#14134: Ability to set csrf cookie path and https-only
------------------------------------------+---------------------------------
Reporter: [email protected] | Owner: nobody
Status: new | Milestone:
Component: Core framework | Version: 1.2
Resolution: | Keywords: csrf
Stage: Accepted | Has_patch: 1
Needs_docs: 1 | Needs_tests: 0
Needs_better_patch: 1 |
------------------------------------------+---------------------------------
Changes (by mtredinnick):
* needs_better_patch: 0 => 1
* summary: Ability to set csrf cookie path => Ability to set csrf cookie
path and https-only
* stage: Design decision needed => Accepted
Comment:
Absolutely required. We also need `CSRF_COOKIE_SECURE`. Changing title to
reflect that and make this ticket about getting the missing pieces of the
CSRF cookie config in place (just needs the "secure" option added).
--
Ticket URL: <http://code.djangoproject.com/ticket/14134#comment:2>
Django <http://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to
[email protected].
For more options, visit this group at
http://groups.google.com/group/django-updates?hl=en.