#16010: Support Origin header checking in the CSRF middleware
-----------------------------+--------------------------------------
     Reporter:  davidben     |                    Owner:  Tim Graham
         Type:  New feature  |                   Status:  assigned
    Component:  CSRF         |                  Version:  master
     Severity:  Normal       |               Resolution:
     Keywords:               |             Triage Stage:  Accepted
    Has patch:  1            |      Needs documentation:  0
  Needs tests:  0            |  Patch needs improvement:  1
Easy pickings:  0            |                    UI/UX:  0
-----------------------------+--------------------------------------
Changes (by Tim Graham):

 * owner:  nobody => Tim Graham
 * status:  new => assigned
 * version:  1.3 => master


Comment:

 I created a [https://github.com/django/django/pull/13829 PR] that brings
 the patch from 10 years ago current. I still need to investigate Luke's
 comment about `CSRF_COOKIE_DOMAIN`.

-- 
Ticket URL: <https://code.djangoproject.com/ticket/16010#comment:9>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/066.3f7a640e8ab02b96399723dc0ee1bcd8%40djangoproject.com.

Reply via email to