diff options
| author | Casey Duncan <casey.duncan@gmail.com> | 2011-01-06 00:00:34 -0700 |
|---|---|---|
| committer | Casey Duncan <casey.duncan@gmail.com> | 2011-01-06 00:00:34 -0700 |
| commit | f8f2fa32bcbec2334e02b9f16ee72d40e2fa857b (patch) | |
| tree | 83e9e8fa7a5e9036820587b6ebf616755aa53d12 /docs | |
| parent | e5f66f8e839ee5d7eeaebb118c9d03f11578dd14 (diff) | |
| download | pyramid-f8f2fa32bcbec2334e02b9f16ee72d40e2fa857b.tar.gz pyramid-f8f2fa32bcbec2334e02b9f16ee72d40e2fa857b.tar.bz2 pyramid-f8f2fa32bcbec2334e02b9f16ee72d40e2fa857b.zip | |
clarify
Diffstat (limited to 'docs')
| -rw-r--r-- | docs/narr/sessions.rst | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/docs/narr/sessions.rst b/docs/narr/sessions.rst index edd24d839..cce77ca5b 100644 --- a/docs/narr/sessions.rst +++ b/docs/narr/sessions.rst @@ -293,7 +293,7 @@ application to perform some command that requires elevated privileges. You can avoid most of these attacks by making sure that the correct *CSRF token* has been set in an :app:`Pyramid` session object before performing any -actions in code which requires elevated privileges and is invoked via a form +actions in code which requires elevated privileges that is invoked via a form post. To use CSRF token support, you must enable a :term:`session factory` as described in :ref:`using_the_default_session_factory` or :ref:`using_alternate_session_factories`. |
