From: Simon Willison <swilli...@gmail.com>
Date: Wed, 14 Sep 2005 17:29:52 +0100
Local: Wed, Sep 14 2005 12:29 pm
Subject: Re: Django's overall security
One thing that Django would definitely benefit from is support for
simple protection against CSRF attacks. The admin site should have this turned on by default, and some kind of mechanism for easily applying it to custom code would be welcome as well. CSRF attacks are described in detail here:
http://www.squarefree.com/securitytips/web-developers.html#CSRF
(Further info at the bottom of the page)
Basically, if I can trick you in to visiting a page that I control
The only guaranteed defence against this attack is to include in
I've filed a bug to track developments on this: http:// Cheers,
Simon Willison
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||