From: Bob Thomas <robert.w.tho...@gmail.com>
Date: Tue, 6 Jan 2009 11:16:41 -0800 (PST)
Local: Tues, Jan 6 2009 2:16 pm
Subject: Re: CSRF / SafeForm
I added a ticket (with patch) for implementing the template tag:
http://code.djangoproject.com/ticket/9977 It also adds a CSRF context processor, which is used by the tag. The diff doesn't look quite right. There obviously needs to be an
-bob
On Jan 5, 12:17 pm, Luke Plant <L.Plant...@cantab.net> wrote:
> I wrote:
> > If you want to implement any of this, I'm not planning on working > > on it for this next week, I'll get in touch when I start in case > > you've made some progress. > I'm now not going to be able to implement this for the 1.1 deadline.
> We would need to also ensure that all apps in contrib use the template
> Finally, most importantly:
> I think we really need CSRF protection for the admin by default for
> Luke
> --
> Luke Plant ||http://lukeplant.me.uk/ You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||