zulip/humbug
Reid Barton 6bb9ad4e3c Avoid cross-site logout attacks
Require POST method for /accounts/logout. This has the side effect of
automatically enabling Django's CSRF protection.

(imported from commit 44b1b6ebaadc1c03006e21ae54ac768e31234801)
2013-03-06 19:10:04 -05:00
..
__init__.py Initial Django commit: basic account, zephyr stream, narrowing, etc. 2012-08-28 12:44:51 -04:00
authhack.py Fix logging in with email addresses long than 30 characters. 2013-01-16 17:02:06 -05:00
backends.py [manual] Implement backend support for authenticating a user via Google. 2013-02-27 10:16:54 -05:00
ratelimit.py Use datetime.min for initial last_error rather than int 0. 2012-12-11 15:59:08 -05:00
settings.py settings: Decrease duplicated code in database configuration. 2013-03-06 11:36:15 -05:00
test_settings.py Re-enable desktop notifications in automated testing 2013-02-26 18:02:20 -05:00
urls.py Avoid cross-site logout attacks 2013-03-06 19:10:04 -05:00
wsgi.py Remove more commented out example code 2012-10-29 23:21:00 -04:00