[Changeset] r12173 - django/trunk/docs/intro

0 views
Skip to first unread message

nor...@djangoproject.com

unread,
Jan 10, 2010, 12:55:47 PM1/10/10
to django-...@googlegroups.com
Author: adrian
Date: 2010-01-10 11:55:46 -0600 (Sun, 10 Jan 2010)
New Revision: 12173

Modified:
django/trunk/docs/intro/tutorial04.txt
Log:
Fixed #12350 -- Fixed typo in tutorial04. Thanks, mortense

Modified: django/trunk/docs/intro/tutorial04.txt
===================================================================
--- django/trunk/docs/intro/tutorial04.txt 2010-01-10 17:54:34 UTC (rev 12172)
+++ django/trunk/docs/intro/tutorial04.txt 2010-01-10 17:55:46 UTC (rev 12173)
@@ -47,15 +47,15 @@
* ``forloop.counter`` indicates how many times the :ttag:`for` tag has gone
through its loop

- * Since we are creating a POST form (which can have the effect of modifying
- data), we unfortunately need to worry about Cross Site Request Forgeries.
+ * Since we're creating a POST form (which can have the effect of modifying
+ data), we need to worry about Cross Site Request Forgeries.
Thankfully, you don't have to worry too hard, because Django comes with
- very easy-to-use system for protecting against it. In short, all POST
- forms that are targetted at internal URLs need the ``{% csrf_token %}``
- template tag adding.
+ a very easy-to-use system for protecting against it. In short, all POST
+ forms that are targeted at internal URLs should use the ``{% csrf_token %}``
+ template tag.

The ``{% csrf_token %}`` tag requires information from the request object, which
-is not normally accessible from within the template context. To fix this, a
+is not normally accessible from within the template context. To fix this, a
small adjustment needs to be made to the ``detail`` view, so that it looks like
the following::

Reply all
Reply to author
Forward
0 new messages