attacks by making sure that a the correct *CSRF
+You can avoid most of these attacks by making sure that the correct *CSRF
token* has been set in an :app:`Pyramid` session object before performing any
actions in code which requires elevated privileges and is invoked via a form
post. To use CSRF token support, you must enable a :term:`session factory`