Name |
Last commit
|
Last update |
---|---|---|
.. | ||
__init__.py | ||
admin.py | ||
djangostore.py | ||
models.py | ||
views.py |
Replaced the previous method of getting it from HTTP_POST to use django's mechanism, which may or may not use HTTP_HOST. However if an attacker changes the request header, there is not much he can do since he cannot recreate the association nonce.
Name |
Last commit
|
Last update |
---|---|---|
.. | ||
__init__.py | Loading commit data... | |
admin.py | Loading commit data... | |
djangostore.py | Loading commit data... | |
models.py | Loading commit data... | |
views.py | Loading commit data... |