#33523: remove dangerous text from translated message about csrf error
------------------------------------+--------------------------------------
Reporter: Maxim Danilov | Owner: nobody
Type: Bug | Status: closed
Component: CSRF | Version: 4.0
Severity: Normal | Resolution: invalid
Keywords: csrf error message | Triage Stage: Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 1 | UI/UX: 0
------------------------------------+--------------------------------------
Changes (by Mariusz Felisiak):
* status: new => closed
* resolution: => invalid
Comment:
Thanks for this report, however I cannot imagine how that could be
dangerous 🤔. As far as I understand correctly, you have a custom template
for CSRF failure and you put `no_referer3` in the `<head>` HTML tag, even
so it's not marked as safe and will not be interpreted by a browser.
--
Ticket URL: <https://code.djangoproject.com/ticket/33523#comment:1>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/067.9c02d11bc1df4802b833a751de711d7d%40djangoproject.com.