zulip/zephyr
Reid Barton 6bb9ad4e3c Avoid cross-site logout attacks
Require POST method for /accounts/logout. This has the side effect of
automatically enabling Django's CSRF protection.

(imported from commit 44b1b6ebaadc1c03006e21ae54ac768e31234801)
2013-03-06 19:10:04 -05:00
..
fixtures Rename zephyrs.json => messages.json in .gitignore. 2012-10-10 10:39:27 -04:00
jstemplates Unsmush the "Add members" textbox on the streams page. 2013-03-05 14:52:57 -05:00
lib Detect image-ness by end of path component, not end of entire URL 2013-03-06 19:02:29 -05:00
management Add support for making Tornado dump its stack via SIGUSR1/2. 2013-03-06 14:19:32 -05:00
migrations [south] Add enter-sends field to UserProfile model. 2013-02-27 17:25:15 -05:00
static Avoid cross-site logout attacks 2013-03-06 19:10:04 -05:00
tests tests: Move casper.page.onError setup outside casper.start(). 2013-03-06 11:36:15 -05:00
__init__.py Initial Django commit: basic account, zephyr stream, narrowing, etc. 2012-08-28 12:44:51 -04:00
context_processors.py [manual] Get rid of the static-access-control mechanism 2013-01-31 15:34:12 -05:00
decorator.py Fix use of case-sensitive comparisons on email addresses. 2013-02-28 17:49:57 -05:00
filters.py Filter out all cookies and the csrfmiddlewaretoken. 2013-02-05 16:12:48 -05:00
forms.py Rename is_active to is_inactive. 2013-02-12 16:15:29 -05:00
handlers.py Catch all exceptions when sending a message from AdminHumbugHandler 2013-02-05 16:12:48 -05:00
middleware.py logging: Fix super verbose logging of 404 errors. 2013-02-12 16:36:13 -05:00
models.py [schema] Save enter_sends on the server in the database. 2013-02-27 17:25:29 -05:00
openid.py [manual] Implement backend support for authenticating a user via Google. 2013-02-27 10:16:54 -05:00
retention_policy.py Fix use of case-sensitive comparisons on email addresses. 2013-02-28 17:49:57 -05:00
tests.py Don't image-ify :( and other smileys 😞 2013-03-05 16:22:51 -05:00
tornadoviews.py Clean up fetch_table_messages code a bit. 2013-02-12 16:25:45 -05:00
views.py Avoid cross-site logout attacks 2013-03-06 19:10:04 -05:00