authentication.py
1.33 KB
-
Skip CSRF referer check for cross-domain requests. · b625e8e3
This commit extends the workaround in `cors_csrf` middleware to Django Rest Framework's SessionAuthentication, which calls Django's CSRF middleware directly. The workaround checks the cross domain whitelist and skips the CSRF referer check for domains on the whitelist.
Will Daly committed