Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

In addition to CSRF token, verify the origin too #2501

Merged
merged 1 commit into from
Apr 16, 2016

Commits on Apr 16, 2016

  1. In addition to CSRF token, verify the origin too

    Add an additional layer of protection against CSRF by verifying the actual
    origin of the request in addition to the CSRF token. We only do this check on
    sites hosted behind HTTPS because only HTTPS sites have evidence to show that
    the Referrer header is not being spuriously removed by random middleware
    boxes.
    dstufft committed Apr 16, 2016
    Configuration menu
    Copy the full SHA
    65dee6e View commit details
    Browse the repository at this point in the history