1. 18 Mar, 2015 1 commit
  2. 16 Mar, 2015 1 commit
    • Skip CSRF referer check for cross-domain requests. · b625e8e3
      This commit extends the workaround in `cors_csrf` middleware
      to Django Rest Framework's SessionAuthentication, which
      calls Django's CSRF middleware directly.
      
      The workaround checks the cross domain whitelist and
      skips the CSRF referer check for domains on the whitelist.
      Will Daly committed
  3. 11 Mar, 2015 2 commits
    • Cross-domain CSRF cookies · a5a303ae
      When configured, set an additional cookie with the CSRF
      token for use by subdomains.
      
      The cookie can have a different name than the default
      CSRF cookie, preventing conflicts between cookies
      from different domains (e.g. ".edx.org", "courses.edx.org",
      and "edge.edx.org").
      
      The new cookie is included only on the enrollment API
      views so that the scope of this change is limited
      to the end-points that require cross-domain POST requests.
      Will Daly committed
  4. 09 Mar, 2015 1 commit
    • Cross-domain CSRF cookies · cbdc269b
      When configured, set an additional cookie with the CSRF
      token for use by subdomains.
      
      The cookie can have a different name than the default
      CSRF cookie, preventing conflicts between cookies
      from different domains (e.g. ".edx.org", "courses.edx.org",
      and "edge.edx.org").
      
      The new cookie is included only on the enrollment API
      views so that the scope of this change is limited
      to the end-points that require cross-domain POST requests.
      Will Daly committed
  5. 17 Feb, 2015 1 commit