diff options
| author | Donald Stufft <donald@stufft.io> | 2016-04-15 17:41:35 -0400 |
|---|---|---|
| committer | Donald Stufft <donald@stufft.io> | 2016-04-15 18:31:23 -0400 |
| commit | f12005b92fa9bb33f082bd50747eb11791605cff (patch) | |
| tree | ba171caede0f861a5ded96309615b10351a7484b /docs/whatsnew-1.7.rst | |
| parent | bf33b200bbb72114ca55150724b0a4c51d7ef535 (diff) | |
| download | pyramid-f12005b92fa9bb33f082bd50747eb11791605cff.tar.gz pyramid-f12005b92fa9bb33f082bd50747eb11791605cff.tar.bz2 pyramid-f12005b92fa9bb33f082bd50747eb11791605cff.zip | |
Only Accept CSRF Tokens in headers or POST bodies
Previously `check_csrf_token` would allow passing in a CSRF token in through a
the URL of a request. However this is a security issue because a CSRF token
must not be allowed to leak, and URLs regularly get copy/pasted or otherwise
end up leaking to the outside world.
Diffstat (limited to 'docs/whatsnew-1.7.rst')
0 files changed, 0 insertions, 0 deletions
